{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T10:30:30Z","timestamp":1787135430501,"version":"3.56.0"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031999901","type":"print"},{"value":"9783031999918","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T00:00:00Z","timestamp":1761609600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T00:00:00Z","timestamp":1761609600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-031-99991-8_13","type":"book-chapter","created":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T05:36:03Z","timestamp":1761543363000},"page":"238-249","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["CTRAIN - A Training Library for Certifiably Robust Neural Networks (Extended Abstract)"],"prefix":"10.1007","author":[{"given":"Konstantin","family":"Kaulen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Holger H.","family":"Hoos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,28]]},"reference":[{"key":"13_CR1","unstructured":"Bai, J., Lu, F., Zhang, K., et\u00a0al.: ONNX: Open Neural Network Exchange (2025). https:\/\/github.com\/onnx\/onnx"},{"issue":"3","key":"13_CR2","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/s10009-023-00703-4","volume":"25","author":"C Brix","year":"2023","unstructured":"Brix, C., M\u00fcller, M.N., Bak, S., Johnson, T.T., Liu, C.: First three years of the international verification of neural networks competition (VNN-COMP). Int. J. Softw. Tools Technol. Transfer 25(3), 329\u2013339 (2023)","journal-title":"Int. J. Softw. Tools Technol. Transfer"},{"issue":"42","key":"13_CR3","first-page":"1","volume":"21","author":"R Bunel","year":"2020","unstructured":"Bunel, R., Lu, J., Turkaslan, I., Torr, P.H., Kohli, P., Kumar, M.P.: Branch and bound for piecewise linear neural network verification. J. Mach. Learn. Res. 21(42), 1\u201339 (2020)","journal-title":"J. Mach. Learn. Res."},{"key":"13_CR4","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proceedings of the 37th International Conference on Machine Learning, (ICML 2020), vol.\u00a0119, pp. 2206\u20132216 (2020)"},{"issue":"61","key":"13_CR5","first-page":"1","volume":"25","author":"A Palma","year":"2024","unstructured":"Palma, A., Behl, H.S., Bunel, R., Torr, P.H.S., Kumar, M.P.: Scaling the convex barrier with sparse dual algorithms. J. Mach. Learn. Res. 25(61), 1\u201351 (2024)","journal-title":"J. Mach. Learn. Res."},{"key":"13_CR6","unstructured":"De\u00a0Palma, A., Bunel, R., Dvijotham, K.D., Kumar, M.P., Stanforth, R., Lomuscio, A.: Expressive Losses for Verified Robustness via Convex Combinations. In: Proceedings of the 12th International Conference on Learning Representations (ICLR 2024). pp. 1\u201328 (2024)"},{"key":"13_CR7","unstructured":"Demarchi, S., et al.: Supporting standardization of neural networks verification with VNNLIB and CoCoNet. In: Proceedings of the 6th Workshop on Formal Methods for ML-Enabled Autonomous Systems (FoMLAS 2023), pp. 47\u201358 (2023)"},{"key":"13_CR8","unstructured":"Dosovitskiy, A., et al.: An image is worth 16x16 words: transformers for image recognition at scale. In: Proceedings of the 9th International Conference on Learning Representations (ICLR 2021), pp. 1\u201322 (2021)"},{"key":"13_CR9","unstructured":"Eggensperger, K., et al.: HPOBench: A collection of reproducible multi-fidelity benchmark problems for HPO. In: Proceedings of the 35th Conference on Neural Information Processing Systems (NeurIPS 2021) Track on Datasets and Benchmarks, pp. 1\u201336 (2021)"},{"key":"13_CR10","unstructured":"Ferrari, C., Mueller, M.N., Jovanovi\u0107, N., Vechev, M.: Complete verification via multi-neuron relaxation guided branch-and-bound. In: Proceedings of the 10th International Conference on Learning Representations (ICLR 2022), pp. 1\u201315 (2022)"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"Gowal, S., et al.: Scalable verified training for provably robust image classification. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 4842\u20134851 (2019)","DOI":"10.1109\/ICCV.2019.00494"},{"key":"13_CR12","unstructured":"Ioffe, S., Szegedy, C.: Batch normalization: accelerating deep network training by reducing internal covariate shift. In: Proceedings of the 32nd International Conference on Machine Learning (ICML 2015), vol.\u00a037, pp. 448\u2013456 (2015)"},{"issue":"7873","key":"13_CR13","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1038\/s41586-021-03819-2","volume":"596","author":"J Jumper","year":"2021","unstructured":"Jumper, J.: Highly accurate protein structure prediction with AlphaFold. Nature 596(7873), 583\u2013589 (2021)","journal-title":"Nature"},{"key":"13_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1007\/978-3-319-63387-9_5","volume-title":"Computer Aided Verification","author":"G Katz","year":"2017","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., Kochenderfer, M.J.: Reluplex: An Efficient SMT Solver for Verifying Deep Neural Networks. In: Majumdar, R., Kun\u010dak, V. (eds.) CAV 2017. LNCS, vol. 10426, pp. 97\u2013117. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63387-9_5"},{"issue":"12","key":"13_CR15","first-page":"1","volume":"25","author":"M K\u00f6nig","year":"2024","unstructured":"K\u00f6nig, M., Bosman, A.W., Hoos, H.H., Rijn, J.N.: Critically assessing the state of the art in neural network verification. J. Mach. Learn. Res. 25(12), 1\u201353 (2024)","journal-title":"J. Mach. Learn. Res."},{"key":"13_CR16","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning Multiple Layers of Features from Tiny Images (2009)"},{"key":"13_CR17","unstructured":"Le, Y., Yang, X.S.: Tiny ImageNet Visual Recognition Challenge (2015)"},{"key":"13_CR18","unstructured":"LeCun, Y.: The MNIST Database of Handwritten Digits (1998)"},{"key":"13_CR19","doi-asserted-by":"crossref","unstructured":"Li, L., Xie, T., Li, B.: Sok: Certified robustness for deep neural networks. In: Proceedings of the 44th IEEE Symposium on Security and Privacy (S and P 2023), pp. 1289\u20131310. IEEE (2023)","DOI":"10.1109\/SP46215.2023.10179303"},{"key":"13_CR20","doi-asserted-by":"crossref","unstructured":"Li, Y., Jin, W., Xu, H., Tang, J.: DeepRobust: a platform for adversarial attacks and defenses. In: Proceedings of the 35th AAAI Conference on Artificial Intelligence (AAAI-21), pp. 16078\u201316080 (2021)","DOI":"10.1609\/aaai.v35i18.18017"},{"issue":"54","key":"13_CR21","first-page":"1","volume":"23","author":"M Lindauer","year":"2022","unstructured":"Lindauer, M.: SMAC3: a versatile Bayesian optimization package for hyperparameter optimization. J. Mach. Learn. Res. 23(54), 1\u20139 (2022)","journal-title":"J. Mach. Learn. Res."},{"key":"13_CR22","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: Proceedings of 6th International Conference on Learning Representations (ICLR 2018), pp. 1\u201323 (2018)"},{"key":"13_CR23","unstructured":"Mao, Y., Balauca, S., Vechev, M.: CTBENCH: A Library and Benchmark for Certified Training. arXiv preprint arXiv:2406.04848 (2024)"},{"key":"13_CR24","unstructured":"Mao, Y., M\u00fcller, M.N., Fischer, M., Vechev, M.T.: Connecting certified and adversarial training. In: Advances in Neural Information Processing Systems 37 (NeurIPS 2023), pp. 1\u201319 (2023)"},{"key":"13_CR25","unstructured":"Mao, Y., M\u00fcller, M.N., Fischer, M., Vechev, M.T.: Understanding certified training with interval bound propagation. In: Proceedings of the 12th International Conference on Learning Representations (ICLR 2024), pp. 1\u201323 (2024)"},{"key":"13_CR26","unstructured":"Mirman, M., Gehr, T., Vechev, M.: Differentiable abstract interpretation for provably robust neural networks. In: Proceedings of the 35th International Conference on Machine Learning (ICML 2018), pp. 3578\u20133586. PMLR (2018)"},{"key":"13_CR27","unstructured":"M\u00fcller, M.N., Brix, C., Bak, S., Liu, C., Johnson, T.T.: The Third International Verification of Neural Networks Competition (VNN-COMP 2022): Summary and Results. arXiv preprint arXiv:2212.10376 (2022)"},{"key":"13_CR28","unstructured":"M\u00fcller, M.N., Eckert, F., Fischer, M., Vechev, M.T.: Certified training: small boxes are all you need. In: Proceedings of the 11th International Conference on Learning Representations (ICLR 2023), pp. 1\u201321 (2023)"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"M\u00fcller, M.N., Makarchuk, G., Singh, G., P\u00fcschel, M., Vechev, M.: PRIMA: general and precise neural network certification via scalable convex hull approximations. In: Proceedings of the 6th ACM on Programming Languages (POPL), pp. 1\u201333 (2022)","DOI":"10.1145\/3498704"},{"key":"13_CR30","unstructured":"Paszke, A., et al.: PyTorch: an imperative style, high-performance deep learning library. In: Advances in Neural Information Processing Systems 33 (NeurIPS 2019), pp. 1\u201312 (2019)"},{"key":"13_CR31","doi-asserted-by":"crossref","unstructured":"Pfisterer, F., Schneider, L., Moosbauer, J., Binder, M., Bischl, B.: YAHPO Gym - an efficient multi-objective multi-fidelity benchmark for hyperparameter optimization. In: Proceedings of the First International Conference on Automated Machine Learning (AutoML-Conf 2022), vol.\u00a0188, pp. 3\/1\u201339. PMLR (2022)","DOI":"10.1145\/3610536"},{"key":"13_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/978-3-030-89716-1_10","volume-title":"Reachability Problems","author":"M S\u00e4lzer","year":"2021","unstructured":"S\u00e4lzer, M., Lange, M.: Reachability is NP-Complete Even for the Simplest Neural Networks. In: Bell, P.C., Totzke, P., Potapov, I. (eds.) RP 2021. LNCS, vol. 13035, pp. 149\u2013164. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-89716-1_10"},{"key":"13_CR33","unstructured":"Shi, Z., Wang, Y., Zhang, H., Yi, J., Hsieh, C.: Fast certified robust training with short warmup. In: Advances in Neural Information Processing Systems 34 (NeurIPS 2021), pp. 18335\u201318349 (2021)"},{"key":"13_CR34","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: An abstract domain for certifying neural networks. In: Proceedings of the 3rd ACM on Programming Languages (POPL 2019), pp. 1\u201330 (2019)","DOI":"10.1145\/3290354"},{"key":"13_CR35","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: Proceedings of the 2nd International Conference on Learning Representations (ICLR 2014), pp. 1\u201310 (2014)"},{"key":"13_CR36","unstructured":"Tjeng, V., Xiao, K.Y., Tedrake, R.: Evaluating robustness of neural networks with mixed integer programming. In: Proceedings of the 7th International Conference on Learning Representations (ICLR 2019), pp. 1\u201321 (2019)"},{"key":"13_CR37","unstructured":"Trusted-AI: adversarial robustness toolbox (2025). https:\/\/github.com\/Trusted-AI\/adversarial-robustness-toolbox"},{"key":"13_CR38","unstructured":"Wang, S., et al.: Beta-CROWN: efficient bound propagation with per-neuron split constraints for neural network robustness verification. In: Advances in Neural Information Processing Systems 34 (NeurIPS 2021), pp. 29909\u201329921 (2021)"},{"key":"13_CR39","unstructured":"Xu, K., et al.: Automatic perturbation analysis for scalable certified robustness and beyond. In: Advances in Neural Information Processing Systems 33 (NeurIPS 2020), pp. 1\u201313 (2020)"},{"key":"13_CR40","unstructured":"Xu, K., et al.: Fast and complete: enabling complete neural network verification with rapid and massively parallel incomplete verifiers. In: Proceedings of the 9th International Conference on Learning Representations (ICLR 2021), pp. 1\u201315 (2021)"},{"key":"13_CR41","unstructured":"Zhang, H., et al.: Theoretically principled trade-off between robustness and accuracy. In: Proceedings of the 36th International Conference on Machine Learning (ICML 2019), vol.\u00a097, pp. 7472\u20137482. PMLR (2019)"},{"key":"13_CR42","unstructured":"Zhang, H., et al.: Towards stable and efficient training of verifiably robust neural networks. In: Proceedings of the 8th International Conference on Learning Representations (ICLR 2020), pp. 1\u201315 (2019)"},{"key":"13_CR43","doi-asserted-by":"crossref","unstructured":"Zhang, H., et al.: General cutting planes for bound-propagation-based neural network verification. Advances in Neural Information Processing Systems 35 (NeurIPS 2022), pp. 1656\u20131670 (2022)","DOI":"10.52202\/068431-0121"},{"key":"13_CR44","unstructured":"Zhang, H., Weng, T.W., Chen, P.Y., Hsieh, C.J., Daniel, L.: Efficient neural network robustness certification with general activation functions. In: Advances in Neural Information Processing Systems 31 (NeurIPS 2018), pp. 4944\u2014-4953 (2018)"}],"container-title":["Lecture Notes in Computer Science","AI Verification"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-99991-8_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T10:14:33Z","timestamp":1787134473000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-99991-8_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,28]]},"ISBN":["9783031999901","9783031999918"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-99991-8_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,28]]},"assertion":[{"value":"28 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","label":"Disclosure of Interests","group":{"name":"EthicsHeading","label":"Ethics"}},{"value":"SAIV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on AI Verification","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Zagreb","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Croatia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"saiv2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.aiverification.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}