{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T11:06:40Z","timestamp":1784286400362,"version":"3.55.0"},"publisher-location":"Cham","reference-count":64,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032323569","type":"print"},{"value":"9783032323576","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-32357-6_1","type":"book-chapter","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T10:34:22Z","timestamp":1784284462000},"page":"3-35","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Hybrid Robustness Verification for\u00a0Spatio-Temporal Neural Networks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0191-8107","authenticated-orcid":false,"given":"Sherwin","family":"Varghese","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0779-3114","authenticated-orcid":false,"given":"Matthew","family":"Wicker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3420-723X","authenticated-orcid":false,"given":"Alessio","family":"Lomuscio","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"1_CR1","doi-asserted-by":"crossref","unstructured":"Agarwal, A., Vatsa, M., Singh, R., Ratha, N.K.: Noise is inside me! generating adversarial perturbations with noise derived from natural filters. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Workshops (2020)","DOI":"10.1109\/CVPRW50498.2020.00395"},{"key":"1_CR2","unstructured":"Balunovic, M., Baader, M., Singh, G., Gehr, T., Vechev, M.T.: Certifying geometric robustness of neural networks. In: Wallach, H.M., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E.B., Garnett, R. (eds.) Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, pp. 15287\u201315297. December 8-14, 2019, Vancouver, BC, Canada (2019). https:\/\/proceedings.neurips.cc\/paper\/2019\/hash\/f7fa6aca028e7ff4ef62d75ed025fe76-Abstract.html"},{"key":"1_CR3","unstructured":"Banerjee, D., Singh, G.: Relational dnn verification with cross executional bound refinement. In: Proceedings of the 41st International Conference on Machine Learning. ICML\u201924, JMLR.org (2024)"},{"key":"1_CR4","doi-asserted-by":"publisher","unstructured":"Botoeva, E., Kouvaros, P., Kronqvist, J., Lomuscio, A., Misener, R.: Efficient verification of relu-based neural networks via dependency analysis. In: The Thirty-Fourth AAAI Conference on rtificial Intelligence, AAAI 2020, The Thirty-Second Innovative Applications of Artificial Intelligence Conference, IAAI 2020, The Tenth AAAI Symposium on Educational Advances in Artificial Intelligence, EAAI 2020, New York, NY, USA, February 7-12, 2020, pp. 3291\u20133299. AAAI Press (2020). https:\/\/doi.org\/10.1609\/AAAI.V34I04.5729","DOI":"10.1609\/AAAI.V34I04.5729"},{"key":"1_CR5","doi-asserted-by":"publisher","unstructured":"Che, H., Chen, S., Chen, H.: Image Quality-aware Diagnosis via Meta-knowledge Co-embedding . In: 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 19819\u201319829. IEEE Computer Society, Los Alamitos, CA, USA (2023). https:\/\/doi.org\/10.1109\/CVPR52729.2023.01898, https:\/\/doi.ieeecomputersociety.org\/10.1109\/CVPR52729.2023.01898","DOI":"10.1109\/CVPR52729.2023.01898"},{"key":"1_CR6","doi-asserted-by":"publisher","unstructured":"Che, H., Cheng, Y., Jin, H., Chen, H.: Towards generalizable diabetic retinopathy grading in unseen domains. In: Greenspan, H., et al. (eds.) Medical Image Computing and Computer Assisted Intervention \u2013 MICCAI 2023, pp. 430\u2013440. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-43904-9_42","DOI":"10.1007\/978-3-031-43904-9_42"},{"key":"1_CR7","unstructured":"Chiang, P., Ni, R., Abdelkader, A., Zhu, C., Studer, C., Goldstein, T.: Certified defenses for adversarial patches. In: 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26-30, 2020. OpenReview.net (2020). https:\/\/openreview.net\/forum?id=HyeaSkrYPH"},{"key":"1_CR8","unstructured":"De\u00a0Palma, A., Bunel, R.R., Dvijotham, K.D., Kumar, M.P., Stanforth, R., Lomuscio, A.: Expressive losses for verified robustness via convex combinations. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Dutta, S., Chen, X., Sankaranarayanan, S.: Reachability analysis for neural feedback systems using regressive polynomial rule inference. In: Proceedings of the 22nd ACM International Conference on Hybrid Systems: Computation and Control (HSCC19), pp. 157\u2013168. ACM (2019)","DOI":"10.1145\/3302504.3311807"},{"key":"1_CR10","unstructured":"Dvijotham, K., Stanforth, R., Gowal, S., Mann, T.A., Kohli, P.: A dual approach to scalable verification of deep networks. In: UAI, vol.\u00a01, p.\u00a03 (2018)"},{"issue":"3","key":"1_CR11","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/S10994-017-5663-3","volume":"107","author":"A Fawzi","year":"2018","unstructured":"Fawzi, A., Fawzi, O., Frossard, P.: Analysis of classifiers\u2019 robustness to adversarial perturbations. Mach. Learn. 107(3), 481\u2013508 (2018). https:\/\/doi.org\/10.1007\/S10994-017-5663-3","journal-title":"Mach. Learn."},{"key":"1_CR12","unstructured":"Fazlyab, M., Morari, M., Pappas, G.J.: Efficient and accurate estimation of lipschitz constants for deep neural networks. In: Advances in Neural Information Processing Systems (NeurIPS) (2019)"},{"key":"1_CR13","doi-asserted-by":"publisher","unstructured":"Gehr, T., Mirman, M., Drachsler-Cohen, D., Tsankov, P., Chaudhuri, S., Vechev, M.: Ai2: Safety and robustness certification of neural networks with abstract interpretation. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318 (2018). https:\/\/doi.org\/10.1109\/SP.2018.00058","DOI":"10.1109\/SP.2018.00058"},{"key":"1_CR14","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: Bengio, Y., LeCun, Y. (eds.) 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings (2015). http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"1_CR15","unstructured":"Gowal, S., et al.: On the effectiveness of interval bound propagation for training verifiably robust models. ArXiv:abs\/1810.12715 (2018). https:\/\/api.semanticscholar.org\/CorpusID:53112003"},{"key":"1_CR16","unstructured":"Hein, M., Andriushchenko, M.: Formal guarantees on the robustness of a classifier against adversarial manipulation. In: Advances in Neural Information Processing Systems (NeurIPS) (2017)"},{"key":"1_CR17","doi-asserted-by":"crossref","unstructured":"Hingun, N., Sitawarin, C., Li, J., Wagner, D.: Reap: A large-scale realistic adversarial patch benchmark. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), pp. 4640\u20134651 (2023)","DOI":"10.1109\/ICCV51070.2023.00428"},{"key":"1_CR18","unstructured":"Hu, H., Liu, C., Zhao, D.: Robustness verification for perception models against camera motion perturbations. In: International conference on machine learning (ICML) Workshop on Formal Verification of Machine Learning (WFVML) (2023)"},{"key":"1_CR19","doi-asserted-by":"crossref","unstructured":"Huchette, J., Mu\u00f1oz, G., Serra, T., Tsay, C.: When deep learning meets polyhedral theory: A survey. INFORMS J. Comput. (2026)","DOI":"10.1287\/ijoc.2024.0902"},{"key":"1_CR20","unstructured":"Jordan, M., Hayase, J., Dimakis, A., Oh, S.: Zonotope domains for lagrangian neural network verification. In: Koyejo, S., Mohamed, S., Agarwal, A., Belgrave, D., Cho, K., Oh, A. (eds.) Advances in Neural Information Processing Systems 35: Annual Conference on Neural Information Processing Systems 2022, NeurIPS 2022, New Orleans, LA, USA, November 28\u2013December 9, 2022 (2022). http:\/\/papers.nips.cc\/paper_files\/paper\/2022\/hash\/37c5e5e5e44950fe20f9e6452d0373ec-Abstract-Conference.html"},{"key":"1_CR21","doi-asserted-by":"publisher","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., Kochenderfer, M.J.: Reluplex: An efficient smt solver for verifying deep neural networks. In: Majumdar, R., Kun\u010dak, V. (eds.) Computer Aided Verification: 29th International Conference, CAV 2017, Heidelberg, Germany, July 24-28, 2017, Proceedings, Part I 30, pp. 97\u2013117. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63387-9_5","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"1_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"443","DOI":"10.1007\/978-3-030-25540-4_26","volume-title":"Computer Aided Verification","author":"G Katz","year":"2019","unstructured":"Katz, G., et al.: The Marabou Framework for Verification and Analysis of Deep Neural Networks. In: Dillig, I., Tasiran, S. (eds.) CAV 2019. LNCS, vol. 11561, pp. 443\u2013452. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25540-4_26"},{"key":"1_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.energy.2024.132885","volume":"308","author":"J Lambert","year":"2024","unstructured":"Lambert, J., Ceruti, A., Spliethoff, H.: Benchmark of mixed-integer linear programming formulations for district heating network design. Energy 308, 132885 (2024)","journal-title":"Energy"},{"key":"1_CR24","first-page":"10171","volume":"34","author":"M Lechner","year":"2021","unstructured":"Lechner, M., \u017dikeli\u0107, \u0110, Chatterjee, K., Henzinger, T.: Infinite time horizon safety of bayesian neural networks. Adv. Neural. Inf. Process. Syst. 34, 10171\u201310185 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"1_CR25","unstructured":"LeCun, Y., Cortes, C., Burges, C.J.: The mnist database of handwritten digits (1998)"},{"issue":"4","key":"1_CR26","doi-asserted-by":"publisher","first-page":"4110","DOI":"10.1109\/TDSC.2023.3346064","volume":"21","author":"HJ Lee","year":"2023","unstructured":"Lee, H.J., Ro, Y.M.: Defending video recognition model against adversarial perturbations via defense patterns. IEEE Trans. Dependable Secure Comput. 21(4), 4110\u20134121 (2023)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"1_CR27","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.106145","volume":"203","author":"IG Lee","year":"2020","unstructured":"Lee, I.G., Zhang, Q., Yoon, S.W., Won, D.: A mixed integer linear programming support vector machine for cost-effective feature selection. Knowl.-Based Syst. 203, 106145 (2020)","journal-title":"Knowl.-Based Syst."},{"key":"1_CR28","doi-asserted-by":"publisher","DOI":"10.1016\/j.tre.2020.102059","volume":"142","author":"YH Lin","year":"2020","unstructured":"Lin, Y.H., Wang, Y., He, D., Lee, L.H.: Last-mile delivery: Optimal locker location under multinomial logit choice model. Transp. Res. Part E: Logist. Transp. Rev. 142, 102059 (2020)","journal-title":"Transp. Res. Part E: Logist. Transp. Rev."},{"key":"1_CR29","unstructured":"Lomuscio, A., Maganti, L.: An approach to reachability analysis for feed-forward relu neural networks. CoRR abs\/1706.07351 (2017). http:\/\/arxiv.org\/abs\/1706.07351"},{"key":"1_CR30","doi-asserted-by":"publisher","unstructured":"Luo, W., Yang, B., Urtasun, R.: Fast and furious: Real time end-to-end 3d detection, tracking and motion forecasting with a single convolutional net. In: 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018, pp. 3569\u20133577. Computer Vision Foundation\/IEEE Computer Society (2018). https:\/\/doi.org\/10.1109\/CVPR.2018.00376, http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Luo_Fast_and_Furious_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00376"},{"key":"1_CR31","unstructured":"Mao, Y., M\u00fcller, M.N., Fischer, M., Vechev, M.T.: Connecting certified and adversarial training. In: Oh, A., Naumann, T., Globerson, A., Saenko, K., Hardt, M., Levine, S. (eds.) Advances in Neural Information Processing Systems 36: Annual Conference on Neural Information Processing Systems 2023, NeurIPS 2023, New Orleans, LA, USA, December 10\u201316, 2023 (2023). http:\/\/papers.nips.cc\/paper_files\/paper\/2023\/hash\/e8b0c97b34fdaf58b2f48f8cca85e76a-Abstract-Conference.html"},{"key":"1_CR32","unstructured":"Massena, T., Friedrich, C., Mamalet, F., Serrurier, M.: Fast and flexible robustness certificates for semantic segmentation (2025). https:\/\/arxiv.org\/abs\/2512.06010"},{"key":"1_CR33","unstructured":"M\u00fcller, M.N., Eckert, F., Fischer, M., Vechev, M.T.: Certified training: Small boxes are all you need. In: The Eleventh International Conference on Learning Representations, ICLR 2023, Kigali, Rwanda, May 1\u20135, 2023. OpenReview.net (2023). https:\/\/openreview.net\/forum?id=7oFuxtJtUMH"},{"key":"1_CR34","doi-asserted-by":"publisher","unstructured":"Mummadi, C.K., Brox, T., Metzen, J.H.: Defending against universal perturbations with shared adversarial training. In: 2019 IEEE\/CVF International Conference on Computer Vision, ICCV 2019, Seoul, Korea (South), October 27\u2013November 2, 2019, pp. 4927\u20134936. IEEE (2019). https:\/\/doi.org\/10.1109\/ICCV.2019.00503","DOI":"10.1109\/ICCV.2019.00503"},{"key":"1_CR35","doi-asserted-by":"crossref","unstructured":"Sasaki, S., Lopez, D.M., Robinette, P.K., Johnson, T.T.: Robustness verification of video classification neural networks. In: Proceedings of the IEEE\/ACM 47th International Conference on Software Engineering (2025)","DOI":"10.1109\/FormaliSE66629.2025.00009"},{"key":"1_CR36","unstructured":"Singh, G., Gehr, T., Mirman, M., P\u00fcschel, M., Vechev, M.: Fast and effective robustness certification. In: Bengio, S., Wallach, H., Larochelle, H., Grauman, K., Cesa-Bianchi, N., Garnett, R. (eds.) Advances in Neural Information Processing Systems, vol.\u00a031. Curran Associates, Inc. (2018). https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/f2f446980d8e971ef3da97af089481c3-Paper.pdf"},{"key":"1_CR37","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: An abstract domain for certifying neural networks. Proc. ACM Program. Lang. 3(POPL), 1\u201330 (2019)","DOI":"10.1145\/3290354"},{"key":"1_CR38","unstructured":"Singla, S., Feizi, S.: Skew orthogonal convolutions. In: International Conference on Machine Learning (ICML) (2021)"},{"key":"1_CR39","unstructured":"Soomro, K., Zamir, A.R., Shah, M.: UCF101: A dataset of 101 human actions classes from videos in the wild. CoRR abs\/1212.0402 (2012). http:\/\/arxiv.org\/abs\/1212.0402"},{"key":"1_CR40","doi-asserted-by":"crossref","unstructured":"Sosnin, P., Knapp, J., Kennedy, F., Collyer, J., Tsay, C.: Exact certification of data-poisoning attacks using mixed-integer programming. arXiv preprint arXiv:2602.16944 (2026)","DOI":"10.1007\/978-3-032-27242-3_32"},{"key":"1_CR41","unstructured":"Sosnin, P., M\u00fcller, M.N., Baader, M., Tsay, C., Wicker, M.: Certified robustness to data poisoning in gradient-based training. Trans. Mach. Learn. Res. (TMLR) (2024)"},{"key":"1_CR42","unstructured":"Sosnin, P., Wicker, M., Collyer, J., Tsay, C.: Abstract gradient training: A unified certification framework for data poisoning, unlearning, and differential privacy. arXiv preprint arXiv:2511.09400 (2025)"},{"key":"1_CR43","doi-asserted-by":"publisher","unstructured":"Stallkamp, J., Schlipsing, M., Salmen, J., Igel, C.: The german traffic sign recognition benchmark: A multi-class classification competition. In: The 2011 International Joint Conference on Neural Networks, pp. 1453\u20131460 (2011). https:\/\/doi.org\/10.1109\/IJCNN.2011.6033395","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"1_CR44","unstructured":"Szegedy, C.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"1_CR45","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: International Conference on Learning Representations (ICLR) (2014)"},{"key":"1_CR46","unstructured":"Tian, Y., Ye, Q., Doermann, D.: Yolov12: Attention-centric real-time object detectors. arXiv preprint arXiv:2502.12524 (2025)"},{"key":"1_CR47","unstructured":"Tjeng, V., Xiao, K.Y., Tedrake, R.: Evaluating robustness of neural networks with mixed integer programming. In: International Conference on Learning Representations (2019). https:\/\/openreview.net\/forum?id=HyGIdiRqtm"},{"key":"1_CR48","unstructured":"Tramer, F., Boneh, D.: Adversarial training and robustness for multiple perturbations. In: Wallach, H., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E., Garnett, R. (eds.) Advances in Neural Information Processing Systems. vol.\u00a032. Curran Associates, Inc. (2019). https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2019\/file\/5d4ae76f053f8f2516ad12961ef7fe97-Paper.pdf"},{"key":"1_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-030-53288-8_2","volume-title":"Computer Aided Verification","author":"H-D Tran","year":"2020","unstructured":"Tran, H.-D., Bak, S., Xiang, W., Johnson, T.T.: Verification of Deep Convolutional Neural Networks Using ImageStars. In: Lahiri, S.K., Wang, C. (eds.) CAV 2020. LNCS, vol. 12224, pp. 18\u201342. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-53288-8_2"},{"key":"1_CR50","unstructured":"Tsuzuku, Y., Sato, I., Sugiyama, M.: Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks. In: Advances in Neural Information Processing Systems (NeurIPS) (2018)"},{"key":"1_CR51","unstructured":"Udacity, A.: Udacity self-driving car dataset (2017)"},{"key":"1_CR52","unstructured":"Virmaux, A., Scaman, K.: Lipschitz regularity of deep neural networks: analysis and efficient estimation. In: Advances in Neural Information Processing Systems (NeurIPS) (2018)"},{"key":"1_CR53","doi-asserted-by":"publisher","unstructured":"Wang, F., Xu, P., Ruan, W., Huang, X.: Towards verifying the geometric robustness of large-scale neural networks. In: Williams, B., Chen, Y., Neville, J. (eds.) Thirty-Seventh AAAI Conference on Artificial Intelligence, AAAI 2023, Thirty-Fifth Conference on Innovative Applications of Artificial Intelligence, IAAI 2023, Thirteenth Symposium on Educational Advances in Artificial Intelligence, EAAI 2023, Washington, DC, USA, February 7-14, 2023, pp. 15197\u201315205. AAAI Press (2023). https:\/\/doi.org\/10.1609\/AAAI.V37I12.26773","DOI":"10.1609\/AAAI.V37I12.26773"},{"key":"1_CR54","doi-asserted-by":"publisher","unstructured":"Wang, Y., Zhao, H., Gummadi, D., Dianati, M., Debattista, K., Donzella, V.: Benchmarking the robustness of panoptic segmentation for automated driving. CoRR abs\/2402.15469 (2024). https:\/\/doi.org\/10.48550\/ARXIV.2402.15469","DOI":"10.48550\/ARXIV.2402.15469"},{"key":"1_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1007\/978-3-319-89960-2_22","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"M Wicker","year":"2018","unstructured":"Wicker, M., Huang, X., Kwiatkowska, M.: Feature-Guided Black-Box Safety Testing of Deep Neural Networks. In: Beyer, D., Huisman, M. (eds.) TACAS 2018. LNCS, vol. 10805, pp. 408\u2013426. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-89960-2_22"},{"key":"1_CR56","unstructured":"Wicker, M., Laurenti, L., Patane, A., Paoletti, N., Abate, A., Kwiatkowska, M.: Certification of iterative predictions in bayesian neural networks. In: Uncertainty in Artificial Intelligence, pp. 1713\u20131723. PMLR (2021)"},{"key":"1_CR57","doi-asserted-by":"publisher","DOI":"10.1016\/j.artint.2024.104132","volume":"334","author":"M Wicker","year":"2024","unstructured":"Wicker, M., Laurenti, L., Patane, A., Paoletti, N., Abate, A., Kwiatkowska, M.: Probabilistic reach-avoid for bayesian neural networks. Artif. Intell. 334, 104132 (2024)","journal-title":"Artif. Intell."},{"key":"1_CR58","unstructured":"Wicker, M.R., et al.: Certification for differentially private prediction in gradient-based training. In: International Conference on Machine Learning, pp. 66726\u201366745. PMLR (2025)"},{"key":"1_CR59","unstructured":"Wong, E., Kolter, Z.: Provable defenses against adversarial examples via the convex outer adversarial polytope. In: International Conference on Machine Learning, pp. 5286\u20135295. PMLR (2018)"},{"key":"1_CR60","doi-asserted-by":"publisher","unstructured":"Wu, M., Kwiatkowska, M.: Robustness guarantees for deep neural networks on videos. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 308\u2013317 (2020). https:\/\/doi.org\/10.1109\/CVPR42600.2020.00039","DOI":"10.1109\/CVPR42600.2020.00039"},{"key":"1_CR61","doi-asserted-by":"publisher","unstructured":"Wu, M., Wicker, M., Ruan, W., Huang, X., Kwiatkowska, M.: A game-based approximate verification of deep neural networks with provable guarantees. Theoret. Comput. Sci. 807, 298\u2013329 (2020). https:\/\/doi.org\/10.1016\/j.tcs.2019.05.046, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0304397519304426","DOI":"10.1016\/j.tcs.2019.05.046"},{"key":"1_CR62","doi-asserted-by":"publisher","unstructured":"Wu, Y., Chen, H., Makki, A.P., Nguyen, P., Yesha, Y.: Efficient data-sketches and fine-tuning for early detection of distributional drift in medical imaging. CoRR abs\/2408.08456 (2024). https:\/\/doi.org\/10.48550\/ARXIV.2408.08456","DOI":"10.48550\/ARXIV.2408.08456"},{"key":"1_CR63","unstructured":"Yang, J., et al.: Medmnist v2: A large-scale lightweight benchmark for 2D and 3D biomedical image classification. CoRR abs\/2110.14795 (2021), https:\/\/arxiv.org\/abs\/2110.14795"},{"key":"1_CR64","unstructured":"Zhang, Y., Kouvaros, P., Lomuscio, A.: Scalable neural network geometric robustness validation via H\u00f6lder optimisation. In: Advances in Neural Information Processing Systems (NeurIPS), vol.\u00a038 (2025). https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2025\/hash\/1435ac9924d7621e44aa2407a1cfdec7-Abstract-Conference.html"}],"container-title":["Lecture Notes in Computer Science","AI Verification"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-32357-6_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T10:34:37Z","timestamp":1784284477000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-32357-6_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,18]]},"ISBN":["9783032323569","9783032323576"],"references-count":64,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-32357-6_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,18]]},"assertion":[{"value":"18 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAIV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on AI Verification","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lisbon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"saiv2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/aiverification.org\/2026","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}