{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T08:27:50Z","timestamp":1777969670185,"version":"3.51.4"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T00:00:00Z","timestamp":1771200000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T00:00:00Z","timestamp":1771200000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001691","name":"Japan Society for the Promotion of Science","doi-asserted-by":"publisher","award":["KAKENHI JP24K20738"],"award-info":[{"award-number":["KAKENHI JP24K20738"]}],"id":[{"id":"10.13039\/501100001691","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001866","name":"National Research Fund","doi-asserted-by":"crossref","award":["NRF 2021-R1A2C1003810"],"award-info":[{"award-number":["NRF 2021-R1A2C1003810"]}],"id":[{"id":"10.13039\/501100001866","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001866","name":"National Research Fund","doi-asserted-by":"crossref","award":["KAKENHI 24K14836"],"award-info":[{"award-number":["KAKENHI 24K14836"]}],"id":[{"id":"10.13039\/501100001866","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Comput Optim Appl"],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1007\/s10589-026-00765-5","type":"journal-article","created":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T15:23:11Z","timestamp":1771255391000},"page":"41-72","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations"],"prefix":"10.1007","volume":"94","author":[{"given":"Godai","family":"Azuma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sunyoung","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Makoto","family":"Yamashita","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,2,16]]},"reference":[{"key":"765_CR1","unstructured":"Argue, C.J., K\u0131l\u0131n\u00e7-Karzan, F., Wang, A.L.: Necessary and sufficient conditions for rank-one generated cones. arXiv:2007.07433, (2020)"},{"issue":"2","key":"765_CR2","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1007\/s10898-021-01071-6","volume":"82","author":"G Azuma","year":"2022","unstructured":"Azuma, G., Fukuda, M., Kim, S., Yamashita, M.: Exact SDP relaxations of quadratically constrained quadratic programs with forest structures. J. Global Optim. 82(2), 243\u2013262 (2022)","journal-title":"J. Global Optim."},{"key":"765_CR3","doi-asserted-by":"publisher","first-page":"671","DOI":"10.1007\/s10898-022-01268-3","volume":"86","author":"G Azuma","year":"2023","unstructured":"Azuma, G., Fukuda, M., Kim, S., Yamashita, M.: Exact SDP relaxations for quadratic programs with bipartite graph structures. J. Global Optim. 86, 671\u2013691 (2023)","journal-title":"J. Global Optim."},{"key":"765_CR4","unstructured":"Bastani, O., Ioannou, Y., Lampropoulos, L., Vytiniotis, D., Nori, A., Criminisi, A.: Measuring neural net robustness with constraints. Advances in neural information processing systems, 29, (2016)"},{"key":"765_CR5","doi-asserted-by":"publisher","unstructured":"Beck, A.: Introduction to Nonlinear Optimization. Society for Industrial and Applied Mathematics, Philadelphia, PA, (2014). https:\/\/doi.org\/10.1137\/1.9781611973655. https:\/\/epubs.siam.org\/doi\/abs\/10.1137\/1.9781611973655","DOI":"10.1137\/1.9781611973655"},{"issue":"1","key":"765_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10107-019-01367-2","volume":"181","author":"S Burer","year":"2020","unstructured":"Burer, S., Ye, Y.: Exact semidefinite formulations for a class of (random and non-random) nonconvex quadratic programs. Math. Program. 181(1), 1\u201317 (2020). https:\/\/doi.org\/10.1007\/s10107-019-01367-2","journal-title":"Math. Program."},{"key":"765_CR7","doi-asserted-by":"crossref","unstructured":"Deng, L., Hinton, G., Kingsbury, B.: New types of deep neural network learning for speech recognition and related applications: An overview. In 2013 IEEE international conference on acoustics, speech and signal processing, 8599\u20138603. IEEE, (2013)","DOI":"10.1109\/ICASSP.2013.6639344"},{"key":"765_CR8","doi-asserted-by":"crossref","unstructured":"Dutta, S., Jha, S., Sankaranarayanan, S., Tiwari, A.: Output range analysis for deep feedforward neural networks. In NASA Formal Methods Symposium, 121\u2013138. Springer, (2018)","DOI":"10.1007\/978-3-319-77935-5_9"},{"key":"765_CR9","unstructured":"Dvijotham, K., Stanforth, R., Gowal, S., Mann, T.A., Kohli, P.: A dual approach to scalable verification of deep networks. In UAI, 1, 3, (2018)"},{"issue":"10","key":"765_CR10","doi-asserted-by":"publisher","first-page":"2279","DOI":"10.1016\/S0031-3203(01)00178-9","volume":"35","author":"M Egmont-Petersen","year":"2002","unstructured":"Egmont-Petersen, M., de Ridder, D., Handels, H.: Image processing with neural networks-a review. Pattern Recogn. 35(10), 2279\u20132301 (2002)","journal-title":"Pattern Recogn."},{"key":"765_CR11","doi-asserted-by":"crossref","unstructured":"Fazlyab, M., Morari, M., Pappas, G.J.: Probabilistic verification and reachability analysis of neural networks via semidefinite programming. In 2019 IEEE 58th Conference on Decision and Control (CDC), 2726\u20132731, (2019)","DOI":"10.1109\/CDC40024.2019.9029310"},{"issue":"1","key":"765_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TAC.2020.3046193","volume":"67","author":"M Fazlyab","year":"2022","unstructured":"Fazlyab, M., Morari, M., Pappas, G.J.: Safety verification and robustness analysis of neural networks via quadratic constraints and semidefinite programming. IEEE Trans. Autom. Control 67(1), 1\u201315 (2022)","journal-title":"IEEE Trans. Autom. Control"},{"key":"765_CR13","doi-asserted-by":"publisher","unstructured":"G\u00e4rtner, B., Matousek, J.: Approximation Algorithms and Semidefinite Programming. Springer Publishing Company, Incorporated (2014)978-3-642-22014-2. https:\/\/doi.org\/10.1007\/978-3-642-22015-9","DOI":"10.1007\/978-3-642-22015-9"},{"key":"765_CR14","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1613\/jair.4992","volume":"57","author":"Y Goldberg","year":"2016","unstructured":"Goldberg, Y.: A primer on neural network models for natural language processing. J. Artif. Intell. Res. 57, 345\u2013420 (2016)","journal-title":"J. Artif. Intell. Res."},{"key":"765_CR15","doi-asserted-by":"crossref","unstructured":"Goldberg, Y.: Neural network methods in natural language processing. Morgan & Claypool Publishers, (2017)","DOI":"10.1007\/978-3-031-02165-7"},{"key":"765_CR16","doi-asserted-by":"crossref","unstructured":"Huang, X., Kwiatkowska, M., Wang, S., Wu, M.: Safety verification of deep neural networks. In R.\u00a0Majumdar and V.\u00a0Kun\u010dak, editors, Computer Aided Verification, 3\u201329, Cham, (2017). Springer International Publishing","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"765_CR17","unstructured":"Huang, X., Jin, G., Ruan, W.: Verification of Deep Learning, 181\u2013203. Springer Nature Singapore, Singapore (2023)978-981-19-6814-3"},{"issue":"2","key":"765_CR18","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1023\/A:1025794313696","volume":"26","author":"S Kim","year":"2003","unstructured":"Kim, S., Kojima, M.: Exact solutions of some nonconvex quadratic optimization problems via SDP and SOCP relaxations. Comput. Optim. Appl. 26(2), 143\u2013154 (2003)","journal-title":"Comput. Optim. Appl."},{"key":"765_CR19","doi-asserted-by":"publisher","unstructured":"Kim, S., Kojima, M.: Strong duality of a conic optimization problem with a single hyperplane and two cone constraints. Optimization, 1\u201321, (2023). https:\/\/doi.org\/10.1080\/02331934.2023.2251987","DOI":"10.1080\/02331934.2023.2251987"},{"key":"765_CR20","unstructured":"K\u0131l\u0131n\u00e7-Karzan, F., Wang, A.L.: Exactness in sdp relaxations of qcqps: Theory and applications. arXiv:2107.06885, (2021)"},{"key":"765_CR21","unstructured":"Lomuscio, A., Maganti, L.: An approach to reachability analysis for feed-forward relu neural networks (2017). arXiv preprint at arXiv:1706.07351, (2017)"},{"key":"765_CR22","doi-asserted-by":"crossref","unstructured":"Luo, Z.-Q., Chang, T.-H.: SDP relaxation of homogeneous quadratic optimization: approximation bounds and applications, 117\u2013165. Cambridge University Press, (2009)","DOI":"10.1017\/CBO9780511804458.005"},{"key":"765_CR23","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In Proceedings of the IEEE conference on computer vision and pattern recognition, 1765\u20131773, (2017)","DOI":"10.1109\/CVPR.2017.17"},{"key":"765_CR24","doi-asserted-by":"crossref","unstructured":"Newton, M., Papachristodoulou, A.: Neural network verification using polynomial optimisation. In 2021 60th IEEE Conference on Decision and Control (CDC), 5092\u20135097. IEEE, (2021)","DOI":"10.1109\/CDC45484.2021.9683286"},{"key":"765_CR25","unstructured":"Salman, H., Yang, G., Zhang, H., Hsieh, C.-J., Zhang, P.: A convex relaxation barrier to tight robustness verification of neural networks. Advances in Neural Information Processing Systems, 32, (2019)"},{"issue":"4","key":"765_CR26","doi-asserted-by":"publisher","first-page":"1746","DOI":"10.1137\/130915261","volume":"24","author":"S Sojoudi","year":"2014","unstructured":"Sojoudi, S., Lavaei, J.: Exactness of semidefinite relaxations for nonlinear optimization problems with underlying graph structure. SIAM J. Optim. 24(4), 1746\u20131778 (2014). https:\/\/doi.org\/10.1137\/130915261","journal-title":"SIAM J. Optim."},{"issue":"5","key":"765_CR27","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su, J., Vargas, D.V., Sakurai, K.: One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. 23(5), 828\u2013841 (2019)","journal-title":"IEEE Trans. Evol. Comput."},{"key":"765_CR28","unstructured":"Tjeng, V., Xiao, K., Tedrake, R.: Evaluating robustness of neural networks with mixed integer programming. arXiv Preprint at arXiv:1711.07356, (2017)"},{"key":"765_CR29","doi-asserted-by":"publisher","DOI":"10.1007\/s10107-020-01589-9","author":"AL Wang","year":"2021","unstructured":"Wang, A.L., K\u0131l\u0131n\u00e7-Karzan, F.: On the tightness of SDP relaxations of QCQPs. Math. Program. (2021). https:\/\/doi.org\/10.1007\/s10107-020-01589-9","journal-title":"Math. Program."},{"key":"765_CR30","unstructured":"Wong, E., Kolter, Z.: Provable defenses against adversarial examples via the convex outer adversarial polytope. In International conference on machine learning, 5286\u20135295. PMLR, (2018)"},{"key":"765_CR31","unstructured":"Zhang, R.: On the tightness of semidefinite relaxations for certifying robustness to adversarial examples. In H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.\u00a0Balcan, and H.\u00a0Lin, editors, Advances in Neural Information Processing Systems, volume\u00a033, 3808\u20133820. Curran Associates, Inc., (2020). https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/27b587bbe83aecf9a98c8fe6ab48cacc-Paper.pdf"}],"container-title":["Computational Optimization and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10589-026-00765-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10589-026-00765-5","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10589-026-00765-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T08:05:00Z","timestamp":1777968300000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10589-026-00765-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,16]]},"references-count":31,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,5]]}},"alternative-id":["765"],"URL":"https:\/\/doi.org\/10.1007\/s10589-026-00765-5","relation":{},"ISSN":["0926-6003","1573-2894"],"issn-type":[{"value":"0926-6003","type":"print"},{"value":"1573-2894","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,16]]},"assertion":[{"value":"14 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 January 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 February 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no Conflict of interest or Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}