{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T17:41:19Z","timestamp":1772300479968,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":59,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,7,12]],"date-time":"2023-07-12T00:00:00Z","timestamp":1689120000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,7,12]]},"DOI":"10.1145\/3597926.3598127","type":"proceedings-article","created":{"date-parts":[[2023,7,13]],"date-time":"2023-07-13T20:12:53Z","timestamp":1689279173000},"page":"1182-1194","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["A Tale of Two Approximations: Tightening Over-Approximation for DNN Robustness Verification via Under-Approximation"],"prefix":"10.1145","author":[{"given":"Zhiyi","family":"Xue","sequence":"first","affiliation":[{"name":"East China Normal University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Si","family":"Liu","sequence":"additional","affiliation":[{"name":"ETH Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhaodi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Chengdu Education Research Institute, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yiting","family":"Wu","sequence":"additional","affiliation":[{"name":"East China Normal University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Min","family":"Zhang","sequence":"additional","affiliation":[{"name":"East China Normal University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,7,13]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Apollo. 2017. ApolloAuto. https:\/\/github.com\/ApolloAuto\/apollo Accessed: 2022-05-06 Apollo. 2017. ApolloAuto. https:\/\/github.com\/ApolloAuto\/apollo Accessed: 2022-05-06"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360544"},{"key":"e_1_3_2_1_3_1","volume-title":"Davide Del Testa","author":"Bojarski Mariusz","year":"2016","unstructured":"Mariusz Bojarski , Davide Del Testa , Daniel Dworakowski, Bernhard Firner , Beat Flepp, Prasoon Goyal, Lawrence D. Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, Xin Zhang, Jake Zhao, and Karol Zieba. 2016 . End to End Learning for Self-Driving Cars. CoRR , abs\/1604.07316 (2016), https:\/\/doi.org\/10.48550\/arXiv.1604.07316 arxiv:1604.07316. 10.48550\/arXiv.1604.07316 Mariusz Bojarski, Davide Del Testa, Daniel Dworakowski, Bernhard Firner, Beat Flepp, Prasoon Goyal, Lawrence D. Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, Xin Zhang, Jake Zhao, and Karol Zieba. 2016. End to End Learning for Self-Driving Cars. CoRR, abs\/1604.07316 (2016), https:\/\/doi.org\/10.48550\/arXiv.1604.07316 arxiv:1604.07316."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_5_1","volume-title":"Adversarial Attacks and Defences: A Survey. CoRR, abs\/1810.00069","author":"Chakraborty Anirban","year":"2018","unstructured":"Anirban Chakraborty , Manaar Alam , Vishal Dey , Anupam Chattopadhyay , and Debdeep Mukhopadhyay . 2018. Adversarial Attacks and Defences: A Survey. CoRR, abs\/1810.00069 ( 2018 ), https:\/\/doi.org\/10.48550\/arXiv.1810.00069 10.48550\/arXiv.1810.00069 Anirban Chakraborty, Manaar Alam, Vishal Dey, Anupam Chattopadhyay, and Debdeep Mukhopadhyay. 2018. Adversarial Attacks and Defences: A Survey. CoRR, abs\/1810.00069 (2018), https:\/\/doi.org\/10.48550\/arXiv.1810.00069"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-53288-8_3"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510232"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00058"},{"key":"e_1_3_2_1_9_1","volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR\u201915)","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR\u201915) . Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR\u201915)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3264835"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-30823-9_11"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.3034721"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.3233\/FAIA200385"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1419"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534373"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270"},{"key":"e_1_3_2_1_17_1","volume-title":"They Are Features. In Advances in Neural Information Processing Systems (NeurIPS\u201919). Curran Associates","author":"Ilyas Andrew","unstructured":"Andrew Ilyas , Shibani Santurkar , Dimitris Tsipras , Logan Engstrom , Brandon Tran , and Aleksander Madry . 2019. Adversarial Examples Are Not Bugs , They Are Features. In Advances in Neural Information Processing Systems (NeurIPS\u201919). Curran Associates , Inc., New York, NY, USA. 125\u2013136. Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial Examples Are Not Bugs, They Are Features. In Advances in Neural Information Processing Systems (NeurIPS\u201919). Curran Associates, Inc., New York, NY, USA. 125\u2013136."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_1_19_1","unstructured":"Alex Krizhevsky and Geoffrey Hinton. 2009. Learning Multiple Layers of Features from Tiny Images. Alex Krizhevsky and Geoffrey Hinton. 2009. Learning Multiple Layers of Features from Tiny Images."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397346"},{"key":"e_1_3_2_1_22_1","volume-title":"Advances in Neural Information Processing Sys- tems (NeurIPS\u201920). Curran Associates","author":"Lee Sungyoon","unstructured":"Sungyoon Lee , Jaewook Lee , and Saerom Park . 2020. Lipschitz-Certifiable Training with a Tight Outer Bound . In Advances in Neural Information Processing Sys- tems (NeurIPS\u201920). Curran Associates , Inc ., 16891\u201316902. Sungyoon Lee, Jaewook Lee, and Saerom Park. 2020. Lipschitz-Certifiable Training with a Tight Outer Bound. In Advances in Neural Information Processing Sys- tems (NeurIPS\u201920). Curran Associates, Inc., 16891\u201316902."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01168"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1561\/2400000035"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510231"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5944"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498704"},{"key":"#cr-split#-e_1_3_2_1_29_1.1","unstructured":"Mark Niklas M\u00fcller Christopher Brix Stanley Bak Changliu Liu and Taylor T Johnson. 2022. The Third International Verification of Neural Networks Competition (VNN-COMP'22): Summary and Results. arXiv preprint arXiv:2212.10376 https:\/\/doi.org\/10.48550\/arXiv.2212.10376 10.48550\/arXiv.2212.10376"},{"key":"#cr-split#-e_1_3_2_1_29_1.2","unstructured":"Mark Niklas M\u00fcller Christopher Brix Stanley Bak Changliu Liu and Taylor T Johnson. 2022. The Third International Verification of Neural Networks Competition (VNN-COMP'22): Summary and Results. arXiv preprint arXiv:2212.10376 https:\/\/doi.org\/10.48550\/arXiv.2212.10376"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377812.3382175"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-13185-1_8"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-99524-9_19"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14295-6_24"},{"key":"e_1_3_2_1_35_1","volume-title":"An Overview of Gradient Descent Optimization Algorithms. CoRR, abs\/1609.04747","author":"Ruder Sebastian","year":"2016","unstructured":"Sebastian Ruder . 2016. An Overview of Gradient Descent Optimization Algorithms. CoRR, abs\/1609.04747 ( 2016 ). Sebastian Ruder. 2016. An Overview of Gradient Descent Optimization Algorithms. CoRR, abs\/1609.04747 (2016)."},{"key":"e_1_3_2_1_36_1","volume-title":"Annual Conference on Neural Information Processing Systems (NeurIPS\u201919)","author":"Salman Hadi","year":"2019","unstructured":"Hadi Salman , Greg Yang , Huan Zhang , Cho-Jui Hsieh , and Pengchuan Zhang . 2019 . A Convex Relaxation Barrier to Tight Robustness Verification of Neural Networks . In Annual Conference on Neural Information Processing Systems (NeurIPS\u201919) . Curran Associates, Inc., New York, NY, USA. 9832\u20139842. Hadi Salman, Greg Yang, Huan Zhang, Cho-Jui Hsieh, and Pengchuan Zhang. 2019. A Convex Relaxation Barrier to Tight Robustness Verification of Neural Networks. In Annual Conference on Neural Information Processing Systems (NeurIPS\u201919). Curran Associates, Inc., New York, NY, USA. 9832\u20139842."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290354"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion.2019.00134"},{"key":"e_1_3_2_1_39_1","volume-title":"DeepID3: Face Recognition with Very Deep Neural Networks. CoRR, abs\/1502.00873","author":"Sun Yi","year":"2015","unstructured":"Yi Sun , Ding Liang , Xiaogang Wang , and Xiaoou Tang . 2015. DeepID3: Face Recognition with Very Deep Neural Networks. CoRR, abs\/1502.00873 ( 2015 ). Yi Sun, Ding Liang, Xiaogang Wang, and Xiaoou Tang. 2015. DeepID3: Face Recognition with Very Deep Neural Networks. CoRR, abs\/1502.00873 (2015)."},{"key":"e_1_3_2_1_40_1","volume-title":"Intriguing Properties of Neural Networks. In International Conference on Learning Representations (ICLR\u201914)","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian J. Goodfellow , and Rob Fergus . 2014 . Intriguing Properties of Neural Networks. In International Conference on Learning Representations (ICLR\u201914) . https:\/\/doi.org\/10.48550\/arXiv.1312.6199 10.48550\/arXiv.1312.6199 Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing Properties of Neural Networks. In International Conference on Learning Representations (ICLR\u201914). https:\/\/doi.org\/10.48550\/arXiv.1312.6199"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-018-0147-y"},{"key":"e_1_3_2_1_42_1","volume-title":"The Convex Relaxation Barrier","author":"Tjandraatmadja Christian","unstructured":"Christian Tjandraatmadja , Ross Anderson , Joey Huchette , Will Ma , Krunal Patel , and Juan Pablo Vielma . 2020. The Convex Relaxation Barrier , Revisited : Tightened Single-Neuron Relaxations for Neural Network Verification. In Advances in Neural Information Processing Systems (NeurIPS\u201920). Curran Associates, Inc., New York, NY, USA. 21675\u201321686. Christian Tjandraatmadja, Ross Anderson, Joey Huchette, Will Ma, Krunal Patel, and Juan Pablo Vielma. 2020. The Convex Relaxation Barrier, Revisited: Tightened Single-Neuron Relaxations for Neural Network Verification. In Advances in Neural Information Processing Systems (NeurIPS\u201920). Curran Associates, Inc., New York, NY, USA. 21675\u201321686."},{"key":"e_1_3_2_1_43_1","volume-title":"USENIX Security\u201918","author":"Wang Shiqi","unstructured":"Shiqi Wang , Kexin Pei , Justin Whitehouse , Junfeng Yang , and Suman Jana . 2018. Formal Security Analysis of Neural Networks using Symbolic Intervals . In USENIX Security\u201918 . USENIX Association , Baltimore, MD . 1599\u20131614. Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana. 2018. Formal Security Analysis of Neural Networks using Symbolic Intervals. In USENIX Security\u201918. USENIX Association, Baltimore, MD. 1599\u20131614."},{"key":"e_1_3_2_1_44_1","volume-title":"Proceedings of the 5th Conference on Robot Learning (ICRL\u201921)","author":"Wang Tai","year":"2022","unstructured":"Tai Wang , Xinge Zhu , Jiangmiao Pang , and Dahua Lin . 2022 . Probabilistic and Geometric Depth: Detecting Objects in Perspective . In Proceedings of the 5th Conference on Robot Learning (ICRL\u201921) . 164, PMLR, 1475\u20131485. Tai Wang, Xinge Zhu, Jiangmiao Pang, and Dahua Lin. 2022. Probabilistic and Geometric Depth: Detecting Objects in Perspective. In Proceedings of the 5th Conference on Robot Learning (ICRL\u201921). 164, PMLR, 1475\u20131485."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498675"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448248"},{"key":"e_1_3_2_1_47_1","volume-title":"International Conference on Machine Learning (ICML\u201918)","author":"Wong Eric","unstructured":"Eric Wong and J. Zico Kolter . 2018. Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope . In International Conference on Machine Learning (ICML\u201918) . PMLR, 5283\u20135292. Eric Wong and J. Zico Kolter. 2018. Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope. In International Conference on Machine Learning (ICML\u201918). PMLR, 5283\u20135292."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00039"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i13.17388"},{"key":"e_1_3_2_1_50_1","volume-title":"Fashion-MNIST: A Novel Image Dataset for Benchmarking Machine Learning Algorithms. CoRR, abs\/1708.07747","author":"Xiao Han","year":"2017","unstructured":"Han Xiao , Kashif Rasul , and Roland Vollgraf . 2017. Fashion-MNIST: A Novel Image Dataset for Benchmarking Machine Learning Algorithms. CoRR, abs\/1708.07747 ( 2017 ), https:\/\/doi.org\/10.48550\/arXiv.1708.07747 10.48550\/arXiv.1708.07747 Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017. Fashion-MNIST: A Novel Image Dataset for Benchmarking Machine Learning Algorithms. CoRR, abs\/1708.07747 (2017), https:\/\/doi.org\/10.48550\/arXiv.1708.07747"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.6084\/m9.figshare.23173448"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Zhiyi Xue Si Liu Zhaodi Zhang Yiting Wu and Min Zhang. 2023. A Tale of Two Approximations: Tightening Over-Approximation for DNN Robustness Verification via Under-Approximation. arxiv:2305.16998 Zhiyi Xue Si Liu Zhaodi Zhang Yiting Wu and Min Zhang. 2023. A Tale of Two Approximations: Tightening Over-Approximation for DNN Robustness Verification via Under-Approximation. arxiv:2305.16998","DOI":"10.1145\/3597926.3598127"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3156620"},{"key":"e_1_3_2_1_54_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS\u201922). Curran Associates","author":"Zhang Huan","unstructured":"Huan Zhang , Shiqi Wang , Kaidi Xu , Linyi Li , Bo Li , Suman Jana , Cho-Jui Hsieh , and J Zico Kolter . 2022. General Cutting Planes for Bound-Propagation-Based Neural Network Verification . In Advances in Neural Information Processing Systems (NeurIPS\u201922). Curran Associates , Inc., New York, NY, USA. 1656\u20131670. Huan Zhang, Shiqi Wang, Kaidi Xu, Linyi Li, Bo Li, Suman Jana, Cho-Jui Hsieh, and J Zico Kolter. 2022. General Cutting Planes for Bound-Propagation-Based Neural Network Verification. In Advances in Neural Information Processing Systems (NeurIPS\u201922). Curran Associates, Inc., New York, NY, USA. 1656\u20131670."},{"key":"e_1_3_2_1_55_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS\u201918). Curran Associates","author":"Zhang Huan","unstructured":"Huan Zhang , Tsui-Wei Weng , Pin-Yu Chen , Cho-Jui Hsieh , and Luca Daniel . 2018. Efficient Neural Network Robustness Certification with General Activation Functions . In Advances in Neural Information Processing Systems (NeurIPS\u201918). Curran Associates , Inc., New York, NY, USA. 4944\u20134953. Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel. 2018. Efficient Neural Network Robustness Certification with General Activation Functions. In Advances in Neural Information Processing Systems (NeurIPS\u201918). Curran Associates, Inc., New York, NY, USA. 4944\u20134953."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409720"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556907"},{"key":"e_1_3_2_1_58_1","volume-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR\u201923)","author":"Zhang Zhaodi","year":"2023","unstructured":"Zhaodi Zhang , Zhiyi Xue , Yang Chen , Si Liu , Yueling Zhang , Jing Liu , and Min Zhang . 2023 . Boosting Verified Training for Robust Image Classifications via Abstraction . In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR\u201923) . IEEE. https:\/\/doi.org\/10.48550\/arXiv.2303.11552 10.48550\/arXiv.2303.11552 Zhaodi Zhang, Zhiyi Xue, Yang Chen, Si Liu, Yueling Zhang, Jing Liu, and Min Zhang. 2023. Boosting Verified Training for Robust Image Classifications via Abstraction. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR\u201923). IEEE. https:\/\/doi.org\/10.48550\/arXiv.2303.11552"}],"event":{"name":"ISSTA '23: 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis","location":"Seattle WA USA","acronym":"ISSTA '23","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","AITO"]},"container-title":["Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597926.3598127","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597926.3598127","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:48:43Z","timestamp":1750182523000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597926.3598127"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,12]]},"references-count":59,"alternative-id":["10.1145\/3597926.3598127","10.1145\/3597926"],"URL":"https:\/\/doi.org\/10.1145\/3597926.3598127","relation":{},"subject":[],"published":{"date-parts":[[2023,7,12]]},"assertion":[{"value":"2023-07-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}