SECURECROWN: Private DNN Robustness Verification

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Neural network verification and data privacy are inherently in tension: _verification demands full access to model parameters and input data, yet both are increasingly restricted by privacy regulations and intellectual property constraints_ . This tension has left robustness verification impractical in privacy-sensitive domains. In this work, we address this gap with SECURECROWN, the first framework for privacy-preserving neural network robustness verification. Built upon secure two-party computation (2PC), our framework enables a model owner and a data owner to jointly compute certified robustness boundsrevealing only the final result while provably protecting both parties private data under the semi-honest security model. A key challenge is securely computing the conditional operations in Linear Bound Propagation, where the data-dependent branching is incompatible with standard secure computation protocols. We eliminate branching by formulating conditional logic as continuous arithmetic operations. Additionally, we introduce a NewtonRaphson refinement method to improve numerical stability. Extensive analysis and experiments show that SECURECROWN strictly matches plaintext verification results, while completing in 0.1200s across varied model sizes and communication settings (LAN/WAN), demonstrating the feasibility of privacy-preserving neural network verification.

Loading executive summary...

LINK COPIED TO CLIPBOARD