{"paper":{"title":"Precise Verification of Transformers through ReLU-Catalyzed Abstraction Refinement","license":"http://creativecommons.org/licenses/by/4.0/","headline":"ReLU encoding of dot-product ranges enables tighter convex bounds for precise transformer verification.","cross_cats":["cs.LG"],"primary_cat":"cs.AI","authors_text":"Hengjie Liu, Jianjun Zhao, Zhenya Zhang","submitted_at":"2026-05-14T02:55:53Z","abstract_excerpt":"Formal verification of transformers has become increasingly important due to their widespread deployment in safety-critical applications. Compared to classic neural networks, the inferences of transformers involve highly complex computations, such as dot products in self-attention layers, rendering their verification extremely difficult. Existing approaches explored over-approximation methods by constructing convex constraints to bound the output ranges of transformers, which can achieve high efficiency. However, they may sacrifice verification precision, and consequently introduce significant"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"we propose a transformer verification approach that can achieve improved precision... by representing a precise but non-linear bound for dot products such that we can further exploit the rich body of literature for convex relaxation of ReLU to derive precise bounds.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the ReLU encoding of dot-product ranges remains tractable for convex relaxation and that the resulting bounds are tight enough to meaningfully reduce false alarms on the evaluated model sizes and properties.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"A ReLU-catalyzed abstraction method yields tighter bounds for transformer verification by converting dot-product constraints into ReLU forms that leverage standard convex relaxations.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"ReLU encoding of dot-product ranges enables tighter convex bounds for precise transformer verification.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"01ecd2c9b2580ee639ea2ea8da342a8a05bd0bfa45f8d5340d4f357fe7ddaebe"},"source":{"id":"2605.14294","kind":"arxiv","version":1},"verdict":{"id":"ef8bad98-1e84-4e9f-b5dc-183f0cb827f3","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-15T02:31:52.684904Z","strongest_claim":"we propose a transformer verification approach that can achieve improved precision... by representing a precise but non-linear bound for dot products such that we can further exploit the rich body of literature for convex relaxation of ReLU to derive precise bounds.","one_line_summary":"A ReLU-catalyzed abstraction method yields tighter bounds for transformer verification by converting dot-product constraints into ReLU forms that leverage standard convex relaxations.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the ReLU encoding of dot-product ranges remains tractable for convex relaxation and that the resulting bounds are tight enough to meaningfully reduce false alarms on the evaluated model sizes and properties.","pith_extraction_headline":"ReLU encoding of dot-product ranges enables tighter convex bounds for precise transformer verification."},"references":{"count":39,"sample":[{"doi":"10.18653/v1/d18-1316","year":2018,"title":"Alzantot, M., Sharma, Y., Elgohary, A., Ho, B.J., Srivastava, M., Chang, K.W.: Generating natural language adversarial examples. In: Riloff, E., Chiang, D., Hocken- maier, J., Tsujii, J. (eds.) Procee","work_id":"178ae929-ee76-462f-803a-eb9692c82dee","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.18653/v1/2021.insights-1.18","year":2021,"title":"In: Sedoc, J., Rogers, A., Rumshisky, A., Tafreshi, S","work_id":"1c1c4369-ee00-46d5-99c0-c9512eb150bc","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.1145/3453483.3454056","year":2021,"title":"Lee, and Brandon Reagen","work_id":"c488edc9-9b8a-4531-a56d-afee25c6b6d3","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.1145/3617508","year":2024,"title":"Boudardara, F., Boussif, A., Meyer, P.J., Ghazel, M.: A review of abstraction methods toward verifying neural networks. ACM Trans. Embed. Comput. Syst. 23(4) (Jun 2024). https://doi.org/10.1145/361750","work_id":"54f332c1-e698-4bd6-9f3c-96d6dba439b9","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.48550/arxiv","year":2024,"title":"URLhttps://doi.org/10.48550/arXiv","work_id":"5c2060c6-427c-4321-be22-49ccae439d80","ref_index":5,"cited_arxiv_id":"2203.14987","is_internal_anchor":true}],"resolved_work":39,"snapshot_sha256":"92da5dace88b78f79caa31ec002320d15769472cbcfc7fb91d06472266fba510","internal_anchors":2},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"}