{"id":"https://openalex.org/W7152061039","doi":"https://doi.org/10.1613/jair.1.18922","title":"ModelStar: Reachability Analysis-based Safety Verification of Neural Networks Against Model Perturbations","display_name":"ModelStar: Reachability Analysis-based Safety Verification of Neural Networks Against Model Perturbations","publication_year":2026,"publication_date":"2026-04-07","ids":{"openalex":"https://openalex.org/W7152061039","doi":"https://doi.org/10.1613/jair.1.18922"},"language":null,"primary_location":{"id":"doi:10.1613/jair.1.18922","is_oa":true,"landing_page_url":"https://doi.org/10.1613/jair.1.18922","pdf_url":"https://www.jair.org/index.php/jair/article/download/18922/27292","source":{"id":"https://openalex.org/S139930977","display_name":"Journal of Artificial Intelligence Research","issn_l":"1076-9757","issn":["1076-9757","1943-5037"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310315760","host_organization_name":"AI Access Foundation","host_organization_lineage":["https://openalex.org/P4310315760"],"host_organization_lineage_names":["AI Access Foundation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Artificial Intelligence Research","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://www.jair.org/index.php/jair/article/download/18922/27292","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5126374195","display_name":"Muhammad Usama Zubair","orcid":null},"institutions":[{"id":"https://openalex.org/I162577319","display_name":"The University of Texas at Dallas","ror":"https://ror.org/049emcs32","country_code":"US","type":"education","lineage":["https://openalex.org/I162577319"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Muhammad Usama Zubair","raw_affiliation_strings":["University of Texas at Dallas, Richardson, TX 75080, USA"],"raw_orcid":"https://orcid.org/0000-0002-0031-8671","affiliations":[{"raw_affiliation_string":"University of Texas at Dallas, Richardson, TX 75080, USA","institution_ids":["https://openalex.org/I162577319"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067901159","display_name":"Taylor T. Johnson","orcid":"https://orcid.org/0000-0001-8021-9923"},"institutions":[{"id":"https://openalex.org/I200719446","display_name":"Vanderbilt University","ror":"https://ror.org/02vm5rt34","country_code":"US","type":"education","lineage":["https://openalex.org/I200719446"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Taylor T. Johnson","raw_affiliation_strings":["Vanderbilt University, Nashville, TN 37212 USA"],"raw_orcid":"https://orcid.org/0000-0001-8021-9923","affiliations":[{"raw_affiliation_string":"Vanderbilt University, Nashville, TN 37212 USA","institution_ids":["https://openalex.org/I200719446"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066320524","display_name":"Kanad Basu","orcid":"https://orcid.org/0000-0002-6431-7512"},"institutions":[{"id":"https://openalex.org/I162577319","display_name":"The University of Texas at Dallas","ror":"https://ror.org/049emcs32","country_code":"US","type":"education","lineage":["https://openalex.org/I162577319"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kanad Basu","raw_affiliation_strings":["University of Texas at Dallas, Richardson, TX 75080, USA"],"raw_orcid":"https://orcid.org/0000-0002-6431-7512","affiliations":[{"raw_affiliation_string":"University of Texas at Dallas, Richardson, TX 75080, USA","institution_ids":["https://openalex.org/I162577319"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5041744190","display_name":"Waseem Abbas","orcid":"https://orcid.org/0000-0002-9013-1463"},"institutions":[{"id":"https://openalex.org/I162577319","display_name":"The University of Texas at Dallas","ror":"https://ror.org/049emcs32","country_code":"US","type":"education","lineage":["https://openalex.org/I162577319"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Waseem Abbas","raw_affiliation_strings":["University of Texas at Dallas, Richardson, TX 75080, USA"],"raw_orcid":"https://orcid.org/0000-0002-9013-1463","affiliations":[{"raw_affiliation_string":"University of Texas at Dallas, Richardson, TX 75080, USA","institution_ids":["https://openalex.org/I162577319"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5126374195"],"corresponding_institution_ids":["https://openalex.org/I162577319"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.60446249,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"85","issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9905999898910522,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9905999898910522,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.0010999999940395355,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.0010000000474974513,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/reachability","display_name":"Reachability","score":0.9176999926567078},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.8798999786376953},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.6941999793052673},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.6370000243186951},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.48829999566078186},{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.4810999929904938},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.3991999924182892}],"concepts":[{"id":"https://openalex.org/C136643341","wikidata":"https://www.wikidata.org/wiki/Q1361526","display_name":"Reachability","level":2,"score":0.9176999926567078},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.8798999786376953},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8072999715805054},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.6941999793052673},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.6370000243186951},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5012999773025513},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.48829999566078186},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.4810999929904938},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4480000138282776},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.3991999924182892},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.3659000098705292},{"id":"https://openalex.org/C155032097","wikidata":"https://www.wikidata.org/wiki/Q798503","display_name":"Backpropagation","level":3,"score":0.34549999237060547},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.33739998936653137},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.30489999055862427},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.30169999599456787},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.2962999939918518},{"id":"https://openalex.org/C50897621","wikidata":"https://www.wikidata.org/wiki/Q2665508","display_name":"Hybrid system","level":2,"score":0.2621999979019165},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2614000141620636},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.25189998745918274}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1613/jair.1.18922","is_oa":true,"landing_page_url":"https://doi.org/10.1613/jair.1.18922","pdf_url":"https://www.jair.org/index.php/jair/article/download/18922/27292","source":{"id":"https://openalex.org/S139930977","display_name":"Journal of Artificial Intelligence Research","issn_l":"1076-9757","issn":["1076-9757","1943-5037"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310315760","host_organization_name":"AI Access Foundation","host_organization_lineage":["https://openalex.org/P4310315760"],"host_organization_lineage_names":["AI Access Foundation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Artificial Intelligence Research","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1613/jair.1.18922","is_oa":true,"landing_page_url":"https://doi.org/10.1613/jair.1.18922","pdf_url":"https://www.jair.org/index.php/jair/article/download/18922/27292","source":{"id":"https://openalex.org/S139930977","display_name":"Journal of Artificial Intelligence Research","issn_l":"1076-9757","issn":["1076-9757","1943-5037"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310315760","host_organization_name":"AI Access Foundation","host_organization_lineage":["https://openalex.org/P4310315760"],"host_organization_lineage_names":["AI Access Foundation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Artificial Intelligence Research","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1331140855","display_name":null,"funder_award_id":"2325416","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G2668951283","display_name":null,"funder_award_id":"2220401","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4151934984","display_name":null,"funder_award_id":"2220426","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4713059963","display_name":null,"funder_award_id":"FA8750","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"},{"id":"https://openalex.org/G5725600090","display_name":null,"funder_award_id":"FA8750-23-C-0518","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"},{"id":"https://openalex.org/F4320332815","display_name":"Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7152061039.pdf","grobid_xml":"https://content.openalex.org/works/W7152061039.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"widespread":[1],"adoption":[2],"of":[3,66,82,86,148],"deep":[4],"neural":[5,31,135],"network":[6,32,136],"(DNN)-based":[7],"learning":[8],"systems":[9],"in":[10,24,30,134,144,150],"safety-critical":[11,152],"applications":[12],"requires":[13],"exceptional":[14],"reliability.":[15],"However,":[16],"this":[17],"reliability":[18,147],"could":[19],"be":[20],"compromised":[21],"by":[22,35],"perturbations":[23],"model":[25],"parameters,":[26],"such":[27],"as":[28],"variations":[29,88],"weights":[33],"caused":[34],"hardware":[36],"vulnerabilities":[37],"and":[38,46],"environmental":[39],"factors,":[40],"which":[41],"can":[42],"lead":[43],"to":[44,62,78,111,120,128],"mispredictions":[45],"compromise":[47],"system":[48],"safety.":[49],"To":[50],"address":[51],"this,":[52],"we":[53],"propose":[54],"\u2018ModelStar\u2019,":[55],"an":[56,83],"innovative":[57],"framework":[58],"leveraging":[59],"reachability":[60],"analysis":[61,94],"evaluate":[63],"the":[64,80,132,146],"robustness":[65,102,108],"DNNs":[67,149],"against":[68],"weight":[69],"perturbations.":[70],"ModelStar":[71,97,124],"employs":[72],"a":[73],"linear":[74],"set":[75],"propagation":[76],"technique":[77],"analyze":[79],"impact":[81],"infinite":[84],"family":[85],"parameter":[87],"on":[89],"DNN":[90,107],"outputs.":[91],"Our":[92],"comprehensive":[93],"demonstrates":[95],"that":[96],"not":[98],"only":[99],"establishes":[100],"tighter":[101],"bounds":[103],"but":[104],"also":[105],"verifies":[106],"for":[109],"up":[110],"60%":[112],"more":[113],"samples":[114],"from":[115],"image":[116],"classification":[117],"datasets":[118],"compared":[119],"existing":[121],"methods.":[122],"Furthermore,":[123],"extends":[125],"safety":[126,137],"verification":[127],"convolutional":[129],"layers,":[130],"advancing":[131],"state-of-the-art":[133],"verification.":[138],"These":[139],"results":[140],"highlight":[141],"ModelStar\u2019s":[142],"efficacy":[143],"improving":[145],"real-world,":[151],"scenarios.":[153]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-04-09T00:00:00"}
