Research

Our research develops mathematical and computational methods for verifying machine-learning models, autonomous AI agents and neuro-symbolic systems. The work spans foundational specification and model-checking questions, scalable verification algorithms, research software and increasingly complex learning-enabled systems. Alongside foundational work, we have applied these methods to real autonomous and perception systems in marine, automotive and aerospace settings.

For the research group, people and group activities, visit the Safe AI Lab.

Verification of Machine Learning Models

Our research on the verification of machine learning models began in 2015 with methods for reachability analysis of neural networks and neural agent-environment systems. Since then we have developed optimisation-based verification, dependency analysis, symbolic bound propagation, adaptive refinement and splitting methods, with a recurring focus on improving scalability while retaining formal guarantees.

A second major theme is robustness: analysing model behaviour over sets of possible inputs rather than individual examples, including perturbations with geometric or application-level interpretations. This work has progressively extended verification from neural classifiers to richer perception models and tasks.

Recent results address geometric robustness at the scale of large image and video models, formal robustness verification for object localisation, and region-level robustness validation for vision-language and vision-language-action models over continuous photometric and geometric perturbations. The latest work scales this analysis to models with up to 32B parameters. Current research continues towards verification questions connecting multimodal perception with action.

Representative publications

  1. 2017

    An approach to reachability analysis for feed-forward ReLU neural Networks

    arXiv preprint

    Early optimisation-based reachability analysis for ReLU networks.

  2. 2018

    Reachability Analysis for Neural Agent-Environment Systems

    KR 2018

    Extends neural reachability analysis to a learned agent interacting with an environment.

  3. 2020

    Efficient Verification of Neural Networks via Dependency Analysis

    AAAI 2020

    Uses dependencies between activations to strengthen and accelerate verification.

  4. 2021

    DEEPSPLIT: An Efficient Splitting Method for Neural Network Verification via Indirect Effect Analysis

    IJCAI 2021

    Introduces indirect-effect-guided splitting and a more efficient encoding of splitting constraints.

  5. 2025

    Scalable Neural Network Geometric Robustness Validation via Hölder Optimisation

    NeurIPS 2025

    Scalable geometric robustness validation for image and video models, with formal soundness under the conditions stated in the paper.

  6. 2026

    IoUCert: Robustness Verification for anchor-based Object Detectors

    ECCV 2026

    Formal robustness bounds for object localisation in the paper’s stated detector setting.

  7. 2026

    Validating, Not Sampling: Region-Level Robustness of Vision-Language and Vision-Language-Action Models

    arXiv:2609.22293 · preprint

    Deep robustness validation study for SoA VLMs and VLAs against photometric/geometric perturbations scaling to 32B parameters.

All publications

Verification of Autonomous AI Agents

Our research on the verification of autonomous agent systems began in 2000 by defining and exploring their model-checking problem: how to establish formally properties of individual and collective behaviour as agents interact. The specification formalisms include temporal, epistemic and strategic modalities, providing a rich framework for expressing how knowledge, capabilities and behaviour evolve over time.

This led to complementary bounded-model-checking and symbolic model-checking techniques, followed by increasingly sophisticated symbolic algorithms implemented in MCMAS and, subsequently, parameterised verification techniques for systems whose number of agents is not fixed in advance, including methods for verifying emergent behaviour in swarms.

More recently, we have extended these ideas to autonomous agents with learned components, including neural agent-environment systems in non-deterministic settings and agents with memory. Current work focuses on multimodal AI agents and on verification and validation questions arising when AI systems perceive and act in physical environments.

Representative publications

  1. 2003

    Verifying Epistemic Properties of Multi-agent Systems via Bounded Model Checking

    Fundamenta Informaticae 55(2)

    With Wojciech Penczek. SAT-based bounded model checking of temporal-epistemic properties over interpreted systems.

  2. 2006

    Model checking knowledge, strategies, and games in multi-agent systems

    AAMAS 2006

    Model checking specifications combining knowledge and strategic ability.

  3. 2007

    Automatic Verification of Multi-Agent Systems by Model Checking via Ordered Binary Decision Diagrams

    Journal of Applied Logic

    Symbolic OBDD-based model checking for multi-agent systems.

  4. 2015

    Verifying Emergent Properties of Swarms

    IJCAI 2015

    Verification of collective behaviour in systems with varying numbers of agents.

  5. 2016

    Parameterised Verification for Multi-Agent Systems

    Artificial Intelligence

    Verification of families of systems independently of a fixed population size.

  6. 2022

    Formal Verification of Neural Agents in Non-deterministic Environments

    JAAMAS 2022

    Branching-time verification of closed-loop neural agent-environment systems.

  7. 2025

    LTL Verification of Memoryful Neural Agents

    AAMAS 2025

    Temporal verification of neural agents with memory in uncertain and partially observable environments.

All publications

Verification of Neuro-symbolic Systems

Our research on neuro-symbolic systems studies how to verify systems that combine learned components with symbolic or probabilistic reasoning. The verification target is the composed system: how uncertainty or perturbations affecting learned components propagate through reasoning and affect properties of the resulting system.

Earlier work investigated the strategic abilities of neural-symbolic multi-agent systems. Our NeSy 2025 Outstanding Paper Award work developed scalable probabilistic robustness verification, propagating input uncertainty through learned perception and symbolic reasoning. The forthcoming NeurIPS 2026 work extends this line to end-to-end verification of temporal neuro-symbolic systems, certifying trajectory-level decisions across learned perception and symbolic automata.

Representative publications

  1. 2026

    End-to-End Verification of Neuro-symbolic Automata via Contrastive Logit-Gaps

    NeurIPS 2026 · forthcoming
  2. 2025
  3. 2020

All publications

Selected applications

Autonomous underwater systems

Formal verification of fault tolerance, self-diagnosability and recovery for Autosub6000, an autonomous underwater vehicle used for deep-ocean exploration. The work used an engineering Simulink/Stateflow model, automatic fault injection and MCMAS to analyse operation under degraded conditions.

Verification software

MCMAS

MCMAS is an open-source symbolic model checker for multi-agent systems. It enables the verification of multi-agent systems, expressed in the Interpreted Systems Programming Language (ISPL), against temporal, epistemic and strategic specifications. Its algorithms use ordered binary decision diagrams to represent and analyse state spaces, with support for fairness, counterexamples and witness executions. The STTT journal article provides the main account of its semantics, verification algorithms and implementation.

Software and documentation

Venus

Venus is a neural-network verification tool for reachability and robustness properties of ReLU-based networks. It combines mixed-integer optimisation with dependency analysis, bound propagation and splitting methods developed in our work. The tool was one of the software outputs of the DARPA Assured Autonomy effort.

Software and documentation

VeriNet

VeriNet is a neural-network verification tool based on variants of symbolic interval propagation developed in our work, combined with adaptive refinement and adversarial search. A feature of the approach is its iterative bound tightening and support for networks with several activation functions.

Software and documentation

Selected research programmes

2018–2028

Royal Academy of Engineering Chair in Emerging Technologies

Principal Investigator

Research on verification methods for establishing guarantees about autonomous and robotic systems incorporating machine learning.

2019–2027

Centre for Doctoral Training in Safe and Trusted Artificial Intelligence

Founding co-director

Joint programme with King’s College London.

2022–2025

EVENFLOW — Robust Learning and Reasoning for Complex Event Forecasting

Principal Investigator

EU Horizon-funded research on robust learning and reasoning for complex-event forecasting, including formal verification of systems combining learning and symbolic reasoning.

2018–2022

DARPA Assured Autonomy — Verification of Neural Systems

Principal Investigator

Research on mathematical methods and tools for verification of machine-learning systems.

All research programmes and projects