\label{introduction}

Neural ordinary differential equations (neural ODE) are gaining prominence in continuous-time modeling, offering distinct advantages over traditional neural networks, such as memory efficiency, continuous-time modeling, adaptive computation balancing speed and accuracy~\cite{chen2018neural,kidger2022neuraldifferentialequations,oh2025comprehensive}. This surge in interest stems from recent advancements in differential programming, which have enhanced the ability to model complex dynamics with greater flexibility and precision~\cite{rackauckas2021universaldifferentialequationsscientific}. 

Neural ODE can be viewed as a continuous-depth generalization of residual networks (ResNet)~\cite{he2015deepresiduallearningimage}, and conversely a ResNet represents an Euler discretization of the continuous transformations modeled by a neural ODE~\cite{Haber_2017,lu2020finitelayerneuralnetworks}. 
Unlike ResNet, neural ODE enable smooth and robust representations through continuous dynamics, leading to improved modeling of time-evolving systems~\cite{chen2018neural,Haber_2017}. By interpreting ResNet as discretized neural ODE, we can leverage advanced ODE solvers to enhance computational efficiency and reduce the number of required parameters~\cite{chen2018neural}. Furthermore, the continuous formulation of neural ODE supports flexible handling of varying input resolutions and scales, making them adaptable to diverse data modalities. This perspective also facilitates theoretical analysis using tools from differential equations, providing insights into network stability and convergence~\cite{kidger2022neuraldifferentialequations}.

Despite the growing interest in neural ODE for continuous-time modeling, formal analysis techniques for these models remain underdeveloped~\cite{lopez2022reachabilityanalysisgeneralclass}. Current verification methods for neural ODE are still maturing, with existing reachability approaches primarily focusing on stochastic methods~\cite{gruenbacher2020verificationneuralodesstochastic,gruenbacher2021gotubescalablestochasticverification}. Other works include the NNVODE tool~\cite{lopez2022reachabilityanalysisgeneralclass} which is an extension of the Neural Network Verification (NNV) framework~\cite{tran2020nnvneuralnetworkverification,lopez2023nnv} that investigates reachability for a general class of neural ODE.
Additionally, another line of verification based on topological properties was introduced in~\cite{liang2022safetyverificationneuralnetworks} through a set-boundary method for safety verification of neural ODE and invertible residual networks (i-ResNet)~\cite{behrmann2019invertibleresidualnetworks}. 

The similarity between the neural ODE and ResNet models enables bidirectional safety verification, where the properties verified for one model can be used to deduce safety guarantees for the other one. This motivates our work, which investigates how verification results from one model can serve as a proxy for the other, addressing practical scenarios where only one model or compatible verification tools are available.
The main contributions of this work are as follows:
\renewcommand{\labelitemi}{$\bullet$}
\begin{itemize}
    \item We derive a rigorous bound on the approximation error between the neural ODE and ResNet models for a given input set.
    \item We use the derived error bound in conjunction with the reachable set of one model as a proxy to verify safety properties of the other model, without applying any verification tools to the other model as illustrated in Figure~\ref{fig:framework}.
\end{itemize}

\begin{figure}[htb]
    \centering
    \includegraphics[width=\columnwidth]{figures/Framework.pdf}
    \caption{Illustration of the proposed framework to verify Model $1$ based on the outcome of the verification of Model $2$ and a bound $\varepsilon$ on the maximal error between the models.}
    \label{fig:framework}
\end{figure}

\paragraph{Related work.}  
Although the similarity between the ResNet and neural ODE models is well established~\cite{chen2018neural,kidger2022neuraldifferentialequations}, to the best of our knowledge, very few works have tried connecting these models through some more formal relationships.
These include various theoretical perspectives, such as quantifying the deviation between the hidden state trajectory of a ResNet and its corresponding neural ODE, focusing on approximation error~\cite{sander2022residualneuralnetworksdiscretize}, while~\cite{marion2023generalizationboundsneuralordinary} derives generalization bounds for neural ODE and ResNet using a Lipschitz-based argument, emphasizing the impact of successive weight matrix differences on generalization capability. On the other hand,~\cite{marion2024implicitregularizationdeepresidual} investigates implicit regularization effects in deep ResNet and its impact on training outcomes. While these studies focus on theoretical analyses of approximation error, generalization, and regularization to understand model behavior and performance, our work leverages this relationship for formal safety verification. We propose a verification proxy approach that uses the reachable set of one model to verify the safety properties of the other, incorporating an error bound to ensure conservative over-approximations, which enables practical verification of nonlinear systems.

Abstraction-based verification (i.e.,\ verifying properties of one model by working on an abstraction of its behaviors into a simpler model) has been a popular topic in the past decades outside of the AI field~\cite{tabuada2009verification}. Within the field of AI verification, its primary application has been on abstracting specific model components rather than the whole model itself, as in approaches based on convex relaxation of nonlinear ReLU activation functions~\cite{katz2017reluplex,huang2017safety}.
On the other hand, full-model abstraction has been mostly unexplored for AI verification, except on the topic of neural network model reduction, where the verification of a neural network is achieved at a lower computational cost on a reduced network with less neurons, see e.g.~\cite{boudardara2023innabstract} for unidirectional relationships, or~\cite{xiang2022approximatebisimulationrelationsneural} for bidirectional ones through the use of approximate bisimulation relations.
Although the overall principle of the proposed approach in our paper is similar (abstracting a model by one that over-approximates the set of all its behaviors), the main difference with the above works between two discrete neural networks is that our paper considers the formal relationships between a continuous neural ODE model and a discrete ResNet one.

\paragraph{Organization of the paper.}
The remainder of the paper is structured as follows. First, we formulate the safety verification problem of interest and provide some preliminaries in Section~\ref{section:preliminaries}. In Section~\ref{section:error}, we describe our proposed approach to bound the approximation error between the ResNet and neural ODE models, and use this error bound to verify the safety of one model based on the reachability analysis of the other. Following this, we provide numerical illustrations of our error bounding and verification proxy results (in both directions: from ResNet to neural ODE, and from neural ODE to ResNet) on an academic example in Section~\ref{section:expirements}. Finally, we summarize the main findings of the paper and discuss potential future work in Section~\ref{section:conclusion}.
