---
title: Critical-Tensor Identification in ViTaX
url: https://www.emergentmind.com/topics/critical-tensor-identification-xai-based-selection
type: topic
---

# Critical-Tensor Identification in ViTaX

Critical-tensor identification is a formal XAI-based feature selection technique introduced in the ViTaX (Verified and Targeted Explanations) framework. It targets the identification of minimal input feature subsets (critical tensors) that are most sensitive to class transitions within deep neural networks, and provides mathematical guarantees about the model’s resilience to perturbations directed toward user-specified alternative classes. In contrast to traditional attribution methods, which lack formal robustness assurances, and generic formal methods, which are untargeted, this approach enables verifiable, targeted, and succinct explanations for high-stakes, safety-critical applications [2604.14209].

## 1. Definition of Critical Tensor

In the ViTaX setting, given an input tensor $x\in\mathbb{R}^{w\times h\times c}$ and a neural classifier $f$, a **critical tensor** $A\subseteq\{1,\ldots,n\}$ (with $n=w\cdot h\cdot c$) is defined as the smallest set of input feature indices such that perturbing $x_A$ by no more than $\varepsilon$ (in a chosen $\ell_p$ norm) cannot flip the classifier's output from a true class $y$ to a specified critical alternative class $t$. Formally, $x_A$ denotes the restriction of the input to indices in $A$. The identification of a critical tensor provides a succinct semifactual explanation: *even if the features indexed by $A$ are perturbed maximally within $\varepsilon$, the classifier remains robust to the transition from $y$ to $t$*.

This concept is particularly relevant in domains where different misclassifications pose differing levels of risk. For example, in traffic sign recognition, confusing a "Stop" sign with a "60 kph" sign is substantially more detrimental than with a "No Passing" sign. Critical tensors focus the explanation on the most consequential potential failure modes [2604.14209].

## 2. Targeted $\varepsilon$-Robustness Specification

Standard robustness verification assesses whether no class logit interval can overlap with the true class under arbitrary $\varepsilon$-bounded input perturbations. In contrast, ViTaX formulates **Targeted $\varepsilon$-Robustness** with respect to a specific alternative class $t$, formalized as follows:

Let $f:\mathbb{R}^{w\times h\times c}\to\mathbb{R}^m$ be a neural network, $x$ the input, $y$ the true class, and $t$ the user-specified alternative. Consider perturbing features in $A$ such that $\|x'_A - x_A\|_p \le \varepsilon$ while $x'_{F\setminus A}=x_{F\setminus A}$. Let $X_{\varepsilon,A}$ denote all such perturbed inputs, with $F$ the full index set.

A feature subset $A$ is said to satisfy **T-ROB** (Targeted Robustness) if the following holds:
$$
\exists\,A\,:\quad \|x'_A - x_A\|_p \le \varepsilon  \;\wedge\; l_{y,A} > u_{t,A} \quad\text{(and optionally)}\; \forall\,k\neq y, t:\;u_{t,A} > u_{k,A}.
$$
where $[l_{k,A}, u_{k,A}]$ are the interval bounds on output logit $k$ under the set $X_{\varepsilon,A}$. If T-ROB holds, the class transition $y\to t$ is formally impossible under $\varepsilon$-bounded perturbations to features in $A$ [2604.14209].

## 3. Algorithm for Critical Tensor Identification

ViTaX operationalizes critical-tensor selection via an efficient algorithm, leveraging feature-sensitivity heuristics and binary search. The principle steps are:

1. **Heuristic Ranking ($\pi$)**: Compute $\pi$ by ranking features according to the gradient-based sensitivity to the target class $t$, i.e., using $|\partial f_t/\partial x_i|$ for each feature $i$.
2. **Binary Search for Minimality**: Iteratively select increasing prefixes of the ranked features and verify T-ROB via a formal reachability solver $V$. The candidate set $A$ is the smallest prefix satisfying T-ROB.
3. **Formal Verification**: At each binary search iteration, call the solver $V$ to check whether, for the selected $A$, the network is robust to the $y\to t$ transition under the specified perturbation.

The algorithm returns a provably minimal (under ranking $\pi$) critical tensor $A$. The complexity of the process is logarithmic in the number of features due to the binary search strategy.

**ViTaX Pseudocode (Algorithm 1):**
```python
Function ViTaX(f, x; target t, norm p, eps):
  π ← HeuristicRanking(x, t)
  I ← 0;  J ← n
  A_candidate ← ∅
  While I ≤ J:
    u ← ⌊(I+J)/2⌋
    d ← π[0:u]
    X_ε,d ← {x' | ||x'_d − x_d||_p ≤ ε, x'_{∁d}=x_{∁d}
    Φ ← (l_{y,d} > u_{t,d})
    (FLAG, c) ← V(f, X_ε,d, Φ)
    If FLAG == true:
      A_candidate ← d
      I ← u + 1
    Else:
      J ← u - 1
  Return A_candidate
```
The reachability solver $V$ (e.g., Star-based reachability, MILP) certifies the required specification over infinite input sets $X_{\varepsilon,d}$ [2604.14209].

## 4. Formal Guarantees and Properties

ViTaX's critical-tensor identification is underpinned by theoretical guarantees assuming the reachability solver is sound and complete and the ranking is sensitivity-optimal:

- **Soundness:** If $V$ certifies T-ROB for $A$, then $l_{y,A}>u_{t,A}$ truly holds for all $x'\in X_{\varepsilon,A}$, meaning the $y\to t$ transition is impossible under such perturbations.
- **Maximality (w.r.t. $\pi$):** $A$ is the largest (minimal in cardinality) prefix of $\pi$ such that the T-ROB criterion holds; supersets of $A$ (w.r.t. the ranking) will violate T-ROB.
- **Algorithmic Complexity:** $O(\log n)$ calls to the reachability solver due to binary search.

These properties ensure that the returned critical tensor $A$ is both succinct and verifiably robust with respect to the $y\to t$ transition [2604.14209].

## 5. Empirical Examples and Size–Fidelity Trade-Off

ViTaX demonstrates practical critical-tensor identification on several datasets:

**MNIST Example:**  
- Input: "4" ($y=4$); Target: "9" ($t=9$).
- Ranking identifies pixels critical for the "4→9" decision (e.g., pixels in the upper-loop of "4").
- Binary search yields a critical tensor $A$ of 5 pixels. Larger $A$ subsets increase robustness but decrease interpretability, defining a size–fidelity trade-off.
- Practitioners can explore $\varepsilon$ vs. $|A|$ curves to balance explanation succinctness against guarantee strength.

**GTSRB Example:**  
- Input: "Stop" sign ($y=14$); Target: "60 kph" ($t=5$).
- ViTaX selects 30 interior pixels (out of 3072) critical for the "Stop→60 kph" misclassification, with higher fidelity and lower cardinality than the 472-pixel baseline from VeriX.
  
This suggests that ViTaX explanations are both more interpretable and more faithful to the underlying risk structure than previous methods [2604.14209].

## 6. Scope of Applicability and Generalizations

ViTaX and its critical-tensor approach are network-architecture and modality agnostic, supporting:

- **Architectures:** MLPs, CNNs, ResNets, Inception, Transformers, contingent upon an appropriate reachability backend (e.g., Approx-Star, CP-Star, MILP).
- **Input Modalities:** Images, time series, textual embeddings, audio spectrograms, and graph features, with critical tensor selection performed on the flattened feature set.
- **Beyond Classification:** Adaptation to regression, ranked retrieval, or multi-label tasks by tuning the T-ROB specification to ensure robust margin (e.g., minimal lower-bound difference between outputs).
- **Higher-Order Explanations:** Chaining calls to the algorithm with varying target classes or perturbation budgets allows coverage of trade-offs and Pareto-optimal robustness sets.

A plausible implication is that critical-tensor identification via ViTaX serves as a general tool for providing semifactual, formally verified, high-fidelity explanations across a spectrum of ML applications, particularly where targeted safety guarantees are required [2604.14209].

Source: https://www.emergentmind.com/topics/critical-tensor-identification-xai-based-selection