We study probabilistic safety for BayesianNeural Networks (BNNs) under adversarial in-put perturbations. Given a compact set of input points,T⊆Rm, we study the probability w.r.t. the BNN posterior that all the pointsinTare mapped to the same region S in theoutput space. In particular, this can be usedto evaluate the probability that a network sam-pled from the BNN is vulnerable to adversarialattacks. We rely on relaxation techniques from non-convex optimization to develop a methodfor computing a lower bound on probabilis-tic safety for BNNs, deriving explicit procedures for the case of interval and linear function propagation techniques. We apply ourmethods to BNNs trained on a regression task,airborne collision avoidance, and MNIST, empirically showing that our approach allows oneto certify probabilistic safety of BNNs withthousands of neurons.