CertMask: Certifiable Defense Against Adversarial Patches via Theoretically Optimal Mask Coverage
Xuntao Lyu, Ching-Chi Lin, Abdullah Al Arafat, Georg von der Brüggen, Jian-Jia Chen, Zhishan Guo
Abstract
Adversarial patch attacks inject localized perturbations into images to mislead deep vision models. These attacks can be physically deployed, posing serious risks to real-world applications. In this paper, we propose CertMask, a certifiably robust defense that constructs a provably sufficient set of binary masks to neutralize patch effects with strong theoretical guarantees. While the state-of-the-art approach (Patch-Cleanser) requires two rounds of masking and incurs O(n 2 ) inference cost, CertMask performs only a single round of masking with O(n) time complexity, where n is the cardinality of the mask set to cover an input image. Our proposed mask set is computed using a mathematically rigorous coverage strategy that ensures each possible patch location is covered at least k times, providing both efficiency and robustness. We offer a theoretical analysis of the coverage condition and prove its sufficiency for certification. Experiments on Im-ageNet, ImageNette, and CIFAR-10 show that CertMask improves certified robust accuracy by up to +13.4% over Patch-Cleanser, while maintaining clean accuracy nearly identical to the vanilla model.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1b4412b0-d882-4714-9fb9-6dd15cba43caBuilds on11
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu et al.ICLR 2020 · 194 citations
- (De)Randomized Smoothing for Certifiable Defense against Patch AttacksAlexander Levine, Soheil FeiziNeurIPS 2020 · 188 citations
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 172 citations
- Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial AttacksFrancesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion et al.AAAI 2022 · 135 citations
Related papers
- PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image ClassifierChong Xiang, Saeed Mahloujifar, Prateek MittalUSENIX Security 2022
- Certified Defences Against Adversarial Patch Attacks on Semantic SegmentationMaksym Yatsura, Kaspar Sakmann, N. Grace Hua, Matthias Hein et al.ICLR 2023 · 3 citations
- PatchDEMUX: A Certifiably Robust Framework for Multi-label Classifiers Against Adversarial PatchesDennis Jacob, Chong Xiang, Prateek MittalCVPR 2025
- Towards Practical Certifiable Patch Defense with Vision TransformerZhaoyu Chen, Bo Li, Jianghe Xu, Shuang Wu et al.CVPR 2022 · 60 citations
- ScaleCert: Scalable Certified Defense against Adversarial Patches with Sparse Superficial LayersHusheng Han, Kaidi Xu, Xing Hu, Xiaobing Chen et al.NeurIPS 2021 · 27 citations
