Lune

ICLR2025Top-tier venue

Certified Robustness Under Bounded Levenshtein Distance

Elías Abad-Rocamora, Grigorios Chrysos, Volkan Cevher

2025Year
2Top-tier citations

Abstract

Text classifiers suffer from small perturbations, that if chosen adversarially, can dramatically change the output of the model. Verification methods can provide robustness certificates against such adversarial perturbations, by computing a sound lower bound on the robust accuracy. Nevertheless, existing verification methods incur in prohibitive costs and cannot practically handle Levenshtein distance constraints. We propose the first method for computing the Lipschitz constant of convolutional classifiers with respect to the Levenshtein distance. We use these Lipschitz constant estimates for training 1-Lipschitz classifiers. This enables computing the certified radius of a classifier in a single forward pass. Our method, LipsLev, is able to obtain 38.8038.80% and 13.9313.93% verified accuracy at distance 11 and 22 respectively in the AG-News dataset, while being 44 orders of magnitude faster than existing approaches. We believe our work can open the door to more efficient verification in the text domain.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 61e376fa-a957-4c64-bb20-46e88a9a9b2d

Cited by top-tier papers2

Ask how each one uses it

Builds on22

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines