Towards Robustness Certification Against Universal Perturbations
Yi Zeng, Zhouxing Shi, Ming Jin, Feiyang Kang, Lingjuan Lyu, Cho-Jui Hsieh, Ruoxi Jia
Abstract
In this paper, we investigate the problem of certifying neural network robustness against universal perturbations (UPs), which have been widely used in universal adversarial attacks and backdoor attacks. Existing robustness certification methods aim to provide robustness guarantees for each sample with respect to the worst-case perturbations given a neural network. However, those sample-wise bounds will be loose when considering the UP threat model as they overlook the important constraint that the perturbation should be shared across all samples. We propose a method based on a combination of linear relaxation-based perturbation analysis and Mixed Integer Linear Programming to establish the first robust certification method for UP. In addition, we develop a theoretical framework for computing error bounds on the entire population using the certification results from a randomly sampled batch. Aside from an extensive evaluation of the proposed certification, we further show how the certification facilitates efficient comparison of robustness among different models or efficacy among different universal adversarial attack defenses and enables accurate detection of backdoor target classes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9ca5e895-ef73-4a2b-b94f-24fa0d06fd95Cited by top-tier papers5
- Input-Relational Verification of Deep Neural NetworksDebangshu Banerjee, Changming Xu, Gagandeep SinghPLDI 2024 · 9 citations
- Relational DNN Verification With Cross Executional Bound RefinementDebangshu Banerjee, Gagandeep SinghICML 2024 · 8 citations
- Relational Verification Leaps Forward with RABBitTarun Suresh, Debangshu Banerjee, Gagandeep SinghNeurIPS 2024 · 5 citations
- Prototype Guided Backdoor Defense via Activation Space ManipulationVenkat Adithya Amula, Sunayana Samavedam, Saurabh Saini, Avani Gupta et al.ICCV 2025 · 2 citations
- A Closer Look at Backdoor Attacks on CLIPShuo He, Zhifang Zhang, Feng Liu, Roy Ka-Wei Lee et al.ICML 2025
Related papers
- CC-CERT: A Probabilistic Approach to Certify General Robustness of Neural NetworksMikhail Pautov, Nurislam Tursynbek, Marina Munkhoeva, Nikita Muravev et al.AAAI 2022 · 27 citations
- MIBP-Cert: Certified Training against Data Perturbations with Mixed-Integer Bilinear ProgramsTobias Lorenz, Marta Kwiatkowska, Mario FritzNeurIPS 2025 · 1 citation
- CBD: A Certified Backdoor Detector Based on Local Dominant ProbabilityZhen Xiang, Zidi Xiong, Bo LiNeurIPS 2023 · 29 citations
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- Fooling a Complete Neural Network VerifierDániel Zombori, Balázs Bánhelyi, Tibor Csendes, István Megyeri et al.ICLR 2021 · 21 citations
