Support is All You Need for Certified VAE Training
Changming Xu, Debangshu Banerjee, Deepak Vasisht, Gagandeep Singh
Abstract
Variational Autoencoders (VAEs) have become increasingly popular and deployed in safety-critical applications. In such applications, we want to give certified probabilistic guarantees on performance under adversarial attacks. We propose a novel method, CIVET, for certified training of VAEs. CIVET depends on the key insight that we can bound worst-case VAE error by bounding the error on carefully chosen support sets at the latent layer. We show this point mathematically and present a novel training algorithm utilizing this insight. We show in an extensive evaluation across different datasets (in both the wireless and vision application areas), architectures, and perturbation magnitudes that our method outperforms SOTA methods achieving good standard performance with strong robustness guarantees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b2cdf94b-1de5-40d0-b63e-ba6fe42f89e8Builds on20
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal et al.ICLR 2020 · 384 citations
- Fast and Complete: Enabling Complete Neural Network Verification with Rapid and Massively Parallel Incomplete VerifiersKaidi Xu, Huan Zhang, Shiqi Wang, Yihan Wang et al.ICLR 2021 · 250 citations
- Adversarial Training and Provable Defenses: Bridging the GapMislav Balunovic, Martin T. VechevICLR 2020 · 186 citations
- PRIMA: general and precise neural network certification via scalable convex hull approximationsMark Niklas Müller, Gleb Makarchuk, Gagandeep Singh, Markus Püschel et al.POPL 2022 · 75 citations
- Fast Certified Robust Training with Short WarmupZhouxing Shi, Yihan Wang, Huan Zhang, Jinfeng Yi et al.NeurIPS 2021 · 74 citations
Related papers
- Improving VAEs' Robustness to Adversarial AttackMatthew Willetts, Alexander Camuto, Tom Rainforth, Stephen J. Roberts et al.ICLR 2021 · 30 citations
- Towards Certification of Uncertainty Calibration under Adversarial AttacksCornelius Emde, Francesco Pinto, Thomas Lukasiewicz, Philip Torr et al.ICLR 2025 · 1 citation
- Alleviating Adversarial Attacks on Variational Autoencoders with MCMCAnna Kuzina, Max Welling, Jakub M. TomczakNeurIPS 2022 · 16 citations
- Information-Theoretic Generalization Bounds for VAEs: A Role of Encoder and Latent VariableFutoshi Futami, Masahiro FujisawaICML 2026
- Generalization Gap in Amortized InferenceMingtian Zhang, Peter Hayes, David BarberNeurIPS 2022 · 14 citations
