It's Simplex! Disaggregating Measures to Improve Certified Robustness
Andrew C. Cullen, Paul Montague, Shijie Liu, Sarah M. Erfani, Benjamin I. P. Rubinstein
Abstract
Certified robustness circumvents the fragility of defences against adversarial attacks, by endowing model predictions with guarantees of class invariance for attacks up to a calculated size. While there is value in these certifications, the techniques through which we assess their performance do not present a proper accounting of their strengths and weaknesses, as their analysis has eschewed consideration of performance over individual samples in favour of aggregated measures. By considering the potential output space of certified models, this work presents two distinct approaches to improve the analysis of certification mechanisms, that allow for both dataset-independent and dataset-dependent measures of certification performance. Embracing such a perspective uncovers new certification approaches, which have the potential to more than double the achievable radius of certification, relative to current state-of-the-art. Empirical evaluation verifies that our new approach can certify 9% more samples at noise scale σ = 1, with greater relative improvements observed as the difficulty of the predictive task increases.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cf213709-ecf2-4ea6-b851-7e45b848d064Cited by top-tier papers5
- Fox in the Henhouse: Supply-Chain Backdoor Attacks Against Reinforcement LearningShijie Liu, Andrew C. Cullen, Paul MONTAGUE, Sarah Erfani et al.ICML 2026 · 5 citations
- Et Tu Certifications: Robustness Certificates Yield Better Adversarial ExamplesAndrew C. Cullen, Shijie Liu, Paul Montague, Sarah Monazam Erfani et al.ICML 2024 · 3 citations
- CertTA: Certified Robustness Made Practical for Learning-Based Traffic AnalysisJinzhu Yan, Zhuotao Liu, Yuyang Xie, Shiyu Liang et al.USENIX Security 2025
- Multi-level Certified Defense Against Poisoning Attacks in Offline Reinforcement LearningShijie Liu, Andrew Craig Cullen, Paul Montague, Sarah Monazam Erfani et al.ICLR 2025
- Provable Repair of Deep Neural Network Defects by Preimage Synthesis and Property RefinementJianan Ma, Jingyi Wang, Qi Xuan, Zhen WangCCS 2025
Builds on9
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang et al.NeurIPS 2020 · 415 citations
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal et al.ICLR 2020 · 384 citations
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified RadiusRuntian Zhai, Chen Dan, Di He, Huan Zhang et al.ICLR 2020 · 195 citations
- A Study of Face Obfuscation in ImageNetKaiyu Yang, Jacqueline H. Yau, Li Fei-Fei, Jia Deng et al.ICML 2022 · 163 citations
Related papers
- Enhancing the Antidote: Improved Pointwise Certifications against Poisoning AttacksShijie Liu, Andrew C. Cullen, Paul Montague, Sarah M. Erfani et al.AAAI 2023 · 7 citations
- Certified but Fooled! Breaking Certified Defenses with Ghost CertificatesViet Quoc Vo, Tashreque Mohammed Haq, Paul Montague, Tamas Abraham et al.AAAI 2026
- Double Bubble, Toil and Trouble: Enhancing Certified Robustness through TransitivityAndrew C. Cullen, Paul Montague, Shijie Liu, Sarah M. Erfani et al.NeurIPS 2022 · 22 citations
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen et al.NeurIPS 2020 · 51 citations
- Average Certified Radius is a Poor Metric for Randomized SmoothingChenhao Sun, Yuhao Mao, Mark Niklas Müller, Martin T. VechevICML 2025
