Provable Defense Against Geometric Transformations
Rem Yang, Jacob Laurel, Sasa Misailovic, Gagandeep Singh
Abstract
Geometric image transformations that arise in the real world, such as scaling and rotation, have been shown to easily deceive deep neural networks (DNNs). Hence, training DNNs to be certifiably robust to these perturbations is critical. However, no prior work has been able to incorporate the objective of deterministic certified robustness against geometric transformations into the training procedure, as existing verifiers are exceedingly slow. To address these challenges, we propose the first provable defense for deterministic certified geometric robustness. Our framework leverages a novel GPU-optimized verifier that can certify images between 60 to 42,600 faster than existing geometric robustness verifiers, and thus unlike existing works, is fast enough for use in training. Across multiple datasets, our results show that networks trained via our framework consistently achieve state-of-the-art deterministic certified geometric robustness and clean accuracy. Furthermore, for the first time, we verify the geometric robustness of a neural network for the challenging, real-world setting of autonomous driving.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext df3a1b05-31b6-4644-b32c-629791e490f5Cited by top-tier papers6
- A general construction for abstract interpretation of higher-order automatic differentiationJacob Laurel, Rem Yang, Shubham Ugare, Robert Nagel et al.OOPSLA 2022 · 9 citations
- Scalable Neural Network Geometric Robustness Validation via Hölder OptimisationYanghao Zhang, Panagiotis Kouvaros, Alessio LomuscioNeurIPS 2025 · 4 citations
- ARQ: A Mixed-Precision Quantization Framework for Accurate and Certifiably Robust DNNsYuchen Yang, Yifan Zhao, Shubham Ugare, Gagandeep Singh et al.ISSTA 2026 · 2 citations
- Synthesizing Sound and Precise Abstract Transformers for Nonlinear Hyperbolic PDE SolversJacob Laurel, Ignacio Laguna, Jan HückelheimOOPSLA 2025 · 1 citation
- Lipschitz Optimization for Formal Verification of HomographiesJean-Guillaume Durand, Panagiotis Kouvaros, Maxime Gariel, Alessio LomuscioCVPR 2026
Builds on7
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang et al.NeurIPS 2020 · 415 citations
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal et al.ICLR 2020 · 384 citations
- Scalable Verified Training for Provably Robust Image ClassificationSven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel et al.ICCV 2019 · 196 citations
- Certified Defense to Image Transformations via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevNeurIPS 2020 · 78 citations
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
Related papers
- PointCert: Point Cloud Classification with Deterministic Certified Robustness GuaranteesJinghuai Zhang, Jinyuan Jia, Hongbin Liu, Neil Zhenqiang GongCVPR 2023
- SoK: Certified Robustness for Deep Neural NetworksLinyi Li, Tao Xie, Bo LiS&P 2023
- Robustness Certification for Point Cloud ModelsTobias Lorenz, Anian Ruoss, Mislav Balunovic, Gagandeep Singh et al.ICCV 2021 · 29 citations
- Efficient Certification of Spatial RobustnessAnian Ruoss, Maximilian Baader, Mislav Balunovic, Martin T. VechevAAAI 2021 · 26 citations
- Provably Robust Adversarial ExamplesDimitar Iliev Dimitrov, Gagandeep Singh, Timon Gehr, Martin T. VechevICLR 2022 · 12 citations
