A Recipe for Improved Certifiable Robustness
Kai Hu, Klas Leino, Zifan Wang, Matt Fredrikson
Abstract
Recent studies have highlighted the potential of Lipschitz-based methods for training certifiably robust neural networks against adversarial attacks. A key challenge, supported both theoretically and empirically, is that robustness demands greater network capacity and more data than standard training. However, effectively adding capacity under stringent Lipschitz constraints has proven more difficult than it may seem, evident by the fact that state-of-the-art approach tend more towards underfitting than overfitting. Moreover, we posit that a lack of careful exploration of the design space for Lipshitz-based approaches has left potential performance gains on the table. In this work, we provide a more comprehensive evaluation to better uncover the potential of Lipschitz-based certification methods. Using a combination of novel techniques, design optimizations, and synthesis of prior work, we are able to significantly improve the state-of-the-art VRA for deterministic certification on a variety of benchmark datasets, and over a range of perturbation sizes. Of particular note, we discover that the addition of large "Cholesky-orthogonalized residual dense" layers to the end of existing state-of-the-art Lipschitz-controlled ResNet architectures is especially effective for increasing network capacity and performance. Combined with filtered generative data augmentation, our final results further the state of the art deterministic VRA by up to 8.5 percentage points 1 .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e2c4ad0f-7cd6-4202-8393-3f3b14d6ccf8Cited by top-tier papers4
- LipNeXt: Scaling up Lipschitz-based Certified Robustness to Billion-parameter ModelsKai Hu, Haoqi Hu, Matt FredriksonICLR 2026 · 3 citations
- Knowledgeable Language Models as Black-Box Optimizers for Personalized MedicineMichael S. Yao, Osbert Bastani, Alma Andersson, Tommaso Biancalani et al.ICLR 2026
- Enhancing Certified Robustness via Block Reflector Orthogonal Layers and Logit Annealing LossBo-Han Lai, Pin-Han Huang, Bo-Han Kung, Shang-Tse ChenICML 2025
- An Adaptive Orthogonal Convolution Scheme for Efficient and Flexible CNN ArchitecturesThibaut Boissin, Franck Mamalet, Thomas Fel, Agustin Martin Picard et al.ICML 2025
Builds on18
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Improved Denoising Diffusion Probabilistic ModelsAlexander Quinn Nichol, Prafulla DhariwalICML 2021 · 5,234 citations
- Elucidating the Design Space of Diffusion-Based Generative ModelsTero Karras, Miika Aittala, Timo Aila, Samuli LaineNeurIPS 2022 · 3,959 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- A Universal Law of Robustness via IsoperimetrySébastien Bubeck, Mark SellkeNeurIPS 2021 · 260 citations
Related papers
- Unlocking Deterministic Robustness Certification on ImageNetKai Hu, Andy Zou, Zifan Wang, Klas Leino et al.NeurIPS 2023 · 18 citations
- Globally-Robust Neural NetworksKlas Leino, Zifan Wang, Matt FredriksonICML 2021 · 150 citations
- Improved techniques for deterministic l2 robustnessSahil Singla, Soheil FeiziNeurIPS 2022 · 13 citations
- LOT: Layer-wise Orthogonal Training on Improving l2 Certified RobustnessXiaojun Xu, Linyi Li, Bo LiNeurIPS 2022 · 42 citations
- Certified Robustness via Dynamic Margin Maximization and Improved Lipschitz RegularizationMahyar Fazlyab, Taha Entesari, Aniket Roy, Rama ChellappaNeurIPS 2023 · 26 citations
