Pith. sign in

REVIEW 2 cited by

IBP Regularization for Verified Adversarial Robustness via Branch-and-Bound

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2206.14772 v2 pith:ENT52Q5W submitted 2022-06-29 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords ibp-rregularizationtrainingverifiedadversarialalgorithmsattacksbranch-and-bound
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Recent works have tried to increase the verifiability of adversarially trained networks by running the attacks over domains larger than the original perturbations and adding various regularization terms to the objective. However, these algorithms either underperform or require complex and expensive stage-wise training procedures, hindering their practical applicability. We present IBP-R, a novel verified training algorithm that is both simple and effective. IBP-R induces network verifiability by coupling adversarial attacks on enlarged domains with a regularization term, based on inexpensive interval bound propagation, that minimizes the gap between the non-convex verification problem and its approximations. By leveraging recent branch-and-bound frameworks, we show that IBP-R obtains state-of-the-art verified robustness-accuracy trade-offs for small perturbations on CIFAR-10 while training significantly faster than relevant previous work. Additionally, we present UPB, a novel branching strategy that, relying on a simple heuristic based on $\beta$-CROWN, reduces the cost of state-of-the-art branching algorithms while yielding splits of comparable quality.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Certified Training for Convolutional Perturbations

    cs.CV 2026-07 conditional novelty 6.0 of 10

    A certified-training method using parameterized blur kernels and symbolic bound propagation gives provable robustness to motion blur and related convolutional perturbations, reaching over 80% verified accuracy on CIFAR10.

  2. Adversarial Attacks Leverage Interference Between Features in Superposition

    cs.LG 2025-10 conditional novelty 6.0 of 10

    Superposition—packing more features than dimensions—is sufficient to create adversarial vulnerability, and attack directions and transferability are predictable from the resulting feature geometry.

Pith tools