REVIEW 2 cited by
Certified Training: Small Boxes are All You Need
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
To obtain, deterministic guarantees of adversarial robustness, specialized training methods are used. We propose, SABR, a novel such certified training method, based on the key insight that propagating interval bounds for a small but carefully selected subset of the adversarial input region is sufficient to approximate the worst-case loss over the whole region while significantly reducing approximation errors. We show in an extensive empirical evaluation that SABR outperforms existing certified defenses in terms of both standard and certifiable accuracies across perturbation magnitudes and datasets, pointing to a new class of certified training methods promising to alleviate the robustness-accuracy trade-off.
Forward citations
Cited by 2 Pith papers
-
A Scalable Approach to Probabilistic Neuro-Symbolic Robustness Verification
Probabilistic NeSy robustness can be verified approximately by compiling neural and symbolic parts into one arithmetic graph and running interval bound propagation, with an NPPP-completeness result for the exact version.
-
Get Global Guarantees: On the Probabilistic Nature of Perturbation Robustness
Tower robustness measures a model's expected accuracy over random perturbations within an Lp ball and comes with computable lower and upper bounds based on exact binomial tests.
Discussion (0). Continue with ORCID to comment.