MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking
In post-deployment time, inputs to deep learning models may or may not be adversarially patched.
Key points
- However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively.
- We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both.
- Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair.
- Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.
Sources (1)
- [1]MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific MaskingarXiv (AI, ML, NLP, CV, robotics, multi-agent) · Oct 7, 07:27 AM
In post-deployment time, inputs to deep learning models may or may not be adversarially patched.
However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively.
Extractive summary: sentences quoted from the sources.
Before this
- Oct 6, 2026Consistent Distribution Matching for Data-Free Diffusion Distillation
- Oct 6, 2026From the Drosophila Visual Connectome to General-Purpose Computer Vision
- Oct 6, 2026Test-Time Adaptation of Quantized ViTs via Single-Pass Quantizer-Aligned Recalibration
- Oct 6, 2026Two Halves are More than One: Phase-wise Velocity Distillation for Fast and High-Quality Image Generation
- Oct 6, 2026Later Is Better: Token Reduction for ViTs Under Distribution Shift
- Oct 1, 2026nvidia/PixelDiT2-ImageNet