AION
Research paperInterpretability · Safety & Alignment · Efficiency & Inference1 source · Oct 7, 2026

MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking

In post-deployment time, inputs to deep learning models may or may not be adversarially patched.

Key points

  • However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively.
  • We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both.
  • Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair.
  • Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.

Sources (1)

Extractive summary: sentences quoted from the sources.

Before this

  1. Oct 6, 2026Consistent Distribution Matching for Data-Free Diffusion Distillation
  2. Oct 6, 2026From the Drosophila Visual Connectome to General-Purpose Computer Vision
  3. Oct 6, 2026Test-Time Adaptation of Quantized ViTs via Single-Pass Quantizer-Aligned Recalibration
  4. Oct 6, 2026Two Halves are More than One: Phase-wise Velocity Distillation for Fast and High-Quality Image Generation
  5. Oct 6, 2026Later Is Better: Token Reduction for ViTs Under Distribution Shift
  6. Oct 1, 2026nvidia/PixelDiT2-ImageNet

Related