Toward Patch Robustness Certification and Detection for Deep Learning Systems Beyond Consistent Samples
arxiv.org·22h
🧪Binary Fuzzing
Preview
Report Post

View PDF HTML (experimental)

Abstract:Patch robustness certification is an emerging kind of provable defense technique against adversarial patch attacks for deep learning systems. Certified detection ensures the detection of all patched harmful versions of certified samples, which mitigates the failures of empirical defense techniques that could (easily) be compromised. However, existing certified detection methods are ineffective in certifying samples that are misclassified or whose mutants are inconsistently pre icted to different labels. This paper proposes HiCert, a novel masking-based certified detection technique. By focusing on the problem of mutants predicted with a label different from the true l…

Similar Posts

Loading similar posts...