arXiv:cs.AI· Qilin Zhou, Zhengyuan Wei, Haipeng Wang, Zhuo Wang, Shuo Liu, W. K. Chan·· 3 小时前
MRCert:面向对抗补丁样本的部署后补丁鲁棒性认证
MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking
AI 导读
MRCert 是首个基于掩码的认证恢复防御方法,通过在部署后针对良性样本与对抗补丁样本分别推断类型特定的模型必要属性,并设计类型导向的标签恢复与认证函数对,实现对返回标签良性性的形式化验证。在 ImageNet、补丁尺寸 16 像素下,MRCert 取得 35.1% 的对抗认证准确率,而 SOTA 方法 PatchCURE 完全失效,且不引入平滑方法导致的干净准确率下降。
正文
Abstract:In post-deployment time, inputs to deep learning models may or may not be adversarially patched. Patch robustness certification on such inputs within a patch bound can verify their label benignity and should retain high prediction accuracy. However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively. We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both. Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair. Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1\% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Machine Learning (cs.LG); Software Engineering (cs.SE) |
| Cite as: | arXiv:2610.10617 [cs.CR] |
| (or arXiv:2610.10617v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.10617 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Qilin Zhou [view email]
[v1]
Wed, 7 Oct 2026 07:27:16 UTC (289 KB)
来源:arXiv:cs.AI · arxiv.org