الملخص
In post-deployment time, inputs to deep learning models may or may not be adversarially patched. Patch robustness certification on such inputs within a patch bound can verify their label benignity and should retain high prediction accuracy. However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively. We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both. Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair. Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1\% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.
الكلمات المفتاحية
الموضوع
بيانات النشر
- المجلة
- غير متاح
- وصول مفتوح
- وصول مفتوح أخضر
اقتبس هذه المقالة
APA 7
Zhou, Q., Wei, Z., Wang, H., Wang, Z., Liu, S., & Chan, W. K. (2026). MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking. https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking
MLA 9
Zhou, Qilin, et al. "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking." https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.
شيكاغو (المؤلف–التاريخ)
Zhou, Qilin, Zhengyuan Wei, Haipeng Wang, Zhuo Wang, Shuo Liu, and W. K. Chan. 2026. "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking." https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.
هارفارد
Zhou, Q., Wei, Z., Wang, H., Wang, Z., Liu, S. and Chan, W. K. (2026) 'MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking', Available at: https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.
فانكوفر
Zhou Q, Wei Z, Wang H, Wang Z, Liu S, Chan WK. MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking. https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking
IEEE
Q. Zhou, Z. Wei, H. Wang, Z. Wang, S. Liu, and W. K. Chan, "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking," https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.