الملخص

In post-deployment time, inputs to deep learning models may or may not be adversarially patched. Patch robustness certification on such inputs within a patch bound can verify their label benignity and should retain high prediction accuracy. However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively. We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both. Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair. Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1\% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.

الكلمات المفتاحية

الموضوع

بيانات النشر

المجلة
غير متاح
وصول مفتوح
وصول مفتوح أخضر

اقتبس هذه المقالة

APA 7

Zhou, Q., Wei, Z., Wang, H., Wang, Z., Liu, S., & Chan, W. K. (2026). MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking. https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking

MLA 9

Zhou, Qilin, et al. "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking." https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.

شيكاغو (المؤلف–التاريخ)

Zhou, Qilin, Zhengyuan Wei, Haipeng Wang, Zhuo Wang, Shuo Liu, and W. K. Chan. 2026. "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking." https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.

هارفارد

Zhou, Q., Wei, Z., Wang, H., Wang, Z., Liu, S. and Chan, W. K. (2026) 'MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking', Available at: https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.

فانكوفر

Zhou Q, Wei Z, Wang H, Wang Z, Liu S, Chan WK. MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking. https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking

IEEE

Q. Zhou, Z. Wei, H. Wang, Z. Wang, S. Liu, and W. K. Chan, "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking," https://omanscience.com/ar/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.