Abstract

In post-deployment time, inputs to deep learning models may or may not be adversarially patched. Patch robustness certification on such inputs within a patch bound can verify their label benignity and should retain high prediction accuracy. However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively. We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both. Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair. Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1\% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.

Keywords

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Zhou, Q., Wei, Z., Wang, H., Wang, Z., Liu, S., & Chan, W. K. (2026). MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking. https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking

MLA 9

Zhou, Qilin, et al. "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking." https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.

Chicago (author–date)

Zhou, Qilin, Zhengyuan Wei, Haipeng Wang, Zhuo Wang, Shuo Liu, and W. K. Chan. 2026. "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking." https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.

Harvard

Zhou, Q., Wei, Z., Wang, H., Wang, Z., Liu, S. and Chan, W. K. (2026) 'MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking', Available at: https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.

Vancouver

Zhou Q, Wei Z, Wang H, Wang Z, Liu S, Chan WK. MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking. https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking

IEEE

Q. Zhou, Z. Wei, H. Wang, Z. Wang, S. Liu, and W. K. Chan, "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking," https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking.