[
    {
        "id": "osp-15345",
        "type": "article-journal",
        "title": "MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking",
        "author": [
            {
                "family": "Zhou",
                "given": "Qilin"
            },
            {
                "family": "Wei",
                "given": "Zhengyuan"
            },
            {
                "family": "Wang",
                "given": "Haipeng"
            },
            {
                "family": "Wang",
                "given": "Zhuo"
            },
            {
                "family": "Liu",
                "given": "Shuo"
            },
            {
                "family": "Chan",
                "given": "W. K."
            }
        ],
        "URL": "https://omanscience.com/en/articles/mrcert-towards-post-deployment-patch-robustness-certification-for-adversarially-patched-samples-via-type-specific-masking",
        "language": "en",
        "issued": {
            "date-parts": [
                [
                    2026
                ]
            ]
        },
        "abstract": "In post-deployment time, inputs to deep learning models may or may not be adversarially patched. Patch robustness certification on such inputs within a patch bound can verify their label benignity and should retain high prediction accuracy. However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively. We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both. Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair. Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1\\% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely."
    }
]