← Search

Klas Leino

8 accepted papers

2023

On the Perils of Cascading Robust Classifiers

ICLR 2023poster

Ensembling certifiably robust neural networks is a promising approach for improving the \emph{certified robust accuracy} of neural models. Black-box ensembles that assume only query-access to the constituent models (and their robustness certifiers) during prediction are particularly attractive due…

2023

Unlocking Deterministic Robustness Certification on ImageNet

NeurIPS 2023poster

Despite the promise of Lipschitz-based methods for provably-robust deep learning with deterministic guarantees, current state-of-the-art results are limited to feed-forward Convolutional Networks (ConvNets) on low-dimensional data, such as CIFAR-10. This paper investigates strategies for expanding…

Cited by 10SourcePDFScholar
2021

Fast Geometric Projections for Local Robustness Certification

ICLR 2021spotlight

Local robustness ensures that a model classifies all inputs within an $\ell_p$-ball consistently, which precludes various forms of adversarial inputs. In this paper, we present a fast procedure for checking local robustness in feed-forward neural networks with piecewise-linear activation functions.…

Cited by 42SourcePDFScholar
2021

Relaxing Local Robustness

NeurIPS 2021poster

Certifiable local robustness, which rigorously precludes small-norm adversarial examples, has received significant attention as a means of addressing security concerns in deep learning. However, for some classification problems, local robustness is not a natural objective, even in the presence of ad…

Cited by 9SourcePDFScholar