← Search

Mikhail Pautov

4 accepted papers

2025

Certification of Speaker Recognition Models to Additive Perturbations

AAAI 2025technical

Speaker recognition technology is applied to various tasks, from personal virtual assistants to secure access systems. However, the robustness of these systems against adversarial attacks, particularly to additive perturbations, remains a significant challenge. In this paper, we pioneer applying rob…

2024

Probabilistically Robust Watermarking of Neural Networks

IJCAI 2024poster

As deep learning (DL) models are widely and effectively used in Machine Learning as a Service (MLaaS) platforms, there is a rapidly growing interest in DL watermarking techniques that can be used to confirm the ownership of a particular model. Unfortunately, these methods usually produce watermarks…

Cited by 4SourcePDFScholar
2022

CC-CERT: A Probabilistic Approach to Certify General Robustness of Neural Networks

AAAI 2022technical

In safety-critical machine learning applications, it is crucial to defend models against adversarial attacks --- small modifications of the input that change the predictions. Besides rigorously studied $ell_p$-bounded additive perturbations, semantic perturbations (e.g. rotation, translation) raise…

2022

Smoothed Embeddings for Certified Few-Shot Learning

NeurIPS 2022accept

Randomized smoothing is considered to be the state-of-the-art provable defense against adversarial perturbations. However, it heavily exploits the fact that classifiers map input objects to class probabilities and do not focus on the ones that learn a metric space in which classification is performe…