← Search

Quoc Viet Vo

2 accepted papers

2026

Certified but Fooled! Breaking Certified Defenses with Ghost Certificates

AAAI 2026technical

Certified defenses promise provable robustness guarantees. We study the malicious exploitation of probabilistic certification frameworks to better understand the limits of guarantee provisions. Now, the objective is to not only mislead a classifier, but also to manipulate the certification process t

Cited by 0SourcePDFScholar
2024

BRUSLEATTACK: A QUERY-EFFICIENT SCORE- BASED BLACK-BOX SPARSE ADVERSARIAL ATTACK

ICLR 2024poster

We study the unique, less-well understood problem of generating sparse adversarial samples simply by observing the score-based replies to model queries. Sparse attacks aim to discover a minimum number—the $l_0$ bounded—perturbations to model inputs to craft adversarial examples and misguide model de…

Cited by 8SourcePDFScholar