← Search

Yuhao Mao

7 accepted papers

2025

Average Certified Radius is a Poor Metric for Randomized Smoothing

ICML 2025poster

Randomized smoothing (RS) is popular for providing certified robustness guarantees against adversarial attacks. The average certified radius (ACR) has emerged as a widely used metric for tracking progress in RS. However, in this work, for the first time we show that ACR is a poor metric for evaluati…

Cited by 1SourcePDFScholar
2024

Expressivity of ReLU-Networks under Convex Relaxations

ICLR 2024poster

Convex relaxations are a key component of training and certifying provably safe neural networks. However, despite substantial progress, a wide and poorly understood accuracy gap to standard networks remains, raising the question of whether this is due to fundamental limitations of convex relaxations…

Cited by 7SourcePDFScholar
2024

Understanding Certified Training with Interval Bound Propagation

ICLR 2024poster

As robustness verification methods are becoming more precise, training certifiably robust neural networks is becoming ever more relevant. To this end, certified training methods compute and then optimize an upper bound on the worst-case loss over a robustness specification. Curiously, training metho…

2023

Connecting Certified and Adversarial Training

NeurIPS 2023poster

Training certifiably robust neural networks remains a notoriously hard problem. While adversarial training optimizes under-approximations of the worst-case loss, which leads to insufficient regularization for certification, sound certified training methods, optimize loose over-approximations, leadin…