ICML 2025oral0 citations

Position: Certified Robustness Does Not (Yet) Imply Model Security

Andrew Craig Cullen, Paul Montague, Sarah Monazam Erfani, Benjamin I. P. Rubinstein

Abstract

While certified robustness is widely promoted as a solution to adversarial examples in Artificial Intelligence systems, significant challenges remain before these techniques can be meaningfully deployed in real-world applications. We identify critical gaps in current research, including the paradox of detection without distinction, the lack of clear criteria for practitioners to evaluate certification schemes, and the potential security risks arising from users' expectations surrounding ``guaranteed" robustness claims. This position paper is a call to arms for the certification research community, proposing concrete steps to address these fundamental challenges and advance the field toward practical applicability.

Certified RobustnessRandomised SmoothingSecurity
BibTeX
@inproceedings{
cullen2025position,
title={Position: Certified Robustness Does Not (Yet) Imply Model Security},
author={Andrew Craig Cullen and Paul Montague and Sarah Monazam Erfani and Benjamin I. P. Rubinstein},
booktitle={Forty-second International Conference on Machine Learning Position Paper Track},
year={2025},
url={https://openreview.net/forum?id=GrBXso0e17}
}
Position: Certified Robustness Does Not (Yet) Imply Model Security · ICML 2025