cs.CROct 7, 2026

MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking

Authors: Qilin Zhou, Zhengyuan Wei, Haipeng Wang, Zhuo Wang, Shuo Liu, W. K. Chan

Abstract

In post-deployment time, inputs to deep learning models may or may not be adversarially patched. Patch robustness certification on such inputs within a patch bound can verify their label benignity and should retain high prediction accuracy. However, existing smoothing-based and masking-based recovery defenders cannot achieve both simultaneously: they degrade the prediction accuracy much and cannot verify the benignity of the returned label of an adversarially patched input, respectively. We propose MRCert, the first masking-based certified recovery defender that shows the feasibility of achieving both. Unlike all existing works to apply a common condition across both types of input (benign and adversarially patched samples) for certification, MRCert infers type-specific necessary properties of deep learning models for both types in post-deployment time and formally relates them to verify the label benignity through a novel type-oriented design of label recovery and certification function pair. Without incurring the degradation in clean accuracy caused by smoothing, experimental results confirm that MRCert achieves 35.1% adversarial certified accuracy on ImageNet at patch size 16 pixels, whereas the SOTA PatchCURE fails completely.

Explore similar work

CardsList
  1. Improving Certified Robustness via Adversarial Distillation

    Jun 30, 2026Matteo Melis, Jesus Martinez Del Rincon, Vishal SharmaNeural Network RobustnessCertified Robustness

  2. Certified Robustness from Approximate Gaussian Mixture Structures in Pretrained Latent Spaces

    May 25, 2026Konstantinos Emmanouilidis, Tianjiao Ding, Nghia Nguyen +2Neural Network RobustnessAdversarial Robustness

  3. Certified Training for Convolutional Perturbations

    Jul 20, 2026Benedikt Brückner, Alessio LomuscioImage Corruption RobustnessNeural Network Robustness