Pith. sign in

REVIEW 1 cited by

Expressive Losses for Verified Robustness via Convex Combinations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2305.13991 v3 pith:DRVK6VQT submitted 2023-05-23 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords lossadversarialexpressivelossesperformancerobustnesstrade-offsworst-case
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In order to train networks for verified adversarial robustness, it is common to over-approximate the worst-case loss over perturbation regions, resulting in networks that attain verifiability at the expense of standard performance. As shown in recent work, better trade-offs between accuracy and robustness can be obtained by carefully coupling adversarial training with over-approximations. We hypothesize that the expressivity of a loss function, which we formalize as the ability to span a range of trade-offs between lower and upper bounds to the worst-case loss through a single parameter (the over-approximation coefficient), is key to attaining state-of-the-art performance. To support our hypothesis, we show that trivial expressive losses, obtained via convex combinations between adversarial attacks and IBP bounds, yield state-of-the-art results across a variety of settings in spite of their conceptual simplicity. We provide a detailed analysis of the relationship between the over-approximation coefficient and performance profiles across different expressive losses, showing that, while expressivity is essential, better approximations of the worst-case loss are not necessarily linked to superior robustness-accuracy trade-offs.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Compression Aware Certified Training

    cs.LG 2025-06 conditional novelty 5.0 of 10

    CACTUS trains a single network on pruned and weight-perturbed copies of itself, beating prior certified-training baselines on compressed MNIST and CIFAR-10 models.

Pith tools