Rethinking Evaluation Paradigms in IBP-based Certified Training
A new arXiv paper (2606.02134) challenges the conventional evaluation of certified training methods for neural network robustness. The authors argue that reporting a single configuration of hyperparameters, which control the trade-off between natural and certified accuracy, can mislead conclusions and prevent unbiased assessments. They propose evaluating methods via Pareto front comparisons over the natural-certified accuracy trade-off, enabling fair, method-agnostic comparisons. To achieve this, they perform efficient automated multi-objective hyperparameter optimization. The paper addresses the computational cost of neural network verification, which provides rigorous robustness guarantees but is expensive, by focusing on certified training techniques that optimize for verifiable robustness during training. The work is relevant to the AI-technology sector, particularly in the context of adversarial robustness in deep learning.
Key facts
- Paper arXiv:2606.02134, announced as replace-cross.
- Focuses on certified training methods for neural network robustness.
- Highlights the trade-off between natural and certified accuracy.
- Criticizes common practice of reporting a single configuration.
- Proposes evaluation via Pareto front comparisons.
- Uses efficient automated multi-objective hyperparameter optimization.
- Addresses computational cost of neural network verification.
- Aims for fair, method-agnostic comparisons.
Entities
Institutions
- arXiv