{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T02:40:00Z","timestamp":1774838400051,"version":"3.50.1"},"publisher-location":"Cham","reference-count":54,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031736490","type":"print"},{"value":"9783031736506","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,11,21]],"date-time":"2024-11-21T00:00:00Z","timestamp":1732147200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,21]],"date-time":"2024-11-21T00:00:00Z","timestamp":1732147200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-73650-6_14","type":"book-chapter","created":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T18:17:51Z","timestamp":1732126671000},"page":"233-250","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Cross-Input Certified Training for\u00a0Universal Perturbations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3079-5652","authenticated-orcid":false,"given":"Changming","family":"Xu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9299-2961","authenticated-orcid":false,"given":"Gagandeep","family":"Singh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,21]]},"reference":[{"key":"14_CR1","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., Kwok, K.: Synthesizing robust adversarial examples. In: International Conference on Machine Learning, pp. 284\u2013293. PMLR (2018)"},{"key":"14_CR2","unstructured":"Balunovi\u0107, M., Vechev, M.: Adversarial training and provable defenses: Bridging the gap. In: 8th International Conference on Learning Representations (ICLR 2020) (virtual). International Conference on Learning Representations (2020)"},{"key":"14_CR3","unstructured":"Banerjee, D., Singh, G.: Relational DNN verification with cross executional bound refinement. arXiv preprint arXiv:2405.10143 (2024)"},{"key":"14_CR4","doi-asserted-by":"publisher","unstructured":"Banerjee, D., Xu, C., Singh, G.: Input-relational verification of deep neural networks. Proc. ACM Program. Lang. 8(PLDI) (2024). https:\/\/doi.org\/10.1145\/3656377","DOI":"10.1145\/3656377"},{"key":"14_CR5","doi-asserted-by":"crossref","unstructured":"Benz, P., Zhang, C., Karjauv, A., Kweon, I.S.: Universal adversarial training with class-wise perturbations. In: 2021 IEEE International Conference on Multimedia and Expo (ICME), pp.\u00a01\u20136. IEEE (2021)","DOI":"10.1109\/ICME51207.2021.9428419"},{"key":"14_CR6","unstructured":"Carlini, N., Tramer, F., Dvijotham, K.D., Rice, L., Sun, M., Kolter, J.Z.: (certified!!) adversarial robustness for free! In: The Eleventh International Conference on Learning Representations (2023)"},{"key":"14_CR7","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"14_CR8","unstructured":"Cohen, J., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In: International Conference on Machine Learning, pp. 1310\u20131320. PMLR (2019)"},{"key":"14_CR9","first-page":"5318","volume":"33","author":"S Dathathri","year":"2020","unstructured":"Dathathri, S.: Enabling certification of verification-agnostic networks via memory-efficient semidefinite programming. Adv. Neural. Inf. Process. Syst. 33, 5318\u20135331 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR10","unstructured":"De\u00a0Palma, A., Behl, H.S., Bunel, R., Torr, P.H.S., Kumar, M.P.: Scaling the convex barrier with active sets. In: International Conference on Learning Representations (2021)"},{"issue":"6","key":"14_CR11","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The mnist database of handwritten digit images for machine learning research. IEEE Signal Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Signal Process. Mag."},{"key":"14_CR12","unstructured":"Dimitrov, D.I., Singh, G., Gehr, T., Vechev, M.: Provably robust adversarial examples. In: International Conference on Learning Representations (2021)"},{"key":"14_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"269","DOI":"10.1007\/978-3-319-68167-2_19","volume-title":"Automated Technology for Verification and Analysis","author":"R Ehlers","year":"2017","unstructured":"Ehlers, R.: Formal verification of piece-wise linear feed-forward neural networks. In: D\u2019Souza, D., Narayan Kumar, K. (eds.) ATVA 2017. LNCS, vol. 10482, pp. 269\u2013286. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-68167-2_19"},{"issue":"6433","key":"14_CR14","doi-asserted-by":"publisher","first-page":"1287","DOI":"10.1126\/science.aaw4399","volume":"363","author":"SG Finlayson","year":"2019","unstructured":"Finlayson, S.G., Bowers, J.D., Ito, J., Zittrain, J.L., Beam, A.L., Kohane, I.S.: Adversarial attacks on medical machine learning. Science 363(6433), 1287\u20131289 (2019)","journal-title":"Science"},{"key":"14_CR15","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"14_CR16","unstructured":"Gowal, S., et al.: On the effectiveness of interval bound propagation for training verifiably robust models. arXiv e-prints pp. arXiv\u20131810 (2018)"},{"issue":"3","key":"14_CR17","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1002\/rob.21918","volume":"37","author":"S Grigorescu","year":"2020","unstructured":"Grigorescu, S., Trasnea, B., Cocias, T., Macesanu, G.: A survey of deep learning techniques for autonomous driving. J. Field Robot. 37(3), 362\u2013386 (2020)","journal-title":"J. Field Robot."},{"key":"14_CR18","unstructured":"Jovanovic, N., Balunovic, M., Baader, M., Vechev, M.: On the paradox of certified training. Trans. Mach. Learn. Res. (2022)"},{"key":"14_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1007\/978-3-319-63387-9_5","volume-title":"Computer Aided Verification","author":"G Katz","year":"2017","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., Kochenderfer, M.J.: Reluplex: an efficient smt solver for verifying deep neural networks. In: Majumdar, R., Kun\u010dak, V. (eds.) CAV 2017, Part I. LNCS, vol. 10426, pp. 97\u2013117. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63387-9_5"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Katz, G., et al.: The marabou framework for verification and analysis of deep neural networks. In: Proceedings of Computer Aided Verification CAV, vol. 11561, pp. 443\u2013452 (2019)","DOI":"10.1007\/978-3-030-25540-4_26"},{"issue":"1","key":"14_CR21","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1016\/S0933-3657(01)00077-X","volume":"23","author":"I Kononenko","year":"2001","unstructured":"Kononenko, I.: Machine learning for medical diagnosis: history, state of the art and perspective. Artif. Intell. Med. 23(1), 89\u2013109 (2001)","journal-title":"Artif. Intell. Med."},{"key":"14_CR22","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"14_CR23","unstructured":"Le, Y., Yang, X.S.: Tiny imagenet visual recognition challenge (2015). https:\/\/api.semanticscholar.org\/CorpusID:16664790"},{"key":"14_CR24","unstructured":"Li, J., Qu, S., Li, X., Szurley, J., Kolter, J.Z., Metze, F.: Adversarial music: real world audio adversary against wake-word detection system. In: Proceedings of Neural Information Processing Systems (NeurIPS), pp. 11908\u201311918 (2019)"},{"key":"14_CR25","unstructured":"Li, J., Schmidt, F.R., Kolter, J.Z.: Adversarial camera stickers: a physical camera-based attack on deep learning systems. In: Proceedings of International Conference on Machine Learning, ICML, vol.\u00a097, pp. 3896\u20133904 (2019)"},{"key":"14_CR26","unstructured":"Liu, Z., et\u00a0al.: Exploring practical vulnerabilities of machine learning-based wireless systems. In: 20th USENIX Symposium on Networked Systems Design and Implementation (NSDI 23), pp. 1801\u20131817 (2023)"},{"key":"14_CR27","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations (2018)"},{"key":"14_CR28","unstructured":"Mao, Y., M\u00fcller, M.N., Fischer, M., Vechev, M.: Taps: Connecting certified and adversarial training. arXiv e-prints pp. arXiv\u20132305 (2023)"},{"key":"14_CR29","unstructured":"Mirman, M., Gehr, T., Vechev, M.: Differentiable abstract interpretation for provably robust neural networks. In: International Conference on Machine Learning, pp. 3578\u20133586. PMLR (2018)"},{"key":"14_CR30","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1765\u20131773 (2017)","DOI":"10.1109\/CVPR.2017.17"},{"key":"14_CR31","unstructured":"Mueller, M.N., Eckert, F., Fischer, M., Vechev, M.: Certified training: small boxes are all you need. In: The Eleventh International Conference on Learning Representations (2022)"},{"key":"14_CR32","doi-asserted-by":"crossref","unstructured":"M\u00fcller, M.N., Makarchuk, G., Singh, G., P\u00fcschel, M., Vechev, M.: Prima: general and precise neural network certification via scalable convex hull approximations. In: Proceedings of the ACM on Programming Languages vol. 6, no. POPL, pp. 1\u201333 (2022)","DOI":"10.1145\/3498704"},{"key":"14_CR33","unstructured":"Paszke, A., et\u00a0al.: Pytorch: an imperative style, high-performance deep learning library. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"14_CR34","unstructured":"Perolat, J., Malinowski, M., Piot, B., Pietquin, O.: Playing the game of universal adversarial perturbations. arXiv preprint arXiv:1809.07802 (2018)"},{"key":"14_CR35","unstructured":"Raghunathan, A., Steinhardt, J., Liang, P.S.: Semidefinite relaxations for certifying robustness to adversarial examples. In: Advances in Neural Information Processing Systems, vol. 31 (2018)"},{"key":"14_CR36","unstructured":"Salman, H., et al.: Provably robust deep learning via adversarially trained smoothed classifiers. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"14_CR37","first-page":"21945","volume":"33","author":"H Salman","year":"2020","unstructured":"Salman, H., Sun, M., Yang, G., Kapoor, A., Kolter, J.Z.: Denoised smoothing: a provable defense for pretrained classifiers. Adv. Neural. Inf. Process. Syst. 33, 21945\u201321957 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"458","DOI":"10.1007\/978-3-319-99229-7_39","volume-title":"Computer Safety, Reliability, and Security","author":"S Shafaei","year":"2018","unstructured":"Shafaei, S., Kugele, S., Osman, M.H., Knoll, A.: Uncertainty in machine learning: a safety perspective on autonomous driving. In: Gallina, B., Skavhaug, A., Schoitsch, E., Bitsch, F. (eds.) SAFECOMP 2018. LNCS, vol. 11094, pp. 458\u2013464. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-99229-7_39"},{"key":"14_CR39","doi-asserted-by":"crossref","unstructured":"Shafahi, A., Najibi, M., Xu, Z., Dickerson, J., Davis, L.S., Goldstein, T.: Universal adversarial training. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 5636\u20135643 (2020)","DOI":"10.1609\/aaai.v34i04.6017"},{"key":"14_CR40","first-page":"18335","volume":"34","author":"Z Shi","year":"2021","unstructured":"Shi, Z., Wang, Y., Zhang, H., Yi, J., Hsieh, C.J.: Fast certified robust training with short warmup. Adv. Neural. Inf. Process. Syst. 34, 18335\u201318349 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR41","unstructured":"Singh, G., Gehr, T., Mirman, M., P\u00fcschel, M., Vechev, M.: Fast and effective robustness certification. In: Advances in Neural Information Processing Systems, vol. 31 (2018)"},{"key":"14_CR42","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: Boosting robustness certification of neural networks. In: International Conference on Learning Representations (2018)"},{"key":"14_CR43","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: An abstract domain for certifying neural networks. Proceedings of the ACM on Programming Languages, vol. 3, no. POPL, pp. 1\u201330 (2019)","DOI":"10.1145\/3290354"},{"key":"14_CR44","unstructured":"Tjeng, V., Xiao, K.Y., Tedrake, R.: Evaluating robustness of neural networks with mixed integer programming. In: International Conference on Learning Representations (2018)"},{"key":"14_CR45","first-page":"1633","volume":"33","author":"F Tramer","year":"2020","unstructured":"Tramer, F., Carlini, N., Brendel, W., Madry, A.: On adaptive attacks to adversarial example defenses. Adv. Neural. Inf. Process. Syst. 33, 1633\u20131645 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR46","volume-title":"Python 3 Reference Manual","author":"G Van Rossum","year":"2009","unstructured":"Van Rossum, G., Drake, F.L.: Python 3 Reference Manual. CreateSpace, Scotts Valley, CA (2009)"},{"key":"14_CR47","unstructured":"Wang, S., Pei, K., Whitehouse, J., Yang, J., Jana, S.: Efficient formal safety analysis of neural networks. In: Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018, 3\u20138 December 2018, Montr\u00e9al, Canada, pp. 6369\u20136379 (2018). http:\/\/papers.nips.cc\/paper\/7873-efficient-formal-safety-analysis-of-neural-networks"},{"key":"14_CR48","unstructured":"Wang, S., et al.: Beta-CROWN: efficient bound propagation with per-neuron split constraints for complete and incomplete neural network verification. In: Advances in Neural Information Processing Systems, vol. 34 (2021)"},{"key":"14_CR49","unstructured":"Wong, E., Kolter, Z.: Provable defenses against adversarial examples via the convex outer adversarial polytope. In: International Conference on Machine Learning, pp. 5286\u20135295. PMLR (2018)"},{"key":"14_CR50","unstructured":"Xu, K., et al.: Fast and complete: enabling complete neural network verification with rapid and massively parallel incomplete verifiers. In: International Conference on Learning Representations (2021). https:\/\/openreview.net\/forum?id=nVZtXBI6LNn"},{"key":"14_CR51","unstructured":"Yang, R., Laurel, J., Misailovic, S., Singh, G.: Provable defense against geometric transformations. In: The Eleventh International Conference on Learning Representations (2023). https:\/\/openreview.net\/forum?id=ThXqBsRI-cY"},{"key":"14_CR52","unstructured":"Zeng, Y., Shi, Z., Jin, M., Kang, F., Lyu, L., Hsieh, C.J., Jia, R.: Towards robustness certification against universal perturbations. In: The Eleventh International Conference on Learning Representations (2022)"},{"key":"14_CR53","unstructured":"Zhang, H., Chen, H., Xiao, C., Li, B., Boning, D., Hsieh, C.J.: Towards stable and efficient training of verifiably robust neural networks. arXiv preprint arXiv:1906.06316 (2019)"},{"key":"14_CR54","unstructured":"Zhang, Y., et al.: How to robustify black-box ml models? a zeroth-order optimization perspective. In: 10th International Conference on Learning Representations, ICLR 2022 (2022)"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-73650-6_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T19:05:57Z","timestamp":1732129557000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-73650-6_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,21]]},"ISBN":["9783031736490","9783031736506"],"references-count":54,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-73650-6_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,21]]},"assertion":[{"value":"21 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}