{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:18:56Z","timestamp":1780633136509,"version":"3.54.1"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031851803","type":"print"},{"value":"9783031851810","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-85181-0_5","type":"book-chapter","created":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T06:58:14Z","timestamp":1745305094000},"page":"71-85","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["FullCert: Deterministic End-to-End Certification for\u00a0Training and\u00a0Inference of\u00a0Neural Networks"],"prefix":"10.1007","author":[{"given":"Tobias","family":"Lorenz","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marta","family":"Kwiatkowska","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mario","family":"Fritz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,23]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Boopathy, A., Weng, T.W., Chen, P.Y., Liu, S., Daniel, L.: CNN-cert: an efficient framework for certifying robustness of convolutional neural networks. In: AAAI Conference on Artificial Intelligence (AAAI) (2019)","DOI":"10.1609\/aaai.v33i01.33013240"},{"key":"5_CR2","unstructured":"Bose, A., Udell, M., Lessard, L., Fazel, M., Dvijotham, K.D.: Certifying robustness to adaptive data poisoning. In: ICML Workshop: Foundations of Reinforcement Learning and Control\u2013Connections and Perspectives (2024)"},{"key":"5_CR3","doi-asserted-by":"crossref","unstructured":"Bottou, L.: Online learning and stochastic approximations. On-Line Learning in Neural Networks (1998)","DOI":"10.1017\/CBO9780511569920.003"},{"key":"5_CR4","unstructured":"Brown, T., et\u00a0al.: Language models are few-shot learners. In: Advances in Neural Information Processing Systems (NeurIPS) (2020)"},{"key":"5_CR5","unstructured":"Carlini, N., Tramer, F., Dvijotham, K.D., Rice, L., Sun, M., Kolter, J.Z.: (certified!!) adversarial robustness for free! In: International Conference on Learning Representations (ICLR) (2023)"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Cousot, P., Cousot, R.: Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints. In: Symposium on Principles of programming languages (POPL) (1977)","DOI":"10.1145\/512950.512973"},{"key":"5_CR7","unstructured":"Diep, N.H.: Efficient implementation of interval matrix multiplication. In: International Conference on Applied Parallel and Scientific Computing (2010)"},{"key":"5_CR8","unstructured":"Dosovitskiy, A., et al.: An image is worth 16x16 words: transformers for image recognition at scale. In: International Conference on Learning Representations (ICLR) (2021)"},{"key":"5_CR9","unstructured":"Ferrari, C., Mueller, M.N., Jovanovi\u0107, N., Vechev, M.: Complete verification via multi-neuron relaxation guided branch-and-bound. In: International Conference on Learning Representations (ICLR) (2022)"},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"Gehr, T., Mirman, M., Drachsler-Cohen, D., Tsankov, P., Chaudhuri, S., Vechev, M.: Ai2: Safety and robustness certification of neural networks with abstract interpretation. In: 2018 IEEE Symposium on Security and Privacy (S &P) (2018)","DOI":"10.1109\/SP.2018.00058"},{"key":"5_CR11","unstructured":"Goodfellow, I., Bengio, Y., Courville, A.: Deep Learning. MIT Press (2016)"},{"key":"5_CR12","unstructured":"Goodfellow, I., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: International Conference on Learning Representations (ICLR) (2015)"},{"key":"5_CR13","unstructured":"Gowal, S., et al.: On the effectiveness of interval bound propagation for training verifiably robust models. arXiv preprint arXiv:1810.12715 (2018)"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Jia, J., Cao, X., Gong, N.Z.: Intrinsic certified robustness of bagging against data poisoning attacks. In: AAAI Conference on Artificial Intelligence (AAAI) (2021)","DOI":"10.1609\/aaai.v35i9.16971"},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"Jia, J., Liu, Y., Cao, X., Gong, N.Z.: Certified robustness of nearest neighbors against data poisoning and backdoor attacks. In: AAAI Conference on Artificial Intelligence (AAAI) (2022)","DOI":"10.1609\/aaai.v36i9.21191"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Katz, G., Barrett, C., Dill, D.L., Julian, K., Kochenderfer, M.J.: Reluplex: an efficient SMT solver for verifying deep neural networks. In: International Conference on Computer Aided Verification (CAV) (2017)","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"Koh, P.W., Steinhardt, J., Liang, P.: Stronger data poisoning attacks break data sanitization defenses. Mach. Learn. (2022)","DOI":"10.1007\/s10994-021-06119-y"},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"LeCun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. In: Proceedings of the IEEE (1998)","DOI":"10.1109\/5.726791"},{"key":"5_CR19","unstructured":"Levine, A., Feizi, S.: Deep partition aggregation: Provable defenses against general poisoning attacks. In: International Conference on Learning Representations (ICLR) (2021)"},{"key":"5_CR20","unstructured":"Mirman, M., Gehr, T., Vechev, M.: Differentiable abstract interpretation for provably robust neural networks. In: International Conference on Machine Learning (ICML) (2018)"},{"key":"5_CR21","unstructured":"OpenAI: ChatGPT: optimizing language models for dialogue (2022). https:\/\/openai.com\/blog\/chatgpt\/. Accessed 17 May 2023"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Sinha, A., Wellman, M.: SOK: security and privacy in machine learning. In: European Symposium on Security and Privacy (EuroS &P) (2018)","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"5_CR23","unstructured":"Paszke, A.: PyTorch: an imperative style, high-performance deep learning library. In: Advances in Neural Information Processing Systems (NeurIPS) (2019)"},{"key":"5_CR24","unstructured":"Rosenfeld, E., Winston, E., Ravikumar, P., Kolter, Z.: Certified robustness to label-flipping attacks via randomized smoothing. In: International Conference on Machine Learning (ICML) (2020)"},{"key":"5_CR25","doi-asserted-by":"crossref","unstructured":"Rump, S.M.: Fast and parallel interval arithmetic. BIT Numerical Mathematics (1999)","DOI":"10.1023\/A:1022374804152"},{"key":"5_CR26","unstructured":"Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J.P., Goldstein, T.: Just how toxic is data poisoning? a unified benchmark for backdoor and data poisoning attacks. In: International Conference on Machine Learning (ICML) (2021)"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Singh, G., Gehr, T., P\u00fcschel, M., Vechev, M.: An abstract domain for certifying neural networks. In: Proceedings of the ACM on Programming Languages (PACMPL) (2019)","DOI":"10.1145\/3290354"},{"key":"5_CR28","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: International Conference on Learning Representations (ICLR) (2014)"},{"key":"5_CR29","doi-asserted-by":"crossref","unstructured":"Tian, Z., Cui, L., Liang, J., Yu, S.: A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Computing Surveys (2022)","DOI":"10.1145\/3551636"},{"key":"5_CR30","unstructured":"Wang, B., Cao, X., Gong, N.Z., et\u00a0al.: On certifying robustness against backdoor attacks via randomized smoothing. arXiv preprint arXiv:2002.11750 (2020)"},{"key":"5_CR31","unstructured":"Wang, W., Feizi, S.: Temporal robustness against data poisoning. In: Advances in Neural Information Processing Systems (NeurIPS) (2023)"},{"key":"5_CR32","unstructured":"Wang, W., Levine, A.J., Feizi, S.: Improved certified defenses against data poisoning with (deterministic) finite aggregation. In: International Conference on Machine Learning (ICML) (2022)"},{"key":"5_CR33","doi-asserted-by":"crossref","unstructured":"Weber, M., Xu, X., Karla\u0161, B., Zhang, C., Li, B.: RAB: provable robustness against backdoor attacks. In: IEEE Symposium on Security and Privacy (S &P) (2023)","DOI":"10.1109\/SP46215.2023.10179451"},{"key":"5_CR34","unstructured":"Weng, L., et al.: Towards fast computation of certified robustness for relu networks. In: International Conference on Machine Learning (ICML) (2018)"},{"key":"5_CR35","unstructured":"Zhang, H., Weng, T.W., Chen, P.Y., Hsieh, C.J., Daniel, L.: Efficient neural network robustness certification with general activation functions. In: Advances in Neural Information Processing Systems (NeurIPS) (2018)"},{"key":"5_CR36","unstructured":"Zhang, Y., Albarghouthi, A., D\u2019Antoni, L.: Bagflip: a certified defense against data poisoning. In: Advances in Neural Information Processing Systems (NeurIPS) (2022)"},{"key":"5_CR37","doi-asserted-by":"crossref","unstructured":"Zhong, H., Liao, C., Squicciarini, A.C., Zhu, S., Miller, D.: Backdoor embedding in convolutional neural network models via invisible perturbation. In: Conference on Data and Application Security and Privacy (CODASPY) (2020)","DOI":"10.1145\/3374664.3375751"}],"container-title":["Lecture Notes in Computer Science","Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-85181-0_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,23]],"date-time":"2025-09-23T13:15:49Z","timestamp":1758633349000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-85181-0_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031851803","9783031851810"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-85181-0_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"23 April 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}