{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T20:17:22Z","timestamp":1784837842412,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,6,18]],"date-time":"2021-06-18T00:00:00Z","timestamp":1623974400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000781","name":"European Research Council","doi-asserted-by":"publisher","award":["680358"],"award-info":[{"award-number":["680358"]}],"id":[{"id":"10.13039\/501100000781","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,6,19]]},"DOI":"10.1145\/3453483.3454056","type":"proceedings-article","created":{"date-parts":[[2021,6,24]],"date-time":"2021-06-24T16:58:48Z","timestamp":1624553928000},"page":"466-481","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":16,"title":["Fast and precise certification of transformers"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9921-4292","authenticated-orcid":false,"given":"Gregory","family":"Bonaert","sequence":"first","affiliation":[{"name":"ETH Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9813-0900","authenticated-orcid":false,"given":"Dimitar I.","family":"Dimitrov","sequence":"additional","affiliation":[{"name":"ETH Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9271-6422","authenticated-orcid":false,"given":"Maximilian","family":"Baader","sequence":"additional","affiliation":[{"name":"ETH Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"Vechev","sequence":"additional","affiliation":[{"name":"ETH Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,18]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/d18-1316"},{"key":"e_1_3_2_2_2_1","volume-title":"Jamie Ryan Kiros, and Geoffrey E. Hinton","author":"Ba Lei Jimmy","year":"2016","unstructured":"Lei Jimmy Ba , Jamie Ryan Kiros, and Geoffrey E. Hinton . 2016 . Layer Normalization. CoRR , abs\/1607.06450 (2016). Lei Jimmy Ba, Jamie Ryan Kiros, and Geoffrey E. Hinton. 2016. Layer Normalization. CoRR, abs\/1607.06450 (2016)."},{"key":"e_1_3_2_2_3_1","volume-title":"Vechev","author":"Balunovic Mislav","year":"2019","unstructured":"Mislav Balunovic , Maximilian Baader , Gagandeep Singh , Timon Gehr , and Martin T . Vechev . 2019 . Certifying Geometric Robustness of Neural Networks. In NeurIPS. 15287\u201315297. Mislav Balunovic, Maximilian Baader, Gagandeep Singh, Timon Gehr, and Martin T. Vechev. 2019. Certifying Geometric Robustness of Neural Networks. In NeurIPS. 15287\u201315297."},{"key":"e_1_3_2_2_4_1","volume-title":"Adversarial Training and Provable Defenses: Bridging the Gap. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SJxSDxrKDr","author":"Balunovic Mislav","year":"2020","unstructured":"Mislav Balunovic and Martin Vechev . 2020 . Adversarial Training and Provable Defenses: Bridging the Gap. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SJxSDxrKDr Mislav Balunovic and Martin Vechev. 2020. Adversarial Training and Provable Defenses: Bridging the Gap. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SJxSDxrKDr"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682430"},{"key":"e_1_3_2_2_6_1","unstructured":"Rudy Bunel Ilker Turkaslan Philip H. S. Torr Pushmeet Kohli and Pawan Kumar Mudigonda. 2018. A Unified View of Piecewise Linear Neural Network Verification. In NeurIPS. 4795\u20134804.  Rudy Bunel Ilker Turkaslan Philip H. S. Torr Pushmeet Kohli and Pawan Kumar Mudigonda. 2018. A Unified View of Piecewise Linear Neural Network Verification. In NeurIPS. 4795\u20134804."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58452-8_13"},{"key":"e_1_3_2_2_8_1","volume-title":"ICML (Proceedings of Machine Learning Research","volume":"1320","author":"Cohen Jeremy M.","unstructured":"Jeremy M. Cohen , Elan Rosenfeld , and J. Zico Kolter . 2019. Certified Adversarial Robustness via Randomized Smoothing . In ICML (Proceedings of Machine Learning Research , Vol. 97). PMLR, 1310\u2013 1320 . Jeremy M. Cohen, Elan Rosenfeld, and J. Zico Kolter. 2019. Certified Adversarial Robustness via Randomized Smoothing. In ICML (Proceedings of Machine Learning Research, Vol. 97). PMLR, 1310\u20131320."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/n19-1423"},{"key":"e_1_3_2_2_10_1","volume-title":"An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. CoRR, abs\/2010.11929","author":"Dosovitskiy Alexey","year":"2020","unstructured":"Alexey Dosovitskiy , Lucas Beyer , Alexander Kolesnikov , Dirk Weissenborn , Xiaohua Zhai , Thomas Unterthiner , Mostafa Dehghani , Matthias Minderer , Georg Heigold , Sylvain Gelly , Jakob Uszkoreit , and Neil Houlsby . 2020. An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. CoRR, abs\/2010.11929 ( 2020 ). Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, Jakob Uszkoreit, and Neil Houlsby. 2020. An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. CoRR, abs\/2010.11929 (2020)."},{"key":"e_1_3_2_2_11_1","volume-title":"A Dual Approach to Scalable Verification of Deep Networks","author":"Dvijotham Krishnamurthy","unstructured":"Krishnamurthy Dvijotham , Robert Stanforth , Sven Gowal , Timothy A. Mann , and Pushmeet Kohli . 2018. A Dual Approach to Scalable Verification of Deep Networks . In UAI. AUAI Press , 550\u2013559. Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy A. Mann, and Pushmeet Kohli. 2018. A Dual Approach to Scalable Verification of Deep Networks. In UAI. AUAI Press, 550\u2013559."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68167-2_19"},{"key":"e_1_3_2_2_13_1","volume-title":"ICML (Proceedings of Machine Learning Research","volume":"1811","author":"Engstrom Logan","year":"2019","unstructured":"Logan Engstrom , Brandon Tran , Dimitris Tsipras , Ludwig Schmidt , and Aleksander Madry . 2019 . Exploring the Landscape of Spatial Robustness . In ICML (Proceedings of Machine Learning Research , Vol. 97). PMLR, 1802\u2013 1811 . Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2019. Exploring the Landscape of Spatial Robustness. In ICML (Proceedings of Machine Learning Research, Vol. 97). PMLR, 1802\u20131811."},{"key":"e_1_3_2_2_14_1","unstructured":"Marc Fischer Maximilian Baader and Martin Vechev. 2020. Certified Defense to Image Transformations via Randomized Smoothing. NeurIPS 33.  Marc Fischer Maximilian Baader and Martin Vechev. 2020. Certified Defense to Image Transformations via Randomized Smoothing. NeurIPS 33."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00058"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02658-4_47"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14295-6_22"},{"key":"e_1_3_2_2_18_1","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR (Poster).  Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR (Poster)."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11823230_3"},{"key":"e_1_3_2_2_20_1","volume-title":"Conformer: Convolution-augmented Transformer for Speech Recognition. In INTERSPEECH. ISCA, 5036\u20135040. https:\/\/doi.org\/10.21437\/Interspeech.2020-3015","author":"Gulati Anmol","year":"2020","unstructured":"Anmol Gulati , James Qin , Chung-Cheng Chiu , Niki Parmar , Yu Zhang , Jiahui Yu , Wei Han , Shibo Wang , Zhengdong Zhang , Yonghui Wu , and Ruoming Pang . 2020 . Conformer: Convolution-augmented Transformer for Speech Recognition. In INTERSPEECH. ISCA, 5036\u20135040. https:\/\/doi.org\/10.21437\/Interspeech.2020-3015 10.21437\/Interspeech.2020-3015 Anmol Gulati, James Qin, Chung-Cheng Chiu, Niki Parmar, Yu Zhang, Jiahui Yu, Wei Han, Shibo Wang, Zhengdong Zhang, Yonghui Wu, and Ruoming Pang. 2020. Conformer: Convolution-augmented Transformer for Speech Recognition. In INTERSPEECH. ISCA, 5036\u20135040. https:\/\/doi.org\/10.21437\/Interspeech.2020-3015"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/p19-1147"},{"key":"e_1_3_2_2_23_1","volume-title":"Joey Tianyi Zhou, and Peter Szolovits","author":"Jin Di","year":"2020","unstructured":"Di Jin , Zhijing Jin , Joey Tianyi Zhou, and Peter Szolovits . 2020 . Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment. In AAAI. AAAI Press , 8018\u20138025. Di Jin, Zhijing Jin, Joey Tianyi Zhou, and Peter Szolovits. 2020. Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment. In AAAI. AAAI Press, 8018\u20138025."},{"key":"e_1_3_2_2_24_1","volume-title":"Dimakis","author":"Jordan Matt","year":"2019","unstructured":"Matt Jordan , Justin Lewis , and Alexandros G . Dimakis . 2019 . Provable Certificates for Adversarial Examples: Fitting a Ball in the Union of Polytopes . In NeurIPS. 14059\u201314069. Matt Jordan, Justin Lewis, and Alexandros G. Dimakis. 2019. Provable Certificates for Adversarial Examples: Fitting a Ball in the Union of Polytopes. In NeurIPS. 14059\u201314069."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00467"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_2_27_1","volume-title":"ALBERT: A Lite BERT for Self-supervised Learning of Language Representations. In ICLR. OpenReview.net.","author":"Lan Zhenzhong","year":"2020","unstructured":"Zhenzhong Lan , Mingda Chen , Sebastian Goodman , Kevin Gimpel , Piyush Sharma , and Radu Soricut . 2020 . ALBERT: A Lite BERT for Self-supervised Learning of Language Representations. In ICLR. OpenReview.net. Zhenzhong Lan, Mingda Chen, Sebastian Goodman, Kevin Gimpel, Piyush Sharma, and Radu Soricut. 2020. ALBERT: A Lite BERT for Self-supervised Learning of Language Representations. In ICLR. OpenReview.net."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_2_30_1","volume-title":"Second-Order Adversarial Attack and Certifiable Robustness. CoRR, abs\/1809.03113","author":"Li Bai","year":"2018","unstructured":"Bai Li , Changyou Chen , Wenlin Wang , and Lawrence Carin . 2018. Second-Order Adversarial Attack and Certifiable Robustness. CoRR, abs\/1809.03113 ( 2018 ). Bai Li, Changyou Chen, Wenlin Wang, and Lawrence Carin. 2018. Second-Order Adversarial Attack and Certifiable Robustness. CoRR, abs\/1809.03113 (2018)."},{"key":"e_1_3_2_2_31_1","volume-title":"TextBugger: Generating Adversarial Text Against Real-world Applications","author":"Li Jinfeng","unstructured":"Jinfeng Li , Shouling Ji , Tianyu Du , Bo Li , and Ting Wang . 2019. TextBugger: Generating Adversarial Text Against Real-world Applications . In NDSS. The Internet Society . Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. 2019. TextBugger: Generating Adversarial Text Against Real-world Applications. In NDSS. The Internet Society."},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313461"},{"key":"e_1_3_2_2_33_1","volume-title":"VisualBERT: A Simple and Performant Baseline for Vision and Language. CoRR, abs\/1908.03557","author":"Li Liunian Harold","year":"2019","unstructured":"Liunian Harold Li , Mark Yatskar , Da Yin , Cho-Jui Hsieh , and Kai-Wei Chang . 2019. VisualBERT: A Simple and Performant Baseline for Vision and Language. CoRR, abs\/1908.03557 ( 2019 ). Liunian Harold Li, Mark Yatskar, Da Yin, Cho-Jui Hsieh, and Kai-Wei Chang. 2019. VisualBERT: A Simple and Performant Baseline for Vision and Language. CoRR, abs\/1908.03557 (2019)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/585"},{"key":"e_1_3_2_2_35_1","volume-title":"Swin Transformer: Hierarchical Vision Transformer using Shifted Windows. arxiv:2103.14030.","author":"Liu Ze","year":"2021","unstructured":"Ze Liu , Yutong Lin , Yue Cao , Han Hu , Yixuan Wei , Zheng Zhang , Stephen Lin , and Baining Guo . 2021 . Swin Transformer: Hierarchical Vision Transformer using Shifted Windows. arxiv:2103.14030. Ze Liu, Yutong Lin, Yue Cao, Han Hu, Yixuan Wei, Zheng Zhang, Stephen Lin, and Baining Guo. 2021. Swin Transformer: Hierarchical Vision Transformer using Shifted Windows. arxiv:2103.14030."},{"key":"e_1_3_2_2_36_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In ICLR (Poster). OpenReview.net.  Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In ICLR (Poster). OpenReview.net."},{"key":"e_1_3_2_2_37_1","volume-title":"Vechev","author":"Mirman Matthew","year":"2018","unstructured":"Matthew Mirman , Timon Gehr , and Martin T . Vechev . 2018 . Differentiable Abstract Interpretation for Provably Robust Neural Networks. In ICML (Proceedings of Machine Learning Research , Vol. 80). PMLR, 3575\u2013 3583 . Matthew Mirman, Timon Gehr, and Martin T. Vechev. 2018. Differentiable Abstract Interpretation for Provably Robust Neural Networks. In ICML (Proceedings of Machine Learning Research, Vol. 80). PMLR, 3575\u20133583."},{"key":"e_1_3_2_2_38_1","volume-title":"Vechev","author":"Mirman Matthew","year":"2019","unstructured":"Matthew Mirman , Gagandeep Singh , and Martin T . Vechev . 2019 . A Provable Defense for Deep Residual Networks. CoRR , abs\/1903.12519 (2019), arxiv:1903.12519 Matthew Mirman, Gagandeep Singh, and Martin T. Vechev. 2019. A Provable Defense for Deep Residual Networks. CoRR, abs\/1903.12519 (2019), arxiv:1903.12519"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00032"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/n16-1018"},{"key":"e_1_3_2_2_41_1","volume-title":"International Conference on Learning Representations.","author":"Mueller Mark Niklas","year":"2021","unstructured":"Mark Niklas Mueller , Mislav Balunovic , and Martin Vechev . 2021 . Boosting Certified Robustness of Deep Networks via a Compositional Architecture . In International Conference on Learning Representations. Mark Niklas Mueller, Mislav Balunovic, and Martin Vechev. 2021. Boosting Certified Robustness of Deep Networks via a Compositional Architecture. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_42_1","volume-title":"Towards Practical Verification of Machine Learning: The Case of Computer Vision Systems. CoRR, abs\/1712.01785","author":"Pei Kexin","year":"2017","unstructured":"Kexin Pei , Yinzhi Cao , Junfeng Yang , and Suman Jana . 2017. Towards Practical Verification of Machine Learning: The Case of Computer Vision Systems. CoRR, abs\/1712.01785 ( 2017 ). Kexin Pei, Yinzhi Cao, Junfeng Yang, and Suman Jana. 2017. Towards Practical Verification of Machine Learning: The Case of Computer Vision Systems. CoRR, abs\/1712.01785 (2017)."},{"key":"e_1_3_2_2_43_1","volume-title":"Functional Analysis","author":"Rudin W.","unstructured":"W. Rudin . 1991. Functional Analysis ( second ed.). McGraw-Hill , 92\u201395. isbn:9780070542365 W. Rudin. 1991. Functional Analysis (second ed.). McGraw-Hill, 92\u201395. isbn:9780070542365"},{"key":"e_1_3_2_2_44_1","volume-title":"Vechev","author":"Ruoss Anian","year":"2020","unstructured":"Anian Ruoss , Maximilian Baader , Mislav Balunovic , and Martin T . Vechev . 2020 . Efficient Certification of Spatial Robustness. CoRR , abs\/2009.09318 (2020). Anian Ruoss, Maximilian Baader, Mislav Balunovic, and Martin T. Vechev. 2020. Efficient Certification of Spatial Robustness. CoRR, abs\/2009.09318 (2020)."},{"key":"e_1_3_2_2_45_1","unstructured":"Hadi Salman Jerry Li Ilya P. Razenshteyn Pengchuan Zhang Huan Zhang S\u00e9bastien Bubeck and Greg Yang. 2019. Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers. In NeurIPS. 11289\u201311300.  Hadi Salman Jerry Li Ilya P. Razenshteyn Pengchuan Zhang Huan Zhang S\u00e9bastien Bubeck and Greg Yang. 2019. Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers. In NeurIPS. 11289\u201311300."},{"key":"e_1_3_2_2_46_1","unstructured":"Hadi Salman Greg Yang Huan Zhang Cho-Jui Hsieh and Pengchuan Zhang. 2019. A Convex Relaxation Barrier to Tight Robustness Verification of Neural Networks. In NeurIPS. 9832\u20139842.  Hadi Salman Greg Yang Huan Zhang Cho-Jui Hsieh and Pengchuan Zhang. 2019. A Convex Relaxation Barrier to Tight Robustness Verification of Neural Networks. In NeurIPS. 9832\u20139842."},{"key":"e_1_3_2_2_47_1","unstructured":"Zhouxing Shi Huan Zhang Kai-Wei Chang Minlie Huang and Cho-Jui Hsieh. 2020. Robustness Verification for Transformers. In ICLR. OpenReview.net.  Zhouxing Shi Huan Zhang Kai-Wei Chang Minlie Huang and Cho-Jui Hsieh. 2020. Robustness Verification for Transformers. In ICLR. OpenReview.net."},{"key":"e_1_3_2_2_48_1","volume-title":"Vechev","author":"Singh Gagandeep","year":"2019","unstructured":"Gagandeep Singh , Rupanshu Ganvir , Markus P\u00fcschel , and Martin T . Vechev . 2019 . Beyond the Single Neuron Convex Barrier for Neural Network Certification. In NeurIPS. 15072\u201315083. Gagandeep Singh, Rupanshu Ganvir, Markus P\u00fcschel, and Martin T. Vechev. 2019. Beyond the Single Neuron Convex Barrier for Neural Network Certification. In NeurIPS. 15072\u201315083."},{"key":"e_1_3_2_2_49_1","volume-title":"Vechev","author":"Singh Gagandeep","year":"2018","unstructured":"Gagandeep Singh , Timon Gehr , Matthew Mirman , Markus P\u00fcschel , and Martin T . Vechev . 2018 . Fast and Effective Robustness Certification. In NeurIPS. 10825\u201310836. Gagandeep Singh, Timon Gehr, Matthew Mirman, Markus P\u00fcschel, and Martin T. Vechev. 2018. Fast and Effective Robustness Certification. In NeurIPS. 10825\u201310836."},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290354"},{"key":"e_1_3_2_2_51_1","unstructured":"Richard Socher Alex Perelygin Jean Wu Jason Chuang Christopher D. Manning Andrew Y. Ng and Christopher Potts. 2013. Recursive Deep Models for Semantic Compositionality Over a Sentiment Treebank. In EMNLP. ACL 1631\u20131642.  Richard Socher Alex Perelygin Jean Wu Jason Chuang Christopher D. Manning Andrew Y. Ng and Christopher Potts. 2013. Recursive Deep Models for Semantic Compositionality Over a Sentiment Treebank. In EMNLP. ACL 1631\u20131642."},{"key":"e_1_3_2_2_52_1","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian J. Goodfellow and Rob Fergus. 2014. Intriguing properties of neural networks. In ICLR (Poster).  Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian J. Goodfellow and Rob Fergus. 2014. Intriguing properties of neural networks. In ICLR (Poster)."},{"key":"e_1_3_2_2_53_1","unstructured":"Vincent Tjeng Kai Y. Xiao and Russ Tedrake. 2019. Evaluating Robustness of Neural Networks with Mixed Integer Programming. In ICLR (Poster). OpenReview.net.  Vincent Tjeng Kai Y. Xiao and Russ Tedrake. 2019. Evaluating Robustness of Neural Networks with Mixed Integer Programming. In ICLR (Poster). OpenReview.net."},{"key":"e_1_3_2_2_54_1","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N. Gomez Lukasz Kaiser and Illia Polosukhin. 2017. Attention is All you Need. In NIPS. 5998\u20136008.  Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N. Gomez Lukasz Kaiser and Illia Polosukhin. 2017. Attention is All you Need. In NIPS. 5998\u20136008."},{"key":"e_1_3_2_2_55_1","volume-title":"Dhillon","author":"Weng Tsui-Wei","year":"2018","unstructured":"Tsui-Wei Weng , Huan Zhang , Hongge Chen , Zhao Song , Cho-Jui Hsieh , Luca Daniel , Duane S. Boning , and Inderjit S . Dhillon . 2018 . Towards Fast Computation of Certified Robustness for ReLU Networks. In ICML (Proceedings of Machine Learning Research , Vol. 80). PMLR, 5273\u2013 5282 . Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane S. Boning, and Inderjit S. Dhillon. 2018. Towards Fast Computation of Certified Robustness for ReLU Networks. In ICML (Proceedings of Machine Learning Research, Vol. 80). PMLR, 5273\u20135282."},{"key":"e_1_3_2_2_56_1","volume-title":"ICML (Proceedings of Machine Learning Research","volume":"5292","author":"Wong Eric","unstructured":"Eric Wong and J. Zico Kolter . 2018. Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope . In ICML (Proceedings of Machine Learning Research , Vol. 80). PMLR, 5283\u2013 5292 . Eric Wong and J. Zico Kolter. 2018. Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope. In ICML (Proceedings of Machine Learning Research, Vol. 80). PMLR, 5283\u20135292."},{"key":"e_1_3_2_2_57_1","volume-title":"Automatic Perturbation Analysis on General Computational Graphs. CoRR, abs\/2002.12920","author":"Xu Kaidi","year":"2020","unstructured":"Kaidi Xu , Zhouxing Shi , Huan Zhang , Minlie Huang , Kai-Wei Chang , Bhavya Kailkhura , Xue Lin , and Cho-Jui Hsieh . 2020. Automatic Perturbation Analysis on General Computational Graphs. CoRR, abs\/2002.12920 ( 2020 ). Kaidi Xu, Zhouxing Shi, Huan Zhang, Minlie Huang, Kai-Wei Chang, Bhavya Kailkhura, Xue Lin, and Cho-Jui Hsieh. 2020. Automatic Perturbation Analysis on General Computational Graphs. CoRR, abs\/2002.12920 (2020)."},{"key":"e_1_3_2_2_58_1","volume-title":"Le","author":"Yang Zhilin","year":"2019","unstructured":"Zhilin Yang , Zihang Dai , Yiming Yang , Jaime G. Carbonell , Ruslan Salakhutdinov , and Quoc V . Le . 2019 . XLNet: Generalized Autoregressive Pretraining for Language Understanding. In NeurIPS. 5754\u20135764. Zhilin Yang, Zihang Dai, Yiming Yang, Jaime G. Carbonell, Ruslan Salakhutdinov, and Quoc V. Le. 2019. XLNet: Generalized Autoregressive Pretraining for Language Understanding. In NeurIPS. 5754\u20135764."},{"key":"e_1_3_2_2_59_1","volume-title":"ICML (Proceedings of Machine Learning Research","volume":"7363","author":"Zhang Han","year":"2019","unstructured":"Han Zhang , Ian J. Goodfellow , Dimitris N. Metaxas , and Augustus Odena . 2019 . Self-Attention Generative Adversarial Networks . In ICML (Proceedings of Machine Learning Research , Vol. 97). PMLR, 7354\u2013 7363 . Han Zhang, Ian J. Goodfellow, Dimitris N. Metaxas, and Augustus Odena. 2019. Self-Attention Generative Adversarial Networks. In ICML (Proceedings of Machine Learning Research, Vol. 97). PMLR, 7354\u20137363."},{"key":"e_1_3_2_2_60_1","unstructured":"Huan Zhang Tsui-Wei Weng Pin-Yu Chen Cho-Jui Hsieh and Luca Daniel. 2018. Efficient Neural Network Robustness Certification with General Activation Functions. In NeurIPS. 4944\u20134953.  Huan Zhang Tsui-Wei Weng Pin-Yu Chen Cho-Jui Hsieh and Luca Daniel. 2018. Efficient Neural Network Robustness Certification with General Activation Functions. In NeurIPS. 4944\u20134953."},{"key":"e_1_3_2_2_61_1","unstructured":"Xiang Zhang Junbo Zhao and Yann LeCun. 2015. Character-Level Convolutional Networks for Text Classification. arXiv:1509.01626 [cs] Sept. arxiv:1509.01626.  Xiang Zhang Junbo Zhao and Yann LeCun. 2015. Character-Level Convolutional Networks for Text Classification. arXiv:1509.01626 [cs] Sept. arxiv:1509.01626."},{"key":"e_1_3_2_2_62_1","volume-title":"ICML (Proceedings of Machine Learning Research","volume":"11032","author":"Zhang Yuhao","year":"2020","unstructured":"Yuhao Zhang , Aws Albarghouthi , and Loris D\u2019Antoni . 2020 . Robustness to Programmable String Transformations via Augmented Abstract Training . In ICML (Proceedings of Machine Learning Research , Vol. 119). PMLR, 11023\u2013 11032 . Yuhao Zhang, Aws Albarghouthi, and Loris D\u2019Antoni. 2020. Robustness to Programmable String Transformations via Augmented Abstract Training. In ICML (Proceedings of Machine Learning Research, Vol. 119). PMLR, 11023\u201311032."}],"event":{"name":"PLDI '21: 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation","location":"Virtual Canada","acronym":"PLDI '21","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages"]},"container-title":["Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3453483.3454056","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3453483.3454056","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:47:47Z","timestamp":1750193267000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3453483.3454056"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,18]]},"references-count":62,"alternative-id":["10.1145\/3453483.3454056","10.1145\/3453483"],"URL":"https:\/\/doi.org\/10.1145\/3453483.3454056","relation":{},"subject":[],"published":{"date-parts":[[2021,6,18]]},"assertion":[{"value":"2021-06-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}