{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T20:11:13Z","timestamp":1784232673071,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":99,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T00:00:00Z","timestamp":1636761600000},"content-version":"vor","delay-in-days":1,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-18-50725, CCF-21-24225"],"award-info":[{"award-number":["CNS-18-50725, CCF-21-24225"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014895","name":"Open Philanthropy Project","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100014895","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006785","name":"Google","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Berkeley Artificial Intelligence Research (BAIR)"},{"DOI":"10.13039\/100004705","name":"Capital One Financial Corporation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004705","id-type":"DOI","asserted-by":"publisher"}]},{"name":"J.P. Morgan"},{"name":"Institute of Information & communications Technology Planning & Evaluation (IITP) grant fundedby the Korea government (MSIT)","award":["2020-0-00153"],"award-info":[{"award-number":["2020-0-00153"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,12]]},"DOI":"10.1145\/3460120.3484776","type":"proceedings-article","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T12:05:34Z","timestamp":1636805134000},"page":"477-494","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["Learning Security Classifiers with Verified Global Robustness Properties"],"prefix":"10.1145","author":[{"given":"Yizheng","family":"Chen","sequence":"first","affiliation":[{"name":"University of California, Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiqi","family":"Wang","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yue","family":"Qin","sequence":"additional","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaojing","family":"Liao","sequence":"additional","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Suman","family":"Jana","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Wagner","sequence":"additional","affiliation":[{"name":"University of California, Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66158-2_44"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-15618-7_5"},{"key":"e_1_3_2_1_3_1","volume-title":"International Conference on Machine Learning. PMLR, 291--301","author":"Anil Cem","year":"2019","unstructured":"Cem Anil, James Lucas, and Roger Grosse. 2019. Sorting out Lipschitz function approximation. In International Conference on Machine Learning. PMLR, 291--301."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1540-5915.1993.tb00462.x"},{"key":"e_1_3_2_1_5_1","volume-title":"Certifying geometric robustness of neural networks. Advances in Neural Information Processing Systems (NeurIPS)","author":"Balunovi\u0107 Mislav","year":"2019","unstructured":"Mislav Balunovi\u0107, Maximilian Baader, Gagandeep Singh, Timon Gehr, and Martin Vechev. 2019. Certifying geometric robustness of neural networks. Advances in Neural Information Processing Systems (NeurIPS) (2019)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022655006810"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013240"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16840"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"e_1_3_2_1_10_1","volume-title":"On Training Robust PDF Malware Classifiers. In USENIX Security Symposium .","author":"Chen Yizheng","year":"2020","unstructured":"Yizheng Chen, Shiqi Wang, Dongdong She, and Suman Jana. 2020. On Training Robust PDF Malware Classifiers. In USENIX Security Symposium ."},{"key":"e_1_3_2_1_11_1","volume-title":"International Conference on Machine Learning. PMLR, 854--863","author":"Cisse Moustapha","year":"2017","unstructured":"Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier. 2017. Parseval networks: Improving robustness to adversarial examples. In International Conference on Machine Learning. PMLR, 854--863."},{"key":"e_1_3_2_1_12_1","volume-title":"2019 a. Universal lipschitz approximation in bounded depth neural networks. arXiv preprint arXiv:1904.04861","author":"Cohen Jeremy EJ","year":"2019","unstructured":"Jeremy EJ Cohen, Todd Huster, and Ra Cohen. 2019 a. Universal lipschitz approximation in bounded depth neural networks. arXiv preprint arXiv:1904.04861 (2019)."},{"key":"e_1_3_2_1_13_1","volume-title":"International Conference on Machine Learning","author":"Cohen Jeremy M","year":"2019","unstructured":"Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter. 2019 b. Certified adversarial robustness via randomized smoothing. International Conference on Machine Learning (2019)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2020\/673"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.2010.2044803"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87479-9_38"},{"key":"e_1_3_2_1_17_1","volume-title":"Output Range Analysis for Deep Feedforward Neural Networks. In NASA Formal Methods Symposium. Springer, 121--138","author":"Dutta Souradeep","year":"2018","unstructured":"Souradeep Dutta, Susmit Jha, Sriram Sankaranarayanan, and Ashish Tiwari. 2018. Output Range Analysis for Deep Feedforward Neural Networks. In NASA Formal Methods Symposium. Springer, 121--138."},{"key":"e_1_3_2_1_18_1","volume-title":"Training verified learners with learned verifiers. arXiv preprint arXiv:1805.10265","author":"Dvijotham Krishnamurthy","year":"2018","unstructured":"Krishnamurthy Dvijotham, Sven Gowal, Robert Stanforth, Relja Arandjelovic, Brendan O'Donoghue, Jonathan Uesato, and Pushmeet Kohli. 2018a. Training verified learners with learned verifiers. arXiv preprint arXiv:1805.10265 (2018)."},{"key":"e_1_3_2_1_19_1","volume-title":"A dual approach to scalable verification of deep networks. arXiv preprint arXiv:1803.06567","author":"Dvijotham Krishnamurthy","year":"2018","unstructured":"Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy Mann, and Pushmeet Kohli. 2018b. A dual approach to scalable verification of deep networks. arXiv preprint arXiv:1803.06567 (2018)."},{"key":"e_1_3_2_1_20_1","volume-title":"Formal Verification of Piece-Wise Linear Feed-Forward Neural Networks. 15th International Symposium on Automated Technology for Verification and Analysis","author":"Ehlers Ruediger","year":"2017","unstructured":"Ruediger Ehlers. 2017. Formal Verification of Piece-Wise Linear Feed-Forward Neural Networks. 15th International Symposium on Automated Technology for Verification and Analysis (2017)."},{"key":"e_1_3_2_1_21_1","volume-title":"International Conference on Learning Representations .","author":"Farnia Farzan","year":"2018","unstructured":"Farzan Farnia, Jesse Zhang, and David Tse. 2018. Generalizable Adversarial Training via Spectral Normalization. In International Conference on Learning Representations ."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2010.92"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.mlwa.2020.100017"},{"key":"e_1_3_2_1_24_1","volume-title":"International Conference on Machine Learning (ICML) .","author":"Fischer Marc","year":"2019","unstructured":"Marc Fischer, Mislav Balunovic, Dana Drachsler-Cohen, Timon Gehr, Ce Zhang, and Martin Vechev. 2019. DL2: Training and Querying Neural Networks with Logic. In International Conference on Machine Learning (ICML) ."},{"key":"e_1_3_2_1_25_1","volume-title":"Deep Neural Networks as 0--1 Mixed Integer Linear Programs: A Feasibility Study. arXiv preprint arXiv:1712.06174","author":"Fischetti Matteo","year":"2017","unstructured":"Matteo Fischetti and Jason Jo. 2017. Deep Neural Networks as 0--1 Mixed Integer Linear Programs: A Feasibility Study. arXiv preprint arXiv:1712.06174 (2017)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1214\/07-AOAS148"},{"key":"e_1_3_2_1_27_1","volume-title":"IEEE Symposium on Security and Privacy (SP) .","author":"Gehr Timon","year":"2018","unstructured":"Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev. 2018. Ai 2: Safety and robustness certification of neural networks with abstract interpretation. In IEEE Symposium on Security and Privacy (SP) ."},{"key":"e_1_3_2_1_28_1","unstructured":"Maxim Goncharov. [n.d.]. Traffic direction systems as malware distribution tools. http:\/\/www.trendmicro.es\/media\/misc\/malware-distribution-tools-research-paper-en.pdf ."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-020-05929-w"},{"key":"e_1_3_2_1_30_1","volume-title":"Adversarial perturbations against deep neural networks for malware classification. arXiv preprint arXiv:1606.04435","author":"Grosse Kathrin","year":"2016","unstructured":"Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel. 2016. Adversarial perturbations against deep neural networks for malware classification. arXiv preprint arXiv:1606.04435 (2016)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/2946645.3007062"},{"key":"e_1_3_2_1_32_1","unstructured":"Matthias Hein and Maksym Andriushchenko. 2017. Formal guarantees on the robustness of a classifier against adversarial manipulation. In Advances in Neural Information Processing Systems ."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_1"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180445.3180449"},{"key":"e_1_3_2_1_35_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Jia Jinyuan","year":"2019","unstructured":"Jinyuan Jia, Xiaoyu Cao, Binghui Wang, and Neil Zhenqiang Gong. 2019. Certified robustness for top-k predictions against adversarial perturbations via randomized smoothing. International Conference on Learning Representations (ICLR) (2019)."},{"key":"e_1_3_2_1_36_1","volume-title":"International Conference on Machine Learning. 2387--2396","author":"Kantchelian Alex","year":"2016","unstructured":"Alex Kantchelian, JD Tygar, and Anthony Joseph. 2016. Evasion and hardening of tree ensemble classifiers. In International Conference on Machine Learning. 2387--2396."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-25540-4_26"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1002\/aic.690461211"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313665"},{"key":"e_1_3_2_1_41_1","volume-title":"International Conference on Learning Representations (ICLR) .","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2017. Adversarial machine learning at scale. In International Conference on Learning Representations (ICLR) ."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57529-2_18"},{"key":"e_1_3_2_1_43_1","volume-title":"Security and Privacy (SP), 2014 IEEE Symposium on. IEEE, 197--211","author":"Pavel","unstructured":"Pavel Laskov et al. 2014. Practical evasion of a learning-based classifier: A case study. In Security and Privacy (SP), 2014 IEEE Symposium on. IEEE, 197--211."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_1_45_1","unstructured":"Kyumin Lee James Caverlee and Steve Webb. 2010. Uncovering social spammers: social honeypots"},{"key":"e_1_3_2_1_46_1","volume-title":"Proceedings of the 33rd international ACM SIGIR conference on Research and development in information retrieval. 435--442","unstructured":"machine learning. In Proceedings of the 33rd international ACM SIGIR conference on Research and development in information retrieval. 435--442."},{"key":"e_1_3_2_1_47_1","volume-title":"Proceedings of the International AAAI Conference on Web and Social Media","volume":"5","author":"Lee Kyumin","year":"2011","unstructured":"Kyumin Lee, Brian Eoff, and James Caverlee. 2011. Seven months with the devils: A long-term study of content polluters on twitter. In Proceedings of the International AAAI Conference on Web and Social Media, Vol. 5."},{"key":"e_1_3_2_1_48_1","volume-title":"Warningbird: A near real-time detection system for suspicious urls in twitter stream","author":"Lee Sangho","year":"2013","unstructured":"Sangho Lee and Jong Kim. 2013. Warningbird: A near real-time detection system for suspicious urls in twitter stream. IEEE transactions on dependable and secure computing, Vol. 10, 3 (2013), 183--195."},{"key":"e_1_3_2_1_49_1","volume-title":"Lipschitz-Certifiable Training with a Tight Outer Bound. Advances in Neural Information Processing Systems (NeurIPS)","author":"Lee Sungyoon","year":"2020","unstructured":"Sungyoon Lee, Jaewook Lee, and Saerom Park. 2020. Lipschitz-Certifiable Training with a Tight Outer Bound. Advances in Neural Information Processing Systems (NeurIPS) (2020)."},{"key":"e_1_3_2_1_50_1","volume-title":"Globally-Robust Neural Networks. arXiv preprint arXiv:2102.08452","author":"Leino Klas","year":"2021","unstructured":"Klas Leino, Zifan Wang, and Matt Fredrikson. 2021. Globally-Robust Neural Networks. arXiv preprint arXiv:2102.08452 (2021)."},{"key":"e_1_3_2_1_51_1","unstructured":"Bai Li Changyou Chen Wenlin Wang and Lawrence Carin. 2018. Second-order adversarial attack and certifiable robustness. (2018)."},{"key":"e_1_3_2_1_52_1","volume-title":"2019 a. Certified adversarial robustness with additive noise. Advances in Neural Information Processing Systems (NeurIPS)","author":"Li Bai","year":"2019","unstructured":"Bai Li, Changyou Chen, Wenlin Wang, and Lawrence Carin. 2019 a. Certified adversarial robustness with additive noise. Advances in Neural Information Processing Systems (NeurIPS) (2019)."},{"key":"e_1_3_2_1_53_1","volume-title":"SoK: Certified Robustness for Deep Neural Networks. arXiv preprint arXiv:2009.04131","author":"Li Linyi","year":"2020","unstructured":"Linyi Li, Xiangyu Qi, Tao Xie, and Bo Li. 2020. SoK: Certified Robustness for Deep Neural Networks. arXiv preprint arXiv:2009.04131 (2020)."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"crossref","unstructured":"Linyi Li Zexuan Zhong Bo Li and Tao Xie. 2019 b. Robustra: Training Provable Robust Neural Networks over Reference Adversarial Space. In IJCAI .","DOI":"10.24963\/ijcai.2019\/654"},{"key":"e_1_3_2_1_55_1","volume-title":"2013 IEEE Symposium on Security and Privacy. IEEE, 112--126","author":"Li Zhou","year":"2013","unstructured":"Zhou Li, Sumayah Alrwais, Yinglian Xie, Fang Yu, and XiaoFeng Wang. 2013. Finding the linchpins of the dark web: a study on topologically dedicated hosts on malicious web infrastructures. In 2013 IEEE Symposium on Security and Privacy. IEEE, 112--126."},{"key":"e_1_3_2_1_56_1","volume-title":"ART: abstraction refinement-guided training for provably correct neural networks. In 2020 Formal Methods in Computer Aided Design (FMCAD)","author":"Lin Xuankang","unstructured":"Xuankang Lin, He Zhu, Roopsha Samanta, and Suresh Jagannathan. 2020. ART: abstraction refinement-guided training for provably correct neural networks. In 2020 Formal Methods in Computer Aided Design (FMCAD). IEEE, 148--157."},{"key":"e_1_3_2_1_57_1","volume-title":"An approach to reachability analysis for feed-forward relu neural networks. arXiv preprint arXiv:1706.07351","author":"Lomuscio Alessio","year":"2017","unstructured":"Alessio Lomuscio and Lalit Maganti. 2017. An approach to reachability analysis for feed-forward relu neural networks. arXiv preprint arXiv:1706.07351 (2017)."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1553374.1553462"},{"key":"e_1_3_2_1_59_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. International Conference on Learning Representations (ICLR) (2018)."},{"key":"e_1_3_2_1_60_1","volume-title":"Can Domain Knowledge Alleviate Adversarial Attacks in Multi-Label Classifiers? arXiv preprint arXiv:2006.03833","author":"Melacci Stefano","year":"2020","unstructured":"Stefano Melacci, Gabriele Ciravegna, Angelo Sotgiu, Ambra Demontis, Battista Biggio, Marco Gori, and Fabio Roli. 2020. Can Domain Knowledge Alleviate Adversarial Attacks in Multi-Label Classifiers? arXiv preprint arXiv:2006.03833 (2020)."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_7"},{"key":"e_1_3_2_1_62_1","volume-title":"Differentiable Abstract Interpretation for Provably Robust Neural Networks. In International Conference on Machine Learning (ICML). 3575--3583","author":"Mirman Matthew","year":"2018","unstructured":"Matthew Mirman, Timon Gehr, and Martin Vechev. 2018. Differentiable Abstract Interpretation for Provably Robust Neural Networks. In International Conference on Machine Learning (ICML). 3575--3583."},{"key":"e_1_3_2_1_63_1","volume-title":"Scaling Polyhedral Neural Network Verification on GPUs. Proceedings of Machine Learning and Systems","volume":"3","author":"M\u00fcller Christoph","year":"2021","unstructured":"Christoph M\u00fcller, Francc ois Serre, Gagandeep Singh, Markus P\u00fcschel, and Martin Vechev. 2021 b. Scaling Polyhedral Neural Network Verification on GPUs. Proceedings of Machine Learning and Systems, Vol. 3 (2021)."},{"key":"e_1_3_2_1_64_1","volume-title":"2021 a. Precise Multi-Neuron Abstractions for Neural Network Certification. arXiv preprint arXiv:2103.03638","author":"M\u00fcller Mark Niklas","year":"2021","unstructured":"Mark Niklas M\u00fcller, Gleb Makarchuk, Gagandeep Singh, Markus P\u00fcschel, and Martin Vechev. 2021 a. Precise Multi-Neuron Abstractions for Neural Network Certification. arXiv preprint arXiv:2103.03638 (2021)."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.23919\/ACC50511.2021.9482773"},{"key":"e_1_3_2_1_66_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Pendlebury Feargus","year":"2019","unstructured":"Feargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder, and Lorenzo Cavallaro. 2019. TESSERACT: Eliminating experimental bias in malware classification across space and time. In 28th USENIX Security Symposium (USENIX Security 19). 729--746."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_3_2_1_68_1","volume-title":"Adversarial robustness through local linearization. Advances in Neural Information Processing Systems (NIPS)","author":"Qin Chongli","year":"2019","unstructured":"Chongli Qin, James Martens, Sven Gowal, Dilip Krishnan, Krishnamurthy Dvijotham, Alhussein Fawzi, Soham De, Robert Stanforth, and Pushmeet Kohli. 2019. Adversarial robustness through local linearization. Advances in Neural Information Processing Systems (NIPS) (2019)."},{"key":"e_1_3_2_1_69_1","volume-title":"Proceedings of the ACM on Programming Languages","volume":"4","author":"Raghothaman Mukund","year":"2019","unstructured":"Mukund Raghothaman, Jonathan Mendelson, David Zhao, Mayur Naik, and Bernhard Scholz. 2019. Provenance-guided synthesis of Datalog programs. Proceedings of the ACM on Programming Languages, Vol. 4, POPL (2019), 1--27."},{"key":"e_1_3_2_1_70_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Raghunathan Aditi","year":"2018","unstructured":"Aditi Raghunathan, Jacob Steinhardt, and Percy Liang. 2018a. Certified defenses against adversarial examples. International Conference on Learning Representations (ICLR) (2018)."},{"key":"e_1_3_2_1_71_1","unstructured":"Aditi Raghunathan Jacob Steinhardt and Percy S Liang. 2018b. Semidefinite relaxations for certifying robustness to adversarial examples. In Advances in Neural Information Processing Systems. 10900--10910."},{"key":"e_1_3_2_1_72_1","volume-title":"International Conference on Learning Representations (ICLR) .","author":"Ryan Gabriel","year":"2020","unstructured":"Gabriel Ryan, Justin Wong, Jianan Yao, Ronghui Gu, and Suman Jana. 2020. CLN2INV: Learning Loop Invariants with Continuous Logic Networks. In International Conference on Learning Representations (ICLR) ."},{"key":"e_1_3_2_1_73_1","volume-title":"2019 a. Provably robust deep learning via adversarially trained smoothed classifiers. Advances in Neural Information Processing Systems (NeurIPS)","author":"Salman Hadi","year":"2019","unstructured":"Hadi Salman, Greg Yang, Jerry Li, Pengchuan Zhang, Huan Zhang, Ilya Razenshteyn, and Sebastien Bubeck. 2019 a. Provably robust deep learning via adversarially trained smoothed classifiers. Advances in Neural Information Processing Systems (NeurIPS) (2019)."},{"key":"e_1_3_2_1_74_1","volume-title":"2019 b. A convex relaxation barrier to tight robustness verification of neural networks. Advances in Neural Information Processing Systems (NeurIPS)","author":"Salman Hadi","year":"2019","unstructured":"Hadi Salman, Greg Yang, Huan Zhang, Cho-Jui Hsieh, and Pengchuan Zhang. 2019 b. A convex relaxation barrier to tight robustness verification of neural networks. Advances in Neural Information Processing Systems (NeurIPS) (2019)."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236034"},{"key":"e_1_3_2_1_76_1","volume-title":"2019 a. Beyond the single neuron convex barrier for neural network certification. Advances in Neural Information Processing Systems (NeurIPS)","author":"Singh Gagandeep","year":"2019","unstructured":"Gagandeep Singh, Rupanshu Ganvir, Markus P\u00fcschel, and Martin Vechev. 2019 a. Beyond the single neuron convex barrier for neural network certification. Advances in Neural Information Processing Systems (NeurIPS) (2019)."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290354"},{"key":"e_1_3_2_1_78_1","unstructured":"Gagandeep Singh Timon Gehr Markus P\u00fcschel and Martin T Vechev. 2019 c. Boosting Robustness Certification of Neural Networks.. In ICLR (Poster) ."},{"key":"e_1_3_2_1_79_1","volume-title":"Bounding singular values of convolution layers. arXiv preprint arXiv:1911.10258","author":"Singla Sahil","year":"2019","unstructured":"Sahil Singla and Soheil Feizi. 2019. Bounding singular values of convolution layers. arXiv preprint arXiv:1911.10258 (2019)."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/1168857.1168907"},{"key":"e_1_3_2_1_81_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. International Conference on Learning Representations (ICLR) (2013)."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.25"},{"key":"e_1_3_2_1_83_1","volume-title":"Evaluating Robustness of Neural Networks with Mixed Integer Programming. arXiv preprint arXiv:1711.07356","author":"Tjeng Vincent","year":"2017","unstructured":"Vincent Tjeng, Kai Xiao, and Russ Tedrake. 2017. Evaluating Robustness of Neural Networks with Mixed Integer Programming. arXiv preprint arXiv:1711.07356 (2017)."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_3_2_1_85_1","volume-title":"MixTrain: Scalable Training of Formally Robust Neural Networks. arXiv preprint arXiv:1811.02625","author":"Wang Shiqi","year":"2018","unstructured":"Shiqi Wang, Yizheng Chen, Ahmed Abdou, and Suman Jana. 2018a. MixTrain: Scalable Training of Formally Robust Neural Networks. arXiv preprint arXiv:1811.02625 (2018)."},{"key":"e_1_3_2_1_86_1","volume-title":"Efficient Formal Safety Analysis of Neural Networks. Advances in Neural Information Processing Systems (NIPS)","author":"Wang Shiqi","year":"2018","unstructured":"Shiqi Wang, Kexin Pei, Whitehouse Justin, Junfeng Yang, and Suman Jana. 2018b. Efficient Formal Safety Analysis of Neural Networks. Advances in Neural Information Processing Systems (NIPS) (2018)."},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277323"},{"key":"e_1_3_2_1_88_1","volume-title":"Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Complete and Incomplete Neural Network Verification. arXiv preprint arXiv:2103.06624","author":"Wang Shiqi","year":"2021","unstructured":"Shiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin, Suman Jana, Cho-Jui Hsieh, and J Zico Kolter. 2021. Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Complete and Incomplete Neural Network Verification. arXiv preprint arXiv:2103.06624 (2021)."},{"key":"e_1_3_2_1_89_1","unstructured":"Antoine Wehenkel and Gilles Louppe. 2019. Unconstrained monotonic neural networks. In Advances in Neural Information Processing Systems ."},{"key":"e_1_3_2_1_90_1","volume-title":"International Conference on Machine Learning (ICML) .","author":"Weng Lily","year":"2018","unstructured":"Lily Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane Boning, and Inderjit Dhillon. 2018a. Towards fast computation of certified robustness for relu networks. In International Conference on Machine Learning (ICML) ."},{"key":"e_1_3_2_1_91_1","volume-title":"International Conference on Learning Representations (ICLR) .","author":"Weng Tsui-Wei","year":"2018","unstructured":"Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen, Jinfeng Yi, Dong Su, Yupeng Gao, Cho-Jui Hsieh, and Luca Daniel. 2018b. Evaluating the robustness of neural networks: An extreme value theory approach. In International Conference on Learning Representations (ICLR) ."},{"key":"e_1_3_2_1_92_1","volume-title":"International Conference on Machine Learning. 5283--5292","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In International Conference on Machine Learning. 5283--5292."},{"key":"e_1_3_2_1_93_1","volume-title":"Jan Hendrik Metzen, and J Zico Kolter","author":"Wong Eric","year":"2018","unstructured":"Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J Zico Kolter. 2018. Scaling provable adversarial defenses. Advances in Neural Information Processing Systems (NIPS) (2018)."},{"key":"e_1_3_2_1_94_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Xu Kaidi","year":"2021","unstructured":"Kaidi Xu, Huan Zhang, Shiqi Wang, Yihan Wang, Suman Jana, Xue Lin, and Cho-Jui Hsieh. 2021. Fast and complete: Enabling complete neural network verification with rapid and massively parallel incomplete verifiers. International Conference on Learning Representations (ICLR) (2021)."},{"key":"e_1_3_2_1_95_1","volume-title":"International Conference on Machine Learning (ICML). PMLR.","author":"Yang Greg","year":"2020","unstructured":"Greg Yang, Tony Duan, J Edward Hu, Hadi Salman, Ilya Razenshteyn, and Jerry Li. 2020. Randomized smoothing of all shapes and sizes. In International Conference on Machine Learning (ICML). PMLR."},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3385986"},{"key":"e_1_3_2_1_97_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Zhang Huan","year":"2020","unstructured":"Huan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal, Robert Stanforth, Bo Li, Duane Boning, and Cho-Jui Hsieh. 2020. Towards stable and efficient training of verifiably robust neural networks. International Conference on Learning Representations (ICLR) (2020)."},{"key":"e_1_3_2_1_98_1","volume-title":"Efficient neural network robustness certification with general activation functions. arXiv preprint arXiv:1811.00866","author":"Zhang Huan","year":"2018","unstructured":"Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel. 2018. Efficient neural network robustness certification with general activation functions. arXiv preprint arXiv:1811.00866 (2018)."},{"key":"e_1_3_2_1_99_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Zhang Xiao","year":"2019","unstructured":"Xiao Zhang and David Evans. 2019. Cost-Sensitive Robustness against Adversarial Examples. International Conference on Learning Representations (ICLR) (2019)."}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event Republic of Korea","acronym":"CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484776","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3484776","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3484776","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T20:53:10Z","timestamp":1763499190000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484776"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,12]]},"references-count":99,"alternative-id":["10.1145\/3460120.3484776","10.1145\/3460120"],"URL":"https:\/\/doi.org\/10.1145\/3460120.3484776","relation":{},"subject":[],"published":{"date-parts":[[2021,11,12]]},"assertion":[{"value":"2021-11-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}