[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118924-en":3,"doc-seo-118924-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118924,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","PROSAC - Provably Safe Certification for Machine Learning Models under Adversarial Attacks","State-of-the-art machine learning models, including vision and language systems, can be substantially compromised by adversarial perturbations, making rigorous certification increasingly necessary. PROSAC introduces a population-level safety certification method for any specified attack by defining an (α, ζ) adversarial risk guarantee. Using a calibration-set testing procedure, it can only certify that population risk is below α when the alternative that the model is unsafe above α holds with probability less than ζ. The paper also develops Bayesian optimization algorithms with statistical guarantees and evaluates them on multiple vision Transformer and ResNet models against attacks such as AutoAttack, SquareAttack, and natural evolution strategies.","PROSAC: Provably Safe Certification for Machine Learning Models under Adversarial Attacks  \nZiquan Liu 1 , Zhuo Zhi 1 , Ilija Bogunovic 1 , Carsten Gerner-Beuerle2 , Miguel R.D. Rodrigues 1  \n1Dept. Electronic and Electrical Engineering, University College London  \n2Faculty of Laws, University College London  \nAbstract  \nIt is widely known that state-of-the-art machine learning models—including vision and language models—can be seriously compromised by adversarial perturbations, so it is also increasingly relevant to develop capability to certify their performance in the presence of the most effective adversarial attacks. Our paper offers a new approach to certify the performance of machine learning models in the presence of adversarial attacks, with population level risk guarantees. In particular, given a specific attack, we introduce the notion of a (α,ζ) machine learning model safety guarantee: this guarantee, which is supported by a testing procedure based on the availability of a calibration set, entails one will only declare that a machine learning model adversarial (population) risk is less than α(i.e. the model is safe) given that the model adversarial (population) risk is higher than α (i.e. the model is in fact unsafe), with probability less than ζ . We also propose Bayesian optimization algorithms to determine very efficiently whether or not a machine learning model is (α,ζ)-safe in the presence of an adversarial attack, along with their statistical guarantees. We apply our framework to a range of machine learning models—including various sizes of vision Transformer (ViT) and ResNet models—impaired by a variety of adversarial attacks such as AutoAttack, SquareAttack and natural evolution strategy attack, in order to illustrate the merit of our approach. Of particular relevance, we show that ViT’s are generally more robust to adversarial attacks than ResNets and ViT-large is more robust than smaller models. Overall, our approach goes beyond existing empirical adversarial risk based certification guarantees, paving the way to more effective AI regulation based on rigorous (and provable) performance guarantees.  \n1 Introduction  \nWith the development of increasingly capable autonomous machine learning systems and their use in a range of domains from healthcare to banking and finance, education, and e-commerce, to name just a few, policy makers across the world are in the process of formulating detailed regulatory requirements that will apply to developers and operators of AI systems. The EU is at the forefront of the drive to regulate AI systems. Proposals for an EU AI Act, an AI Liability Directive, and an extension of the EU Product Liability Directive to AI systems and AI-enabled goods are at advanced stages of the legislative process. Other jurisdictions, too, pursue a variety of regulatory initiatives. In some countries, such as the United States and the UK, these initiatives consist so far mostly in highlevel principles designed to guide regulators in the interpretation and application of sector-specific regulation to AI. In others, such as China, policy makers have adopted highly detailed regulations that are often tailored to specific techniques, for example generative AI [1] .  \nWhere detailed regulation exists or has been proposed, as in the EU, it typically operates from two angles. Some regulatory instruments establish ex ante and ongoing requirements that are a precon  \nWorkshop on Regulatable Machine Learning at the 37th Conference on Neural Information Processing Systems (RegML @ NeurIPS 2023) .  \ndition for the (continued) operation of an AI system. The proposed EU AI Act is a prime example of this approach. Depending on the risk level of a system, it requires, for example, an assessment of conformity with applicable standards, as well as compliance with risk management, testing, data governance, transparency, and cybersecurity requirements. Other regulatory instruments, such asthe proposed EU AI Liabil","cbCaijcOpSYhsDb1","https://ap.wps.com/l/cbCaijcOpSYhsDb1","pdf",563860,1,14,"English","en",105,"# Abstract\n# Introduction\n## Regulatory context for AI certification\n## Certification requirements and challenges\n## Statistical certification approaches for black-box models","[{\"question\":\"What does PROSAC certify about a machine learning model under an adversarial attack?\",\"answer\":\"PROSAC certifies population-level adversarial risk guarantees using a (α, ζ) safety notion. It supports declarations that adversarial population risk is less than α while keeping the probability of being actually unsafe below ζ.\"},{\"question\":\"How is the (α, ζ) safety guarantee supported during testing?\",\"answer\":\"It is supported by a testing procedure that relies on the availability of a calibration set. This enables the guarantee that the unsafe case (risk higher than α) occurs with probability less than ζ.\"},{\"question\":\"What methods does the paper use to check whether a model is (α, ζ)-safe efficiently?\",\"answer\":\"The paper proposes Bayesian optimization algorithms to determine (α, ζ)-safety very efficiently in the presence of an adversarial attack, along with their statistical guarantees.\"}]","PROSAC - Provably Safe Certification for Machine Learning Models under Adversarial Attacks | PDF",1785720971,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"prosac-provably-safe-certification-for-machine-learning-models-under-adversarial-attacks","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/prosac-provably-safe-certification-for-machine-learning-models-under-adversarial-attacks/118924/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What does PROSAC certify about a machine learning model under an adversarial attack?","Question",{"text":75,"@type":76},"PROSAC certifies population-level adversarial risk guarantees using a (α, ζ) safety notion. It supports declarations that adversarial population risk is less than α while keeping the probability of being actually unsafe below ζ.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is the (α, ζ) safety guarantee supported during testing?",{"text":80,"@type":76},"It is supported by a testing procedure that relies on the availability of a calibration set. This enables the guarantee that the unsafe case (risk higher than α) occurs with probability less than ζ.",{"name":82,"@type":73,"acceptedAnswer":83},"What methods does the paper use to check whether a model is (α, ζ)-safe efficiently?",{"text":84,"@type":76},"The paper proposes Bayesian optimization algorithms to determine (α, ζ)-safety very efficiently in the presence of an adversarial attack, along with their statistical guarantees.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]