[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119418-en":3,"doc-seo-119418-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119418,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","PROSAC - Provably Safe Certification for Machine Learning Models Under Adversarial Attacks","State-of-the-art machine learning models, including vision and language systems, can be seriously compromised by adversarial perturbations, making rigorous certification increasingly important. The paper introduces a population-level safety guarantee framework: for a given attack, an (α,ζ) guarantee ensures a model is certified as having adversarial risk below α, with probability at most ζ of falsely declaring safety. A calibration-based testing procedure and Bayesian optimization algorithms are proposed to decide (α,ζ)-safety efficiently, with statistical guarantees. Experiments on ViT and ResNet variants under attacks such as AutoAttack, SquareAttack, and natural evolution strategies illustrate the framework’s value and comparative robustness insights.","PROSAC: PROVABLY SAFE CERTIFICATION FOR MACHINE LEARNING MODELS UNDER ADVERSARIAL ATTACKS  \nAnonymous authors  \nPaper under double-blind review  \nABSTRACT  \nIt is widely known that state-of-the-art machine learning models—including vision and language models—can be seriously compromised by adversarial perturbations, so it is also increasingly relevant to develop capability to certify their performance in the presence of the most effective adversarial attacks. Our paper offers a new approach to certify the performance of machine learning models in the presence of adversarial attacks, with population level risk guarantees. In particular, given a specific attack, we introduce the notion of a (α,ζ) machine learning model safety guarantee: this guarantee, which is supported by a testing procedure based on the availability of a calibration set, entails one will only declare that a machine learning model adversarial (population) risk is less than α(i.e. the model is safe) given that the model adversarial (population) risk is higher than α (i.e. the model is in fact unsafe), with probability less than ζ . We also propose Bayesian optimization algorithms to determine very efficiently whether or not a machine learning model is (α,ζ)-safe in the presence of an adversarial attack, along with their statistical guarantees. We apply our framework to a range of machine learning models—including various sizes of vision Transformer (ViT) and ResNet models—impaired by a variety of adversarial attacks such as AutoAttack, SquareAttack and natural evolution strategy attack, in order to illustrate the merit of our approach. Of particular relevance, we show that ViT’s are generally more robust to adversarial attacks than ResNets and ViT-large is more robust than smaller models. Overall, our approach goes beyond existing empirical adversarial risk based certification guarantees, paving the way to more effective AI regulation based on rigorous (and provable) performance guarantees.  \n1 INTRODUCTION  \nWith the development of increasingly capable autonomous machine learning systems and their use in a range of domains from healthcare to banking and finance, education, and e-commerce, to name just a few, policy makers across the world are in the process of formulating detailed regulatory requirements that will apply to developers and operators of AI systems. The EU is at the forefront of the drive to regulate AI systems. Proposals for an EU AI Act, an AI Liability Directive, and an extension of the EU Product Liability Directive to AI systems and AI-enabled goods are at advanced stages of the legislative process. Other jurisdictions, too, pursue a variety of regulatory initiatives. In some countries, such as the United States and the UK, these initiatives consist so far mostly in highlevel principles designed to guide regulators in the interpretation and application of sector-specific regulation to AI. In others, such as China, policy makers have adopted highly detailed regulations that are often tailored to specific techniques, for example generative AI (Sheehan, 2023) .  \nWhere detailed regulation exists or has been proposed, as in the EU, it typically operates from two angles. Some regulatory instruments establish ex ante and ongoing requirements that are a precondition for the (continued) operation of an AI system. The proposed EU AI Act is a prime example of this approach. Depending on the risk level of a system, it requires, for example, an assessment of conformity with applicable standards, as well as compliance with risk management, testing, data governance, transparency, and cybersecurity requirements. Other regulatory instruments, such as  \nthe proposed EU AI Liability Directive, seek to facilitate the recovery of damages if end users are injured as a result of the operation of an AI system.  \nIn both cases, regulation presupposes that it is technically possible to develop certification procedures that can provide rigorous (provable) performance ","cbCaigC2oEnFdtuP","https://ap.wps.com/l/cbCaigC2oEnFdtuP","pdf",578338,1,14,"English","en",105,"# Abstract\n# Introduction","[{\"question\":\"What problem does PROSAC address in machine learning under adversarial attacks?\",\"answer\":\"It addresses the need to certify model performance against strong adversarial perturbations with rigorous, provable guarantees rather than relying on purely empirical checks.\"},{\"question\":\"What is an (α,ζ) machine learning model safety guarantee?\",\"answer\":\"Given a specific attack, an (α,ζ) guarantee means the procedure will only declare the model adversarial (population) risk is less than α (safe), and the chance of a wrong declaration is bounded by ζ when the true risk is actually higher than α (unsafe).\"},{\"question\":\"How does the paper determine whether a model is (α,ζ)-safe, and what evidence is used?\",\"answer\":\"It uses a testing procedure supported by availability of a calibration set, and proposes Bayesian optimization algorithms to decide (α,ζ)-safety efficiently, together with statistical guarantees. The framework is applied to ViT and ResNet models under multiple attacks to demonstrate effectiveness and robustness differences.\"}]","PROSAC - Provably Safe Certification for Machine Learning Models Under Adversarial Attacks | PDF",1785724196,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"prosac-provably-safe-certification-for-machine-learning-models-under-adversarial-attacks","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/prosac-provably-safe-certification-for-machine-learning-models-under-adversarial-attacks/119418/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does PROSAC address in machine learning under adversarial attacks?","Question",{"text":75,"@type":76},"It addresses the need to certify model performance against strong adversarial perturbations with rigorous, provable guarantees rather than relying on purely empirical checks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is an (α,ζ) machine learning model safety guarantee?",{"text":80,"@type":76},"Given a specific attack, an (α,ζ) guarantee means the procedure will only declare the model adversarial (population) risk is less than α (safe), and the chance of a wrong declaration is bounded by ζ when the true risk is actually higher than α (unsafe).",{"name":82,"@type":73,"acceptedAnswer":83},"How does the paper determine whether a model is (α,ζ)-safe, and what evidence is used?",{"text":84,"@type":76},"It uses a testing procedure supported by availability of a calibration set, and proposes Bayesian optimization algorithms to decide (α,ζ)-safety efficiently, together with statistical guarantees. The framework is applied to ViT and ResNet models under multiple attacks to demonstrate effectiveness and robustness differences.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]