[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119649-en":3,"doc-seo-119649-105":30,"detail-sidebar-cat-0-en-105":95},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119649,13056703020460,"Valentina","https://ap-avatar.wpscdn.com/avatar/be000253dac470eee5d?_k=1778207105932848923",8,"Research & Report","PROSAC - Provably Safe Certification for Machine Learning Models under Adversarial Attacks","State-of-the-art machine learning models for vision and language can be significantly degraded by adversarial perturbations, making certification of robustness increasingly necessary. This work presents PROSAC, a certification approach with population-level risk guarantees based on (α,ζ)-safe learning. It introduces a calibration-set hypothesis testing procedure to bound the probability of incorrectly declaring safety. Efficient Bayesian optimization is proposed to determine (α,ζ)-safety under attack with statistical guarantees. Experiments on ViT and ResNet under multiple attacks show generally stronger robustness for ViTs and larger models than smaller ones, exceeding empirical certification limits.","PROSAC: Provably Safe Certification for Machine Learning Models under  \nAdversarial Attacks  \narXiv :2402 .02629v2 [ cs .LG] 17 Dec 2024  \nChen Feng 1 , Ziquan Liu2 , Zhuo Zhi 1 , Ilija Bogunovic 1 , Carsten Gerner-Beuerle3 , Miguel  \nRodrigues4  \n1Department of Electronic and Electrical Engineering, University College London  \n2 School of Electronic Engineering and Computer Science, Queen Mary University of London  \n3Faculty of Laws, University College London  \n4AI Centre, Department of Electronic and Electrical Engineering, University College London  \n[chen.feng@ucl.ac.uk](chen.feng@ucl.ac.uk), [ziquan.liu@qmul.ac.uk](ziquan.liu@qmul.ac.uk), {zhuo.zhi.21, i.bogunovic, c.gerner, [m.rodrigues](m.rodrigues}@ucl.ac.uk)[}](m.rodrigues}@ucl.ac.uk)[@ucl.ac.uk](m.rodrigues}@ucl.ac.uk)  \nAbstract  \nIt is widely known that state-of-the-art machine learning models, including vision and language models, can be seriously compromised by adversarial perturbations. It is therefore increasingly relevant to develop capabilities to certify their performance in the presence of the most effective adversarial attacks. Our paper offers a new approach to certify the performance of machine learning models in the presence of adversarial attacks with population level risk guarantees. In particular, we introduce the notion of (α,ζ)-safe machine learning model. We propose a hypothesis testing procedure, based on the availability of a calibration set, to derive statistical guarantees providing that the probability of declaring that the adversarial (population) risk of a machine learning model is less than α (i.e. the model is safe), while the model is in fact unsafe (i.e. the model adversarial population risk is higher than α), is less than ζ . We also propose Bayesian optimization algorithms to determine efficiently whether a machine learning model is (α,ζ)-safe in the presence of an adversarial attack, along with statistical guarantees. We apply our framework to a range of machine learning models-including various sizes of vision Transformer (ViT) and ResNet models - impaired by a variety of adversarial attacks, such as PGDAttack, MomentumAttack, GenAttack and BanditAttack, to illustrate the operation of our approach. Importantly, we show that ViT’s are generally more robust to adversarial attacks than ResNets, and large models are generally more robust than smaller models. Our approach goes beyond existing empirical adversarial risk-based certification guarantees. It formulates rigorous (and provable) performance guarantees that can be used to satisfy regulatory requirements mandating the use of state-of-the-art technical tools.  \nIntroduction  \nWith the development of increasingly capable autonomous machine learning systems and their use in a range of domains from healthcare to banking and finance, education, and e-commerce, to name just a few, policy makers across the world are in the process of formulating detailed regulatory requirements that will apply to developers and operators of AI systems. The EU is at the forefront of the drive to regulate AI systems. Proposals for an EU AI Act, an AI  \nCopyright © 2025, Association for the Advancement of Artificial Intelligence ([www.aaai.org](www.aaai.org)). All rights reserved.  \nLiability Directive and an extension of the EU Product Liability Directive to AI systems and AI-enabled goods are at advanced stages of the legislative process. Other jurisdictions, too, pursue a variety of regulatory initiatives, and standard setters such as the National Institute of Standards and Technology in the United States and the Supreme Audit Institutions of Germany, the UK, and other countries have started work on more precise standards, including standards concerning the robustness of machine learning systems in the presence of adversarial attacks.  \nRegulatory frameworks adopted so far are mostly highlevel, but those that establish more detailed requirements for AI systems to be put in service or for ongoing complian","cbCairvc2heLUxCQ","https://ap.wps.com/l/cbCairvc2heLUxCQ","pdf",570241,1,9,"English","en",105,"# Abstract\n## Problem: adversarial vulnerability of machine learning\n## PROSAC approach and (α,ζ)-safe definition\n## Calibration-set hypothesis testing and risk guarantees\n## Bayesian optimization for efficient certification\n## Experimental evaluation on ViT/ResNet and multiple attacks\n## Relation to existing certification methods\n## Regulatory motivation and need for robust metrics","[{\"question\":\"What does PROSAC certify in the presence of adversarial attacks?\",\"answer\":\"PROSAC provides population-level risk guarantees for machine learning models when facing adversarial perturbations, aiming to certify robustness against the most effective attacks.\"},{\"question\":\"How is (α,ζ)-safety defined and verified?\",\"answer\":\"A model is treated as (α,ζ)-safe when the probability of incorrectly declaring its adversarial population risk is below α is bounded by ζ, even if the model is actually unsafe.\"},{\"question\":\"What techniques does PROSAC use to obtain these guarantees?\",\"answer\":\"It uses a hypothesis testing procedure based on a calibration set, and it proposes Bayesian optimization algorithms to determine (α,ζ)-safety efficiently under adversarial attacks.\"},{\"question\":\"What empirical findings are reported for ViT versus ResNet and model size?\",\"answer\":\"The results indicate that ViT models are generally more robust than ResNets, and larger models are generally more robust than smaller ones under the tested adversarial attacks.\"}]","PROSAC - Provably Safe Certification for Machine Learning Models under Adversarial Attacks | PDF",1785725468,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":90,"head_meta":92,"extra_data":94,"updated_unix":28},"prosac-provably-safe-certification-for-machine-learning-models-under-adversarial-attacks","",{"@graph":36,"@context":89},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/prosac-provably-safe-certification-for-machine-learning-models-under-adversarial-attacks/119649/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81,85],{"name":72,"@type":73,"acceptedAnswer":74},"What does PROSAC certify in the presence of adversarial attacks?","Question",{"text":75,"@type":76},"PROSAC provides population-level risk guarantees for machine learning models when facing adversarial perturbations, aiming to certify robustness against the most effective attacks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is (α,ζ)-safety defined and verified?",{"text":80,"@type":76},"A model is treated as (α,ζ)-safe when the probability of incorrectly declaring its adversarial population risk is below α is bounded by ζ, even if the model is actually unsafe.",{"name":82,"@type":73,"acceptedAnswer":83},"What techniques does PROSAC use to obtain these guarantees?",{"text":84,"@type":76},"It uses a hypothesis testing procedure based on a calibration set, and it proposes Bayesian optimization algorithms to determine (α,ζ)-safety efficiently under adversarial attacks.",{"name":86,"@type":73,"acceptedAnswer":87},"What empirical findings are reported for ViT versus ResNet and model size?",{"text":88,"@type":76},"The results indicate that ViT models are generally more robust than ResNets, and larger models are generally more robust than smaller ones under the tested adversarial attacks.","https://schema.org",{"og:url":52,"og:type":91,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":93,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":96},[97,101,105,109,114,119,124,127,131,134,138],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Exam",70,"exam",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},5,"Comic",60,"comic",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},6,"Technology",50,"technology",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":125,"slug":126},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":129,"slug":130},"Religion & Spirituality",20,"religion-spirituality",{"id":129,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":129,"slug":133},"World Cup","world-cup",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":135,"slug":137},10,"Lifestyle","lifestyle",{"id":139,"doc_module":4,"doc_module_name":46,"category_name":140,"show_sort_weight":110,"slug":141},19,"General","general"]