Position: Certified Robustness Does Not (Yet) Imply Model Security

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Cullen, Andrew C., Montague, Paul, Erfani, Sarah M., Rubinstein, Benjamin I. P.
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916889404375040
author Cullen, Andrew C.
Montague, Paul
Erfani, Sarah M.
Rubinstein, Benjamin I. P.
author_facet Cullen, Andrew C.
Montague, Paul
Erfani, Sarah M.
Rubinstein, Benjamin I. P.
contents While certified robustness is widely promoted as a solution to adversarial examples in Artificial Intelligence systems, significant challenges remain before these techniques can be meaningfully deployed in real-world applications. We identify critical gaps in current research, including the paradox of detection without distinction, the lack of clear criteria for practitioners to evaluate certification schemes, and the potential security risks arising from users' expectations surrounding ``guaranteed" robustness claims. These create an alignment issue between how certifications are presented and perceived, relative to their actual capabilities. This position paper is a call to arms for the certification research community, proposing concrete steps to address these fundamental challenges and advance the field toward practical applicability.
format Preprint
id arxiv_https___arxiv_org_abs_2506_13024
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Position: Certified Robustness Does Not (Yet) Imply Model Security
Cullen, Andrew C.
Montague, Paul
Erfani, Sarah M.
Rubinstein, Benjamin I. P.
Cryptography and Security
Machine Learning
While certified robustness is widely promoted as a solution to adversarial examples in Artificial Intelligence systems, significant challenges remain before these techniques can be meaningfully deployed in real-world applications. We identify critical gaps in current research, including the paradox of detection without distinction, the lack of clear criteria for practitioners to evaluate certification schemes, and the potential security risks arising from users' expectations surrounding ``guaranteed" robustness claims. These create an alignment issue between how certifications are presented and perceived, relative to their actual capabilities. This position paper is a call to arms for the certification research community, proposing concrete steps to address these fundamental challenges and advance the field toward practical applicability.
title Position: Certified Robustness Does Not (Yet) Imply Model Security
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2506.13024