papers

Publications (30)

cs.LG2023

Emergent Linguistic Structures in Neural Networks are Fragile

Emanuele La Malfa, Matthew Wicker, Marta Kwiatkowska

Large Language Models (LLMs) have been reported to have strong performance on natural language processing tasks. However, performance metrics such as accuracy do not measure the qu…

cs.LG2019

A Game-Based Approximate Verification of Deep Neural Networks with Provable Guarantees

Min Wu, Matthew Wicker, Wenjie Ruan +2

Despite the improved accuracy of deep neural networks, the discovery of adversarial examples has raised serious safety concerns. In this paper, we study two variants of pointwise r…

cs.CV2019

Robustness of 3D Deep Learning in an Adversarial Setting

Matthew Wicker, Marta Kwiatkowska

Understanding the spatial arrangement and nature of real-world objects is of paramount importance to many complex engineering tasks, including autonomous navigation. Deep learning…

cs.LG2025

Certification for Differentially Private Prediction in Gradient-Based Training

Matthew Wicker, Philip Sosnin, Igor Shilov +5

We study private prediction where differential privacy is achieved by adding noise to the outputs of a non-private model. Existing methods rely on noise proportional to the global…

cs.LG2023

Individual Fairness in Bayesian Neural Networks

Alice Doherty, Matthew Wicker, Luca Laurenti +1

We study Individual Fairness (IF) for Bayesian neural networks (BNNs). Specifically, we consider the --individual fairness notion, which requires that, for any pair of inpu…

cs.LG2021

Certification of Iterative Predictions in Bayesian Neural Networks

Matthew Wicker, Luca Laurenti, Andrea Patane +3

We consider the problem of computing reach-avoid probabilities for iterative predictions made with Bayesian neural network (BNN) models. Specifically, we leverage bound propagation…

cs.LG2026

Provably Safe Model Updates

Leo Elmecker-Plakolm, Pierre Fasterling, Philip Sosnin +2

Safety-critical environments are inherently dynamic. Distribution shifts, emerging vulnerabilities, and evolving requirements demand continuous updates to machine learning models.…

cs.LG2026

Towards Poisoning Robustness Certification for Natural Language Generation

Mihnea Ghitu, Matthew Wicker

Understanding the reliability of natural language generation is critical for deploying foundation models in security-sensitive domains. While certified poisoning defenses provide p…

cs.LG2026

SafeAdapt: Provably Safe Policy Updates in Deep Reinforcement Learning

Maksim Anisimov, Francesco Belardinelli, Matthew Wicker

Safety guarantees are a prerequisite to the deployment of reinforcement learning (RL) agents in safety-critical tasks. Often, deployment environments exhibit non-stationary dynamic…

cs.DS2018

Efficient Learning of Optimal Markov Network Topology with k-Tree Modeling

Liang Ding, Di Chang, Russell Malmberg +5

The seminal work of Chow and Liu (1968) shows that approximation of a finite probabilistic system by Markov trees can achieve the minimum information loss with the topology of a ma…

cs.LG2026

Certified Robustness to Data Poisoning in Gradient-Based Training

Philip Sosnin, Mark N. Müller, Maximilian Baader +2

Modern machine learning pipelines leverage large amounts of public data, making it infeasible to guarantee data quality and leaving models open to poisoning and backdoor attacks. P…

cs.LG2023

Adversarial Robustness Certification for Bayesian Neural Networks

Matthew Wicker, Andrea Patane, Luca Laurenti +1

We study the problem of certifying the robustness of Bayesian neural networks (BNNs) to adversarial input perturbations. Given a compact set of input points $T \subseteq \mathbb{R}…

cs.LG2022

Individual Fairness Guarantees for Neural Networks

Elias Benussi, Andrea Patane, Matthew Wicker +2

We consider the problem of certifying the individual fairness (IF) of feed-forward neural networks (NNs). In particular, we work with the --IF formulation, which, given a N…

cs.LG2025

Model Guidance via Robust Feature Attribution

Mihnea Ghitu, Vihari Piratla, Matthew Wicker

Controlling the patterns a model learns is essential to preventing reliance on irrelevant or misleading features. Such reliance on irrelevant features, often called shortcut featur…

cs.LG2020

Robustness of Bayesian Neural Networks to Gradient-Based Attacks

Ginevra Carbone, Matthew Wicker, Luca Laurenti +3

Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical a…

cs.LG2023

Certification of Distributional Individual Fairness

Matthew Wicker, Vihari Piratia, Adrian Weller

Providing formal guarantees of algorithmic fairness is of paramount importance to socially responsible deployment of machine learning algorithms. In this work, we study formal guar…

cs.LG2019

Statistical Guarantees for the Robustness of Bayesian Neural Networks

Luca Cardelli, Marta Kwiatkowska, Luca Laurenti +3

We introduce a probabilistic robustness measure for Bayesian Neural Networks (BNNs), defined as the probability that, given a test point, there exists a point within a bounded set…

cs.LG2023

Probabilistic Reach-Avoid for Bayesian Neural Networks

Matthew Wicker, Luca Laurenti, Andrea Patane +3

Model-based reinforcement learning seeks to simultaneously learn the dynamics of an unknown stochastic environment and synthesise an optimal policy for acting in it. Ensuring the s…

cs.CV2026

Hybrid Robustness Verification for Spatio-Temporal Neural Networks

Sherwin Varghese, Matthew Wicker, Alessio Lomuscio

With AI increasingly deployed in safety-critical systems, providing formal robustness guarantees for the underlying models is essential. Existing verification methods either rely o…

cs.LG2023

Use Perturbations when Learning from Explanations

Juyeon Heo, Vihari Piratla, Matthew Wicker +1

Machine learning from explanations (MLX) is an approach to learning that uses human-provided explanations of relevant or irrelevant features for each input to ensure that model pre…

cs.LG2024

On the Robustness of Bayesian Neural Networks to Adversarial Attacks

Luca Bortolussi, Ginevra Carbone, Luca Laurenti +3

Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical a…

cs.LG2020

Gradient-Free Adversarial Attacks for Bayesian Neural Networks

Matthew Yuan, Matthew Wicker, Luca Laurenti

The existence of adversarial examples underscores the importance of understanding the robustness of machine learning models. Bayesian neural networks (BNNs), due to their calibrate…

cs.CV2018

Feature-Guided Black-Box Safety Testing of Deep Neural Networks

Matthew Wicker, Xiaowei Huang, Marta Kwiatkowska

Despite the improved accuracy of deep neural networks, the discovery of adversarial examples has raised serious safety concerns. Most existing approaches for crafting adversarial e…

cs.LG2026

Variational Routing: A Scalable Bayesian Framework for Calibrated Mixture-of-Experts Transformers

Albus Yizhuo Li, Matthew Wicker

Foundation models are increasingly being deployed in contexts where understanding the uncertainty of their outputs is critical to ensuring responsible deployment. While Bayesian me…

cs.LG2025

Abstract Gradient Training: A Unified Certification Framework for Data Poisoning, Unlearning, and Differential Privacy

Philip Sosnin, Matthew Wicker, Josh Collyer +1

The impact of inference-time data perturbation (e.g., adversarial attacks) has been extensively studied in machine learning, leading to well-established certification techniques fo…

cs.LG2022

Tractable Uncertainty for Structure Learning

Benjie Wang, Matthew Wicker, Marta Kwiatkowska

Bayesian structure learning allows one to capture uncertainty over the causal directed acyclic graph (DAG) responsible for generating given data. In this work, we present Tractable…

cs.LG2021

Bayesian Inference with Certifiable Adversarial Robustness

Matthew Wicker, Luca Laurenti, Andrea Patane +3

We consider adversarial training of deep neural networks through the lens of Bayesian learning, and present a principled framework for adversarial training of Bayesian Neural Netwo…

cs.LG2019

Uncertainty Quantification with Statistical Guarantees in End-to-End Autonomous Driving Control

Rhiannon Michelmore, Matthew Wicker, Luca Laurenti +3

Deep neural network controllers for autonomous driving have recently benefited from significant performance improvements, and have begun deployment in the real world. Prior to thei…

cs.LG2022

Robust Explanation Constraints for Neural Networks

Matthew Wicker, Juyeon Heo, Luca Costabello +1

Post-hoc explanation methods are used with the intent of providing insights about neural networks and are sometimes said to help engender trust in their outputs. However, popular e…

cs.LG2020

Probabilistic Safety for Bayesian Neural Networks

Matthew Wicker, Luca Laurenti, Andrea Patane +1

We study probabilistic safety for Bayesian Neural Networks (BNNs) under adversarial input perturbations. Given a compact set of input points, , we study t…