8 papers
Certified Robustness to Data Poisoning in Gradient-Based Training
Philip Sosnin, Mark N. Müller, Maximilian Baader +2
Modern machine learning pipelines leverage large amounts of public data, making it infeasible to guarantee data quality and leaving models open to poisoning and backdoor attacks. P…
Relaxation-Informed Training of Neural Network Surrogate Models
Calvin Tsay
ReLU neural networks trained as surrogate models can be embedded exactly in mixed-integer linear programs (MILPs), enabling global optimization over the learned function. The tract…
An Efficient Spatial Branch-and-Bound Algorithm for Global Optimization of Gaussian Process Posterior Mean Functions
Wei-Ting Tang, Akshay Kudva, Calvin Tsay +1
We study the deterministic global optimization of trained Gaussian process posterior mean functions over hyperrectangular domains. Although the posterior mean function has a compac…
Provably Safe Model Updates
Leo Elmecker-Plakolm, Pierre Fasterling, Philip Sosnin +2
Safety-critical environments are inherently dynamic. Distribution shifts, emerging vulnerabilities, and evolving requirements demand continuous updates to machine learning models.…
Exact Certification of Data-Poisoning Attacks Using Mixed-Integer Programming
Philip Sosnin, Jodie Knapp, Fraser Kennedy +2
This work introduces a verification framework that provides both sound and complete guarantees for data poisoning attacks during neural network training. We formulate adversarial d…
Abstract Gradient Training: A Unified Certification Framework for Data Poisoning, Unlearning, and Differential Privacy
Philip Sosnin, Matthew Wicker, Josh Collyer +1
The impact of inference-time data perturbation (e.g., adversarial attacks) has been extensively studied in machine learning, leading to well-established certification techniques fo…