{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/double-bubble-toil-and-trouble-enhancing","title":"Double Bubble, Toil and Trouble: Enhancing Certified Robustness through Transitivity","arxiv_id":"2210.06077","date":"2022-10-12","proceeding":null,"authors":["Andrew C. Cullen","Paul Montague","Shijie Liu","Sarah M. Erfani","Benjamin I. P. Rubinstein"],"abstract":"In response to subtle adversarial examples flipping classifications of neural network models, recent research has promoted certified robustness as a solution. There, invariance of predictions to all norm-bounded attacks is achieved through randomised smoothing of network inputs. Today's state-of-the-art certifications make optimal use of the class output scores at the input instance under test: no better radius of certification (under the $L_2$ norm) is possible given only these score. However, it is an open question as to whether such lower bounds can be improved using local information around the instance under test. In this work, we demonstrate how today's \"optimal\" certificates can be improved by exploiting both the transitivity of certifications, and the geometry of the input space, giving rise to what we term Geometrically-Informed Certified Robustness. By considering the smallest distance to points on the boundary of a set of certifications this approach improves certifications for more than $80\\%$ of Tiny-Imagenet instances, yielding an on average $5 \\%$ increase in the associated certification. When incorporating training time processes that enhance the certified radius, our technique shows even more promising results, with a uniform $4$ percentage point increase in the achieved certified radius.","url_abs":"https://arxiv.org/abs/2210.06077v1","url_pdf":"https://arxiv.org/pdf/2210.06077v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"double-bubble-toil-and-trouble-enhancing","repo_url":"https://github.com/andrew-cullen/doublebubble","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"open-question","task_name":"Open-Ended Question Answering"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2210.06077","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2210.06077"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/andrew-cullen/DoubleBubble","reach":{"status":"ok","spdx":"MIT"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/andrew-cullen/doublebubble","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran_draft_wrong":1,"unverified":4},"by_repo_kind":{"official":{"samples":5,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"6af95ebe99af2e36","entry":"conv3x3","repo":"andrew-cullen/DoubleBubble","repo_kind":"official","path":"src/macer_model.py","file_url":"https://github.com/andrew-cullen/DoubleBubble/blob/HEAD/src/macer_model.py","link_basis":"harvester_set","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6af95ebe99af2e36"}},{"code_sha256_prefix":"f9e225be8c997100","entry":"dE_ds","repo":"andrew-cullen/DoubleBubble","repo_kind":"official","path":"src/evaluation_common.py","file_url":"https://github.com/andrew-cullen/DoubleBubble/blob/HEAD/src/evaluation_common.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"f9e225be8c997100"}},{"code_sha256_prefix":"346972f9d7292d6f","entry":"grad_phi","repo":"andrew-cullen/DoubleBubble","repo_kind":"official","path":"src/evaluation_common.py","file_url":"https://github.com/andrew-cullen/DoubleBubble/blob/HEAD/src/evaluation_common.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"346972f9d7292d6f"}},{"code_sha256_prefix":"e19a9b7b25bc95cd","entry":"inv_cdf_grad","repo":"andrew-cullen/DoubleBubble","repo_kind":"official","path":"src/evaluation_support.py","file_url":"https://github.com/andrew-cullen/DoubleBubble/blob/HEAD/src/evaluation_support.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"e19a9b7b25bc95cd"}},{"code_sha256_prefix":"35912a35794d4b2b","entry":"multi_conf_wrapper","repo":"andrew-cullen/DoubleBubble","repo_kind":"official","path":"src/evaluation_common.py","file_url":"https://github.com/andrew-cullen/DoubleBubble/blob/HEAD/src/evaluation_common.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"35912a35794d4b2b"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}