{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/ibp-regularization-for-verified-adversarial","title":"IBP Regularization for Verified Adversarial Robustness via Branch-and-Bound","arxiv_id":"2206.14772","date":"2022-06-29","proceeding":null,"authors":["Alessandro De Palma","Rudy Bunel","Krishnamurthy Dvijotham","M. Pawan Kumar","Robert Stanforth"],"abstract":"Recent works have tried to increase the verifiability of adversarially trained networks by running the attacks over domains larger than the original perturbations and adding various regularization terms to the objective. However, these algorithms either underperform or require complex and expensive stage-wise training procedures, hindering their practical applicability. We present IBP-R, a novel verified training algorithm that is both simple and effective. IBP-R induces network verifiability by coupling adversarial attacks on enlarged domains with a regularization term, based on inexpensive interval bound propagation, that minimizes the gap between the non-convex verification problem and its approximations. By leveraging recent branch-and-bound frameworks, we show that IBP-R obtains state-of-the-art verified robustness-accuracy trade-offs for small perturbations on CIFAR-10 while training significantly faster than relevant previous work. Additionally, we present UPB, a novel branching strategy that, relying on a simple heuristic based on $\\beta$-CROWN, reduces the cost of state-of-the-art branching algorithms while yielding splits of comparable quality.","url_abs":"https://arxiv.org/abs/2206.14772v2","url_pdf":"https://arxiv.org/pdf/2206.14772v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"ibp-regularization-for-verified-adversarial","repo_url":"https://github.com/alessandrodepalma/ibpr","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"jax","reach":null}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2206.14772","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2206.14772"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/alessandrodepalma/ibpr","reach":null}],"summary":{"unverified":3},"by_repo_kind":{"official":{"samples":3,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"04187cef1d40b7b3","entry":"attack_layer","repo":"alessandrodepalma/ibpr","repo_kind":"official","path":"train/latent_representation.py","file_url":"https://github.com/alessandrodepalma/ibpr/blob/HEAD/train/latent_representation.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"04187cef1d40b7b3"}},{"code_sha256_prefix":"74360138d4b72a9f","entry":"compute_l1_loss","repo":"alessandrodepalma/ibpr","repo_kind":"official","path":"train/train_main.py","file_url":"https://github.com/alessandrodepalma/ibpr/blob/HEAD/train/train_main.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"74360138d4b72a9f"}},{"code_sha256_prefix":"4ed95ba1d5134f63","entry":"compute_relu_kw_area_loss","repo":"alessandrodepalma/ibpr","repo_kind":"official","path":"train/train_main.py","file_url":"https://github.com/alessandrodepalma/ibpr/blob/HEAD/train/train_main.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4ed95ba1d5134f63"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}