{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/unlocking-deterministic-robustness-1","title":"Unlocking Deterministic Robustness Certification on ImageNet","arxiv_id":"2301.12549","date":"2023-01-29","proceeding":"NeurIPS 2023 11","authors":["Kai Hu","Andy Zou","Zifan Wang","Klas Leino","Matt Fredrikson"],"abstract":"Despite the promise of Lipschitz-based methods for provably-robust deep learning with deterministic guarantees, current state-of-the-art results are limited to feed-forward Convolutional Networks (ConvNets) on low-dimensional data, such as CIFAR-10. This paper investigates strategies for expanding certifiably robust training to larger, deeper models. A key challenge in certifying deep networks is efficient calculation of the Lipschitz bound for residual blocks found in ResNet and ViT architectures. We show that fast ways of bounding the Lipschitz constant for conventional ResNets are loose, and show how to address this by designing a new residual block, leading to the \\emph{Linear ResNet} (LiResNet) architecture. We then introduce \\emph{Efficient Margin MAximization} (EMMA), a loss function that stabilizes robust training by simultaneously penalizing worst-case adversarial examples from \\emph{all} classes. Together, these contributions yield new \\emph{state-of-the-art} robust accuracy on CIFAR-10/100 and Tiny-ImageNet under $\\ell_2$ perturbations. Moreover, for the first time, we are able to scale up fast deterministic robustness guarantees to ImageNet, demonstrating that this approach to robust learning can be applied to real-world applications. We release our code on Github: \\url{https://github.com/klasleino/gloro}.","url_abs":"https://arxiv.org/abs/2301.12549v3","url_pdf":"https://arxiv.org/pdf/2301.12549v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"unlocking-deterministic-robustness-1","repo_url":"https://github.com/hukkai/liresnet","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"unlocking-deterministic-robustness-1","repo_url":"https://github.com/klasleino/gloro","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"tf","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2301.12549","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2301.12549"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/klasleino/gloro","reach":{"status":"ok","spdx":"MIT"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/hukkai/liresnet","reach":null}],"summary":{"unverified":6},"by_repo_kind":{"official":{"samples":6,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"57ae48273a26c148","entry":"add_extra_column","repo":"klasleino/gloro","repo_kind":"official","path":"gloro/utils.py","file_url":"https://github.com/klasleino/gloro/blob/HEAD/gloro/utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"57ae48273a26c148"}},{"code_sha256_prefix":"7901528e206fe76b","entry":"add_extra_column_np","repo":"klasleino/gloro","repo_kind":"official","path":"gloro/utils.py","file_url":"https://github.com/klasleino/gloro/blob/HEAD/gloro/utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"7901528e206fe76b"}},{"code_sha256_prefix":"8b67d39fa09a8026","entry":"add_extra_column_tf","repo":"klasleino/gloro","repo_kind":"official","path":"gloro/utils.py","file_url":"https://github.com/klasleino/gloro/blob/HEAD/gloro/utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"8b67d39fa09a8026"}},{"code_sha256_prefix":"bdf696539a2d4052","entry":"rtk_vra","repo":"klasleino/gloro","repo_kind":"official","path":"gloro/relaxations/metrics.py","file_url":"https://github.com/klasleino/gloro/blob/HEAD/gloro/relaxations/metrics.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"bdf696539a2d4052"}},{"code_sha256_prefix":"b3268cdd063d9b88","entry":"rtk_vra_cat","repo":"klasleino/gloro","repo_kind":"official","path":"gloro/relaxations/metrics.py","file_url":"https://github.com/klasleino/gloro/blob/HEAD/gloro/relaxations/metrics.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"b3268cdd063d9b88"}},{"code_sha256_prefix":"da61868fd42d7481","entry":"rtk_vra_sparse","repo":"klasleino/gloro","repo_kind":"official","path":"gloro/relaxations/metrics.py","file_url":"https://github.com/klasleino/gloro/blob/HEAD/gloro/relaxations/metrics.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"da61868fd42d7481"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}