{"id":"https://openalex.org/W7123342507","doi":"https://doi.org/10.1109/tr.2025.3642046","title":"HiCert: Toward Patch Robustness Certification and Detection for Deep Learning Systems Beyond Consistent Samples","display_name":"HiCert: Toward Patch Robustness Certification and Detection for Deep Learning Systems Beyond Consistent Samples","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7123342507","doi":"https://doi.org/10.1109/tr.2025.3642046"},"language":null,"primary_location":{"id":"doi:10.1109/tr.2025.3642046","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tr.2025.3642046","pdf_url":null,"source":{"id":"https://openalex.org/S87725633","display_name":"IEEE Transactions on Reliability","issn_l":"0018-9529","issn":["0018-9529","1558-1721"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Reliability","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5103178922","display_name":"Qilin Zhou","orcid":"https://orcid.org/0000-0003-2289-9849"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":true,"raw_author_name":"Qilin Zhou","raw_affiliation_strings":["City University of Hong Kong, HKSAR, China"],"affiliations":[{"raw_affiliation_string":"City University of Hong Kong, HKSAR, China","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072631246","display_name":"Zhengyuan Wei","orcid":"https://orcid.org/0000-0001-5966-1338"},"institutions":[{"id":"https://openalex.org/I4210086892","display_name":"Education University of Hong Kong","ror":"https://ror.org/000t0f062","country_code":"HK","type":"education","lineage":["https://openalex.org/I4210086892"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Zhengyuan Wei","raw_affiliation_strings":["The Education University of Hong Kong, HKSAR, China"],"affiliations":[{"raw_affiliation_string":"The Education University of Hong Kong, HKSAR, China","institution_ids":["https://openalex.org/I4210086892"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100405759","display_name":"Haipeng Wang","orcid":"https://orcid.org/0000-0002-7410-393X"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Haipeng Wang","raw_affiliation_strings":["City University of Hong Kong, HKSAR, China"],"affiliations":[{"raw_affiliation_string":"City University of Hong Kong, HKSAR, China","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029221427","display_name":"Zhuo Wang","orcid":"https://orcid.org/0000-0002-2735-6969"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Zhuo Wang","raw_affiliation_strings":["City University of Hong Kong, HKSAR, China"],"affiliations":[{"raw_affiliation_string":"City University of Hong Kong, HKSAR, China","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5087870014","display_name":"W K Chan","orcid":null},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Wing-Kwong Chan","raw_affiliation_strings":["City University of Hong Kong, HKSAR, China"],"affiliations":[{"raw_affiliation_string":"City University of Hong Kong, HKSAR, China","institution_ids":["https://openalex.org/I168719708"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5103178922"],"corresponding_institution_ids":["https://openalex.org/I168719708"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.09793517,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"75","issue":null,"first_page":"679","last_page":"693"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9970999956130981,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9970999956130981,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.00039999998989515007,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.00039999998989515007,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.8079000115394592},{"id":"https://openalex.org/keywords/certification","display_name":"Certification","score":0.7623999714851379},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4997999966144562},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.3601999878883362},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.33480000495910645}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.8079000115394592},{"id":"https://openalex.org/C46304622","wikidata":"https://www.wikidata.org/wiki/Q374814","display_name":"Certification","level":2,"score":0.7623999714851379},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6111000180244446},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.589900016784668},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4997999966144562},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4357999861240387},{"id":"https://openalex.org/C200601418","wikidata":"https://www.wikidata.org/wiki/Q2193887","display_name":"Reliability engineering","level":1,"score":0.38929998874664307},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.3601999878883362},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.33480000495910645},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.31220000982284546},{"id":"https://openalex.org/C129848803","wikidata":"https://www.wikidata.org/wiki/Q2564360","display_name":"Sample size determination","level":2,"score":0.29899999499320984},{"id":"https://openalex.org/C95922358","wikidata":"https://www.wikidata.org/wiki/Q5432725","display_name":"False positive rate","level":2,"score":0.2648000121116638},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.25780001282691956}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tr.2025.3642046","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tr.2025.3642046","pdf_url":null,"source":{"id":"https://openalex.org/S87725633","display_name":"IEEE Transactions on Reliability","issn_l":"0018-9529","issn":["0018-9529","1558-1721"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Reliability","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.5637530088424683}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W2001164678","https://openalex.org/W2108598243","https://openalex.org/W2117876524","https://openalex.org/W2194775991","https://openalex.org/W2798302089","https://openalex.org/W2902867332","https://openalex.org/W2916673431","https://openalex.org/W2963302614","https://openalex.org/W2963448658","https://openalex.org/W2963542245","https://openalex.org/W3083878034","https://openalex.org/W3097269597","https://openalex.org/W3107990944","https://openalex.org/W3205945722","https://openalex.org/W4226409694","https://openalex.org/W4245587674","https://openalex.org/W4282936640","https://openalex.org/W4293195547","https://openalex.org/W4312675304","https://openalex.org/W4312918928","https://openalex.org/W4313156423","https://openalex.org/W4362721716","https://openalex.org/W4383221314","https://openalex.org/W4385819786","https://openalex.org/W4386362985","https://openalex.org/W4388483142","https://openalex.org/W4399310732","https://openalex.org/W4400581754","https://openalex.org/W4402979947"],"related_works":[],"abstract_inverted_index":{"Patch":[0],"robustness":[1,212],"certification":[2,213],"is":[3,199,267],"an":[4],"emerging":[5],"kind":[6],"of":[7,24,29,36,82,118,129,206,223],"provable":[8],"defense":[9,38,264],"technique":[10],"against":[11],"adversarial":[12],"patch":[13,211,261],"attacks":[14],"for":[15,214],"deep":[16],"learning":[17],"systems.":[18],"Certified":[19],"detection":[20,23,48,75],"ensures":[21,134],"the":[22,34,80,90,116,119,141,149,152,171,200,220],"all":[25],"patched":[26],"harmful":[27,104,125,137,153,172],"versions":[28],"certified":[30,47,74,215],"samples,":[31,235],"which":[32],"mitigates":[33],"failures":[35],"empirical":[37],"techniques":[39],"that":[40,55,135,146],"could":[41],"(easily)":[42],"be":[43],"compromised.":[44],"However,":[45],"existing":[46],"methods":[49],"are":[50,56,61,147],"ineffective":[51],"in":[52],"certifying":[53],"samples":[54,105,187,190,248],"misclassified":[57],"or":[58,159],"whose":[59],"mutants":[60,83,128,145],"inconsistently":[62],"predicted":[63,84,148,165],"to":[64,191],"different":[65,88,169],"labels.":[66],"This":[67],"paper":[68],"proposes":[69],"HiCert,":[70],"a":[71,86,99,167,192,209,226,252],"novel":[72,100,178],"masking-based":[73],"technique.":[76],"By":[77,114],"focusing":[78],"on":[79,246,259],"problem":[81],"with":[85,93,166,225],"label":[87,92,168],"from":[89,170],"true":[91],"our":[94,196],"formal":[95,101],"analysis,":[96],"HiCert":[97,133,182,198,224],"formulates":[98],"relation":[102],"between":[103],"generated":[106],"by":[107],"identified":[108],"loopholes":[109],"and":[110,188,239,241,251],"their":[111],"benign":[112,131,234],"counterparts.":[113],"checking":[115],"bound":[117],"maximum":[120],"confidence":[121,143],"among":[122,144],"these":[123],"potentially":[124],"(i.e.,":[126],"inconsistent)":[127],"each":[130,136],"sample,":[132],"sample":[138,154,173],"either":[139],"has":[140,160],"minimum":[142],"same":[150],"as":[151],"itself":[155],"below":[156],"this":[157],"bound,":[158],"at":[161],"least":[162],"one":[163],"mutant":[164],"itself,":[174],"formulated":[175],"after":[176],"two":[177],"insights.":[179],"As":[180],"such,":[181],"systematically":[183],"certifies":[184,231],"those":[185,237,247],"inconsistent":[186,238],"consistent":[189],"large":[193],"extent.":[194],"To":[195],"knowledge,":[197],"<italic":[201],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[202],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">first</i>":[203],"work":[204],"capable":[205],"providing":[207],"such":[208],"comprehensive":[210],"detection.":[216],"Our":[217],"experiments":[218],"show":[219],"high":[221],"effectiveness":[222],"new":[227],"state-of-the-art":[228],"performance:":[229],"It":[230],"significantly":[232,243,253,268],"more":[233],"including":[236],"consistent,":[240],"achieves":[242],"higher":[244,269],"accuracy":[245],"without":[249],"warnings":[250],"lower":[254],"false":[255],"silent":[256],"ratio.":[257],"Moreover,":[258],"actual":[260],"attacks,":[262],"its":[263,271],"success":[265],"ratio":[266],"than":[270],"peers.":[272]},"counts_by_year":[],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2026-01-14T00:00:00"}
