{"id":"https://openalex.org/W7138230635","doi":"https://doi.org/10.1609/aaai.v40i10.37716","title":"CertMask: Certifiable Defense Against Adversarial Patches via Theoretically Optimal Mask Coverage","display_name":"CertMask: Certifiable Defense Against Adversarial Patches via Theoretically Optimal Mask Coverage","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7138230635","doi":"https://doi.org/10.1609/aaai.v40i10.37716"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i10.37716","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i10.37716","pdf_url":"https://ojs.aaai.org/index.php/AAAI/article/download/37716/41678","source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://ojs.aaai.org/index.php/AAAI/article/download/37716/41678","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5125701309","display_name":"Xuntao Lyu","orcid":null},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Xuntao Lyu","raw_affiliation_strings":["North Carolina State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"North Carolina State University","institution_ids":["https://openalex.org/I137902535"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064871646","display_name":"Ching\u2010Chi Lin","orcid":"https://orcid.org/0000-0002-9518-2809"},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Ching-Chi Lin","raw_affiliation_strings":["TU Dortmund University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"TU Dortmund University","institution_ids":["https://openalex.org/I200332995"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129686902","display_name":"Abdullah Al Arafat","orcid":null},"institutions":[{"id":"https://openalex.org/I19700959","display_name":"Florida International University","ror":"https://ror.org/02gz6gg07","country_code":"US","type":"education","lineage":["https://openalex.org/I19700959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Abdullah Al Arafat","raw_affiliation_strings":["North Carolina State University\nFlorida International University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"North Carolina State University\nFlorida International University","institution_ids":["https://openalex.org/I19700959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004024181","display_name":"Georg von der Br\u00fcggen","orcid":"https://orcid.org/0000-0002-8137-3612"},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Georg Von der Br\u00fcggen","raw_affiliation_strings":["TU Dortmund University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"TU Dortmund University","institution_ids":["https://openalex.org/I200332995"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107997940","display_name":"Jian-Jia Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Jian-Jia Chen","raw_affiliation_strings":["TU Dortmund University\nLamarr Institute for AI and ML"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"TU Dortmund University\nLamarr Institute for AI and ML","institution_ids":["https://openalex.org/I200332995"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5129743711","display_name":"Zhishan Guo","orcid":null},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Zhishan Guo","raw_affiliation_strings":["North Carolina State University\nTU Dortmund University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"North Carolina State University\nTU Dortmund University","institution_ids":["https://openalex.org/I200332995"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5125701309"],"corresponding_institution_ids":["https://openalex.org/I137902535"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.39053537,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"10","first_page":"7735","last_page":"7743"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.988099992275238,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.988099992275238,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.0024999999441206455,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11105","display_name":"Advanced Image Processing Techniques","score":0.0020000000949949026,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.6162999868392944},{"id":"https://openalex.org/keywords/masking","display_name":"Masking (illustration)","score":0.5264000296592712},{"id":"https://openalex.org/keywords/cover","display_name":"Cover (algebra)","score":0.5163000226020813},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.4404999911785126},{"id":"https://openalex.org/keywords/cardinality","display_name":"Cardinality (data modeling)","score":0.4300999939441681},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.42340001463890076},{"id":"https://openalex.org/keywords/set-operations","display_name":"Set operations","score":0.42100000381469727}],"concepts":[{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.6162999868392944},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6133000254631042},{"id":"https://openalex.org/C2777402240","wikidata":"https://www.wikidata.org/wiki/Q6783436","display_name":"Masking (illustration)","level":2,"score":0.5264000296592712},{"id":"https://openalex.org/C2780428219","wikidata":"https://www.wikidata.org/wiki/Q16952335","display_name":"Cover (algebra)","level":2,"score":0.5163000226020813},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.4945000112056732},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.4404999911785126},{"id":"https://openalex.org/C87117476","wikidata":"https://www.wikidata.org/wiki/Q362383","display_name":"Cardinality (data modeling)","level":2,"score":0.4300999939441681},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.42340001463890076},{"id":"https://openalex.org/C2777168461","wikidata":"https://www.wikidata.org/wiki/Q42196253","display_name":"Set operations","level":3,"score":0.42100000381469727},{"id":"https://openalex.org/C48372109","wikidata":"https://www.wikidata.org/wiki/Q3913","display_name":"Binary number","level":2,"score":0.42089998722076416},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3675999939441681},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.35429999232292175},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3490000069141388},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.3488999903202057},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3248000144958496},{"id":"https://openalex.org/C153046414","wikidata":"https://www.wikidata.org/wiki/Q12482","display_name":"Set theory","level":3,"score":0.3075999915599823},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.3021000027656555},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.28619998693466187},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.28600001335144043},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.27970001101493835}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i10.37716","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i10.37716","pdf_url":"https://ojs.aaai.org/index.php/AAAI/article/download/37716/41678","source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i10.37716","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i10.37716","pdf_url":"https://ojs.aaai.org/index.php/AAAI/article/download/37716/41678","source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.44887691736221313,"id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7138230635.pdf","grobid_xml":"https://content.openalex.org/works/W7138230635.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Adversarial":[0],"patch":[1,46,109],"attacks":[2,14],"inject":[3],"localized":[4],"perturbations":[5],"into":[6],"images":[7],"to":[8,22,44,88,152,162],"mislead":[9],"deep":[10],"vision":[11],"models.":[12],"These":[13],"can":[15],"be":[16],"physically":[17],"deployed,":[18],"posing":[19],"serious":[20],"risks":[21],"real-world":[23],"applications.":[24],"In":[25],"this":[26],"paper,":[27],"we":[28],"propose":[29],"CertMask,":[30],"a":[31,37,70,100,124],"certifiably":[32],"robust":[33,148],"defense":[34],"that":[35,105,144],"constructs":[36],"provably":[38],"sufficient":[39],"set":[40,87,96],"of":[41,60,73,84,127],"binary":[42],"masks":[43],"neutralize":[45],"effects":[47],"with":[48,75],"strong":[49],"theoretical":[50,125],"guarantees.":[51],"While":[52],"the":[53,82,85,128,163],"state-of-the-art":[54],"approach":[55],"(PatchCleanser)":[56],"requires":[57],"two":[58],"rounds":[59],"masking":[61,74],"and":[62,120,131,141],"incurs":[63],"O(n^2)":[64],"inference":[65],"cost,":[66],"CertMask":[67,145],"performs":[68],"only":[69],"single":[71],"round":[72],"O(n)":[76],"time":[77],"complexity,":[78],"where":[79],"n":[80],"is":[81,97,111],"cardinality":[83],"mask":[86,95],"cover":[89],"an":[90],"input":[91],"image.":[92],"Our":[93],"proposed":[94],"computed":[98],"using":[99],"mathematically":[101],"rigorous":[102],"coverage":[103,129],"strategy":[104],"ensures":[106],"each":[107],"possible":[108],"location":[110],"covered":[112],"at":[113],"least":[114],"k":[115],"times,":[116],"providing":[117],"both":[118],"efficiency":[119],"robustness.":[121],"We":[122],"offer":[123],"analysis":[126],"condition":[130],"prove":[132],"its":[133],"sufficiency":[134],"for":[135],"certification.":[136],"Experiments":[137],"on":[138],"ImageNet,":[139],"ImageNette,":[140],"CIFAR-10":[142],"show":[143],"improves":[146],"certified":[147],"accuracy":[149,159],"by":[150],"up":[151],"+13.4%":[153],"over":[154],"PatchCleanser,":[155],"while":[156],"maintaining":[157],"clean":[158],"nearly":[160],"identical":[161],"vanilla":[164],"model.":[165]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-03-18T00:00:00"}
