Support is All You Need for Certified VAE Training

📅 2025-04-16
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Variational autoencoders (VAEs) lack provable robustness guarantees under adversarial attacks in safety-critical applications. Method: We propose CIVET, the first end-to-end certifiably robust training framework for VAEs. Its core insight is that a VAE’s worst-case reconstruction performance is fully governed by the reconstruction error bound over a critical support set in latent space. Leveraging this, CIVET integrates variational inference, Lagrangian duality optimization, and support-set sensitivity analysis with randomized smoothing and gradient regularization. Contribution/Results: Evaluated across multiple wireless communication and computer vision datasets, CIVET significantly outperforms state-of-the-art methods. It achieves ≥92% provably guaranteed reconstruction confidence under diverse perturbation magnitudes—the first such result—while maintaining high reconstruction fidelity and strong probabilistic robustness.

Technology Category

Application Category

📝 Abstract
Variational Autoencoders (VAEs) have become increasingly popular and deployed in safety-critical applications. In such applications, we want to give certified probabilistic guarantees on performance under adversarial attacks. We propose a novel method, CIVET, for certified training of VAEs. CIVET depends on the key insight that we can bound worst-case VAE error by bounding the error on carefully chosen support sets at the latent layer. We show this point mathematically and present a novel training algorithm utilizing this insight. We show in an extensive evaluation across different datasets (in both the wireless and vision application areas), architectures, and perturbation magnitudes that our method outperforms SOTA methods achieving good standard performance with strong robustness guarantees.
Problem

Research questions and friction points this paper is trying to address.

Certify VAE performance under adversarial attacks
Bound worst-case error via latent support sets
Achieve robustness guarantees across diverse datasets
Innovation

Methods, ideas, or system contributions that make the work stand out.

Certified VAE training via support sets
Bounding worst-case error mathematically
Novel algorithm for robust performance
🔎 Similar Papers
No similar papers found.
Changming Xu
Changming Xu
University of Illinois Urbana Champaign
Trustworthy Machine Learning
D
Debangshu Banerjee
Department of Computer Science, University of Illinois Urbana-Champaign
Deepak Vasisht
Deepak Vasisht
University of Illinois at Urbana-Champaign
Wireless NetworksInternet of Things
G
Gagandeep Singh
Department of Computer Science, University of Illinois Urbana-Champaign