Improving Certified Robustness via Adversarial Distillation

Summary
Certified training aims to produce models whose predictions can be formally verified against adversarial perturbations, typically by optimising upper bounds on the worst-case loss over an allowed perturbation set.
Original Article
Captured source content or English translation, normalized into this reading format.
arXiv is now an independent nonprofit!Learn more×
Search arXiv
Press Enter to search ·Advanced search
Computer Science > Machine Learning
arXiv:2606.31653v1 (cs)
[Submitted on 30 Jun 2026]
Title:Improving Certified Robustness via Adversarial Distillation
Authors:Matteo Melis,Jesus Martinez Del Rincon,Vishal Sharma
View a PDF of the paper titled Improving Certified Robustness via Adversarial Distillation, by Matteo Melis and 2 other authors
Abstract:Certified training aims to produce models whose predictions can be formally verified against adversarial perturbations, typically by optimising upper bounds on the worst-case loss over an allowed perturbation set. For neural networks, certified training methods based purely on tight relaxation bounds produce networks that are amenable to certification, but sacrifice standard accuracy. Conversely, adversarial training often yields stronger empirical robustness and standard accuracy, but the resulting models are generally difficult to certify with neural network verifiers. Recently, the literature has shown that better standard-certified accuracy trade-offs can be achieved by combining adversarial training objectives with loose over-approximations based on Interval Bound Propagation (IBP), effectively interpolating between lower and upper bounds of the worst-case loss. Building on this, we introduce AD-CERT, a certified training objective that combines adversarial distillation with an IBP upper bound. We show that distilling adversarial information over the logit space from an empirically robust teacher provides an effective lower bound surrogate for certified training, with AD-CERT achieving state-of-the-art certified performance on several robustness benchmarks. Furthermore, in a unified setup, distilling adversarial information at the logit-level is shown to improve certified accuracy over a robust feature-space distillation objective by up to 5.40 percentage points.
| | | | --- | --- | | Subjects: | Machine Learning (cs.LG); Artificial Intelligence (cs.AI) | | Cite as: |arXiv:2606.31653[cs.LG] | | | (orarXiv:2606.31653v1[cs.LG] for this version) | | |https://doi.org/10.48550/arXiv.2606.31653<br>Focus to learn more<br>arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Matteo Melis \[view email]
[v1] Tue, 30 Jun 2026 13:31:35 UTC (53 KB)
Full-text links:
Access Paper:
View a PDF of the paper titled Improving Certified Robustness via Adversarial Distillation, by Matteo Melis and 2 other authors

Current browse context:
cs.LG
[< prev](https://arxiv.org/prevnext?id=2606.31653&function=prev&context=cs.LG "previous in cs.LG (accesskey p)") \| [next >](https://arxiv.org/prevnext?id=2606.31653&function=next&context=cs.LG "next in cs.LG (accesskey n)")
Change to browse by:
References & Citations
export BibTeX citation
Bookmark

Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer _(What is the Explorer?)_
Connected Papers Toggle
Connected Papers _(What is Connected Papers?)_
Litmaps Toggle
Litmaps _(What is Litmaps?)_
scite.ai Toggle
scite Smart Citations _(What are Smart Citations?)_
Code, Data, Media
Code, Data and Media Associated with this Article
alphaXiv Toggle
alphaXiv _(What is alphaXiv?)_
Links to Code Toggle
CatalyzeX Code Finder for Papers _(What is CatalyzeX?)_
DagsHub Toggle
DagsHub _(What is DagsHub?)_
GotitPub Toggle
Gotit.pub _(What is GotitPub?)_
Huggingface Toggle
Hugging Face _(What is Huggingface?)_
ScienceCast Toggle
ScienceCast _(What is ScienceCast?)_
Demos
Demos
Replicate Toggle
Replicate _(What is Replicate?)_
Spaces Toggle
Hugging Face Spaces _(What is Spaces?)_
Spaces Toggle
TXYZ.AI _(What is TXYZ.AI?)_
Related Papers
Recommenders and Search Tools
Link to Influence Flower
Influence Flower _(What are Influence Flowers?)_
Core recommender toggle
CORE Recommender _(What is CORE?)_
IArxiv recommender toggle
IArxiv Recommender _(What is IArxiv?)_
- Author
- Venue
- Institution
- Topic
About arXivLabs
arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community?Learn more about arXivLabs.
Which authors of this paper are endorsers?\| Disable MathJax (What is MathJax?)
Region
Global
Heat Score
81
Category
Research
Language
en
