Center Smoothing: Certified Robustness for Networks with Structured Outputs

Neural Information Processing Systems 

The study of provable adversarial robustness has mostly been limited to classification tasks and models with one-dimensional real-valued outputs. We extend the scope of certifiable robustness to problems with more general and structured outputs like sets, images, language, etc.