SupplementaryMaterial: RelaxingLocalRobustness
–Neural Information Processing Systems
This presents aproblem for certifying unseen points asthe ground truth cannot be known. We therefore stipulate that certification must be independent of the true label of the point being certified. Moreover, replacing the ground truth with the predicted label is unsatisfactory,because thepurpose ofgeneralizing totop-k predictions istoconsider cases where anyofthepredictionsinFk(x)maybecorrect. Wewouldthusliketopredict only whenm(S,x) < 0. To accomplish this we create an instrumented model,g, as given by EquationB2. First, by applying (C7), we obtain (C8).
Neural Information Processing Systems
Feb-9-2026, 20:37:00 GMT
- Country:
- North America > United States > Pennsylvania > Allegheny County > Pittsburgh (0.05)
- Technology: