55d491cf951b1b920900684d71419282-Supplemental.pdf
–Neural Information Processing Systems
Now, one could try to translate the constraint as|xk x0k| α for all k = 1,...,r. Here, we investigate the impact of the balance parameterγ from Equation (5) on the accuracyfairnesstradeoff. Note thatourmethod canincrease bothaccuracy, albeit only by a small amount, and fairness for certain values ofγ (e.g., γ = 2). Across all datasets and values ofγ the largest increase in certification for adversarial training is roughly 7%, with a simultaneous accuracy drop of 0.5%, and the largest accuracy drop is roughly 1%, with a simultaneous increaseincertification of2.9%. Wenote that although Fischer et al.[15]support terms with real-valued functions, we only consider linear functions since nonlinear constraints, e.g.,x2 < 3, cannot be encoded exactly as MILP.
Neural Information Processing Systems
Feb-8-2026, 11:44:46 GMT