Supplementary Material: Relaxing Local Robustness

Neural Information Processing Systems 

That is, Jia et al. provide a probabilistic guarantee that Equation A1 holds. In their evaluation, Jia et al. consider a point, We therefore stipulate that certification must be independent of the true label of the point being certified. While Jia et al. do not address this issue, one straightforward adaptation of their approach is to take Nets, which naturally satisfy affinity robustness on all non-rejected points. By the definition of y, we obtain (C2). Then, by applying (C6) we obtain (C9).