VLDB 2026 Research / reviewers in the wild / expert
Robert Stanforth
dblp:217/2131
· DBLP profile ↗
13ranked-venue papers
0as first author
2since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 13 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
11 papers |
Trustworthy machine learning · 84% Reinforcement learning · 5% Language models and text generation · 5% | |
| Software engineering, system software, and programming languages
2 papers |
Program verification · 100% |
Topics — the 19 heaviest of 22, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning
robustness |
2.1 | 5 | 2021 | Make Sure You're Unsure: A Framework for Verifying Probabilistic Specifications · NeurIPS 2021 Towards Stable and Efficient Training of Verifiably Robust Neural Networks · ICLR 2020 A Dual Approach to Verify and Train Deep Networks · IJCAI 2019 |
Machine learning › Trustworthy machine learning › robustness › certified robustness
certified adversarial robustness |
1.1 | 2 | 2024 | Expressive Losses for Verified Robustness via Convex Combinations · ICLR 2024 A Dual Approach to Verify and Train Deep Networks · IJCAI 2019 |
Machine learning › Trustworthy machine learning › robustness
certified robustness |
0.8 | 2 | 2020 | Towards Stable and Efficient Training of Verifiably Robust Neural Networks · ICLR 2020 Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation · EMNLP/IJCNLP (1) 2019 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.8 | 2 | 2019 | Adversarial Robustness through Local Linearization · NeurIPS 2019 Are Labels Required for Improving Adversarial Robustness? · NeurIPS 2019 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training |
0.8 | 2 | 2019 | Adversarial Robustness through Local Linearization · NeurIPS 2019 Scalable Verified Training for Provably Robust Image Classification · ICCV 2019 |
Machine learning › Trustworthy machine learning › robustness › certified robustness
interval bound propagation |
0.8 | 2 | 2019 | Scalable Verified Training for Provably Robust Image Classification · ICCV 2019 Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation · EMNLP/IJCNLP (1) 2019 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness › adversarially robust generalization
robustness-accuracy trade-off |
0.8 | 1 | 2024 | Expressive Losses for Verified Robustness via Convex Combinations · ICLR 2024 |
Program verification
neural network verification |
0.6 | 2 | 2021 | Make Sure You're Unsure: A Framework for Verifying Probabilistic Specifications · NeurIPS 2021 Towards Verified Robustness under Text Deletion Interventions · ICLR 2020 |
Machine learning › Reinforcement learning
deep reinforcement learning |
0.4 | 1 | 2020 | Toward Evaluating Robustness of Deep Reinforcement Learning with Continuous Control · ICLR 2020 |
Machine learning › Trustworthy machine learning
robustness evaluation |
0.4 | 1 | 2020 | Toward Evaluating Robustness of Deep Reinforcement Learning with Continuous Control · ICLR 2020 |
Machine learning › Trustworthy machine learning › verification
robustness verification |
0.4 | 1 | 2020 | Towards Verified Robustness under Text Deletion Interventions · ICLR 2020 |
Machine learning › Trustworthy machine learning
calibration |
0.4 | 1 | 2019 | Adversarial Robustness through Local Linearization · NeurIPS 2019 |
Machine learning › Trustworthy machine learning › verification
formal verification of neural networks |
0.4 | 1 | 2019 | A Dual Approach to Verify and Train Deep Networks · IJCAI 2019 |
Machine learning › Trustworthy machine learning › robustness
neural network verification |
0.4 | 1 | 2019 | Verification of Non-Linear Specifications for Neural Networks · ICLR (Poster) 2019 |
Machine learning › Reinforcement learning
continuous control |
0.1 | 1 | 2020 | Toward Evaluating Robustness of Deep Reinforcement Learning with Continuous Control · ICLR 2020 |
Machine learning › Trustworthy machine learning
verification |
0.1 | 1 | 2020 | Towards Stable and Efficient Training of Verifiably Robust Neural Networks · ICLR 2020 |
Machine learning › Optimization for machine learning
constrained optimization |
0.1 | 1 | 2019 | A Dual Approach to Verify and Train Deep Networks · IJCAI 2019 |
Machine learning › Optimization for machine learning
lagrangian relaxation |
0.1 | 1 | 2019 | A Dual Approach to Verify and Train Deep Networks · IJCAI 2019 |
Natural language and speech › Language models and text generation › natural language understanding › sentence pair modeling
natural language inference |
0.1 | 1 | 2019 | Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation · EMNLP/IJCNLP (1) 2019 |
Methods — techniques the papers use, named apart from their topics
adversarial training · 2.3interval bound propagation · 1.5lagrangian duality · 1.0functional multipliers · 1.0text deletion interventions · 0.9formal verification · 0.9convex combination · 0.8verification · 0.4robust training · 0.4adversarial perturbation · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Expressive Losses for Verified Robustness via Convex CombinationsabstractIn order to train networks for verified adversarial robustness, it is common to over-approximate the worst-case loss over perturbation regions, resulting in networks that attain verifiability at the expense of standard performance.
As shown in recent work, better trade-offs between accuracy and robustness can be obtained by carefully coupling adversarial training with over-approximations.
We hypothesize that the expressivity of a loss function, which we formalize as the ability to span a range of trade-offs between lower and upper bounds to the worst-case loss through a single parameter (the over-approximation coefficient), is key to attaining state-of-the-art performance.
To support our hypothesis, we show that trivial expressive losses, obtained via convex combinations between adversarial attacks and IBP bounds, yield state-of-the-art results across a variety of settings in spite of their conceptual simplicity.
We provide a detailed analysis of the relationship between the over-approximation coefficient and performance profiles across different expressive losses, showing that, while expressivity is essential, better approximations of the worst-case loss are not necessarily linked to superior robustness-accuracy trade-offs. Alessandro De Palma, Rudy Bunel, Krishnamurthy Dvijotham, M. Pawan Kumar, Robert Stanforth, Alessio Lomuscio |
ICLR | 5 |
| 2021 | Make Sure You're Unsure: A Framework for Verifying Probabilistic SpecificationsabstractMost real world applications require dealing with stochasticity like sensor noise or predictive uncertainty, where formal specifications of desired behavior are inherently probabilistic. Despite the promise of formal verification in ensuring the reliability of neural networks, progress in the direction of probabilistic specifications has been limited. In this direction, we first introduce a general formulation of probabilistic specifications for neural networks, which captures both probabilistic networks (e.g., Bayesian neural networks, MC-Dropout networks) and uncertain inputs (distributions over inputs arising from sensor noise or other perturbations). We then propose a general technique to verify such specifications by generalizing the notion of Lagrangian duality, replacing standard Lagrangian multipliers with "functional multipliers" that can be arbitrary functions of the activations at a given layer. We show that an optimal choice of functional multipliers leads to exact verification (i.e., sound and complete verification), and for specific forms of multipliers, we develop tractable practical verification algorithms. We empirically validate our algorithms by applying them to Bayesian Neural Networks (BNNs) and MC Dropout Networks, and certifying properties such as adversarial robustness and robust detection of out-of-distribution (OOD) data. On these tasks we are able to provide significantly stronger guarantees when compared to prior work -- for instance, for a VGG-64 MC-Dropout CNN trained on CIFAR-10 in a verification-agnostic manner, we improve the certified AUC (a verified lower bound on the true AUC) for robust OOD detection (on CIFAR-100) from $0 \% \rightarrow 29\%$. Similarly, for a BNN trained on MNIST, we improve on the $\ell_\infty$ robust accuracy from $60.2 \% \rightarrow 74.6\%$. Further, on a novel specification -- distributionally robust OOD detection -- we improve on the certified AUC from $5\% \rightarrow 23\%$. Leonard Berrada, Sumanth Dathathri, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Jonathan Uesato, Sven Gowal, M. Pawan Kumar |
NeurIPS | 4 |
| 2020 | Towards Verified Robustness under Text Deletion Interventions
Johannes Welbl, Po-Sen Huang, Robert Stanforth, Sven Gowal, Krishnamurthy Dvijotham, Martin Szummer, Pushmeet Kohli |
ICLR | 3 |
| 2020 | Toward Evaluating Robustness of Deep Reinforcement Learning with Continuous Control
Tsui-Wei Weng, Krishnamurthy Dvijotham, Jonathan Uesato, Sven Gowal, Robert Stanforth, Pushmeet Kohli |
ICLR | 6 |
| 2020 | Towards Stable and Efficient Training of Verifiably Robust Neural Networks
Huan Zhang 0001, Hongge Chen, Chaowei Xiao, Sven Gowal, Robert Stanforth, Bo Li 0026, Duane S. Boning, Cho-Jui Hsieh |
ICLR | 5 |
| 2019 | Achieving Verified Robustness to Symbol Substitutions via Interval Bound PropagationabstractPo-Sen Huang, Robert Stanforth, Johannes Welbl, Chris Dyer, Dani Yogatama, Sven Gowal, Krishnamurthy Dvijotham, Pushmeet Kohli. Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). 2019. Po-Sen Huang, Robert Stanforth, Johannes Welbl, Chris Dyer, Dani Yogatama, Sven Gowal, Krishnamurthy Dvijotham, Pushmeet Kohli |
EMNLP/IJCNLP (1) | 2 |
| 2019 | Scalable Verified Training for Provably Robust Image ClassificationabstractRecent work has shown that it is possible to train deep neural networks that are provably robust to norm-bounded adversarial perturbations. Most of these methods are based on minimizing an upper bound on the worst-case loss over all possible adversarial perturbations. While these techniques show promise, they often result in difficult optimization procedures that remain hard to scale to larger networks. Through a comprehensive analysis, we show how a simple bounding technique, interval bound propagation (IBP), can be exploited to train large provably robust neural networks that beat the state-of-the-art in verified accuracy. While the upper bound computed by IBP can be quite weak for general networks, we demonstrate that an appropriate loss and clever hyper-parameter schedule allow the network to adapt such that the IBP bound is tight. This results in a fast and stable learning algorithm that outperforms more sophisticated methods and achieves state-of-the-art results on MNIST, CIFAR-10 and SVHN. It also allows us to train the largest model to be verified beyond vacuous bounds on a downscaled version of IMAGENET. Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy A. Mann, Pushmeet Kohli |
ICCV | 3 |
| 2019 | Verification of Non-Linear Specifications for Neural Networks
Chongli Qin, Krishnamurthy Dvijotham, Brendan O'Donoghue, Rudy Bunel, Robert Stanforth, Sven Gowal, Jonathan Uesato, Grzegorz Swirszcz, Pushmeet Kohli |
ICLR (Poster) | 5 |
| 2019 | A Dual Approach to Verify and Train Deep NetworksabstractThis paper addressed the problem of formally verifying desirable properties of neural networks, i.e., obtaining provable guarantees that neural networks satisfy specifications relating their inputs and outputs (e.g., robustness to bounded norm adversarial perturbations). Most previous work on this topic was limited in its applicability by the size of the network, network architecture and the complexity of properties to be verified. In contrast, our framework applies to a general class of activation functions and specifications. We formulate verification as an optimization problem (seeking to find the largest violation of the specification) and solve a Lagrangian relaxation of the optimization problem to obtain an upper bound on the worst case violation of the specification being verified. Our approach is anytime, i.e., it can be stopped at any time and a valid bound on the maximum violation can be obtained. Finally, we highlight how this approach can be used to train models that are amenable to verification. Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Timothy A. Mann, Pushmeet Kohli |
IJCAI | 3 |
| 2019 | Are Labels Required for Improving Adversarial Robustness?abstractRecent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classification. This result is a key hurdle in the deployment of robust machine learning models in many real world applications where labeled data is expensive. Our main insight is that unlabeled data can be a competitive alternative to labeled data for training adversarially robust models. Theoretically, we show that in a simple statistical setting, the sample complexity for learning an adversarially robust model from unlabeled data matches the fully supervised case up to constant factors. On standard datasets like CIFAR- 10, a simple Unsupervised Adversarial Training (UAT) approach using unlabeled data improves robust accuracy by 21.7% over using 4K supervised examples alone, and captures over 95% of the improvement from the same number of labeled examples. Finally, we report an improvement of 4% over the previous state-of-the- art on CIFAR-10 against the strongest known attack by using additional unlabeled data from the uncurated 80 Million Tiny Images dataset. This demonstrates that our finding extends as well to the more realistic case where unlabeled data is also uncurated, therefore opening a new avenue for improving adversarial training. Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Alhussein Fawzi, Robert Stanforth, Pushmeet Kohli |
NeurIPS | 5 |
| 2019 | Adversarial Robustness through Local LinearizationabstractAdversarial training is an effective methodology for training deep neural networks that are robust against adversarial, norm-bounded perturbations. However, the computational cost of adversarial training grows prohibitively as the size of the model and number of input dimensions increase. Further, training against less expensive and therefore weaker adversaries produces models that are robust against weak attacks but break down under attacks that are stronger. This is often attributed to the phenomenon of gradient obfuscation; such models have a highly non-linear loss surface in the vicinity of training examples, making it hard for gradient-based attacks to succeed even though adversarial examples still exist. In this work, we introduce a novel regularizer that encourages the loss to behave linearly in the vicinity of the training data, thereby penalizing gradient obfuscation while encouraging robustness. We show via extensive experiments on CIFAR-10 and ImageNet, that models trained with our regularizer avoid gradient obfuscation and can be trained significantly faster than adversarial training. Using this regularizer, we exceed current state of the art and achieve 47% adversarial accuracy for ImageNet with L-infinity norm adversarial perturbations of radius 4/255 under an untargeted, strong, white-box attack. Additionally, we match state of the art results for CIFAR-10 at 8/255. Chongli Qin, James Martens, Sven Gowal, Dilip Krishnan, Krishnamurthy Dvijotham, Alhussein Fawzi, Soham De, Robert Stanforth, Pushmeet Kohli |
NeurIPS | 8 |
| 2019 | Efficient Neural Network Verification with Exactness Characterization
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Chongli Qin, Soham De, Pushmeet Kohli |
UAI | 2 |
| 2018 | A Dual Approach to Scalable Verification of Deep Networks
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy A. Mann, Pushmeet Kohli |
UAI | 2 |