Falsification-Driven Robust Training
Using adversarial falsification to expand certified L2 robustness radii.
- Period
- August–November 2025
- Kind
- course
- Stack
- CARLA, VerifAI, AutoLiRPA, PyTorch
- Guide
- Prof. Supratik Chakraborty, IIT Bombay
- Built a pipeline coupling the CARLA simulator with VerifAI to synthesise adversarial examples, then used them to train models that are provably more robust.
- Computed certified L2 robustness radii with CROWN via auto_LiRPA, chosen over the tighter Alpha- and Beta-CROWN variants whose VRAM and latency demands made verification infeasible at this scale on a 6 GB GPU.
- Falsification-driven active learning expanded certified L2 robustness radii over three retraining cycles, showing markedly better sample efficiency than random sampling.