Certified Adversarial Robustness of End-to-End Malware Detectors via (De)Randomized Smoothing
A novel deterministic certification schema based on (de)randomized smoothing that guarantees that each chunk either contains or does not contain an adversarial perturbation, enabling it to handle manipulations occurring at arbitrary locations within the program and compute deterministic estimates of the perturbation magnitude required to evade detection.