Certified Adversarial Robustness for TinyLM Semantic Encoders

Develop a certified-robustness framework for TinyLM semantic encoders that covers semantic input perturbations, knowledge-base poisoning, federated model poisoning, and covert semantic-channel attacks under wireless channel conditions.

Background

The paper distinguishes semantic-level attacks from conventional perturbations in pixel or token space because compression and wireless transmission intervene between the input and the final decision. Existing certified-robustness methods do not directly account for this semantic-and-channel pipeline.

Four attack classes are identified: semantic perturbation, knowledge-base poisoning, federated-learning model poisoning, and covert semantic-channel attacks. The paper states that existing work does not address all four within one certification framework.

References

Semantic-level adversarial attacks (imperceptible input perturbations that flip a decoded meaning) have no certified-robustness framework analogous to $\ell_\infty$-norm certification in image classification --- and the TinyLM systems surveyed here (Section~\ref{sec:compression}) are, if anything, a smaller attack surface to certify than a full LLM, yet none of the compression techniques reviewed was evaluated with certification in mind.

Closing the Semantic-Edge Gap: Tiny Language Models for 6G Wireless Intelligence  (2609.03747 - Kamath et al., 3 Sep 2026) in Challenge 5, Section 8