IoUCert — Robustness Verification for Anchor-Based Object Detectors

Benedikt Brückner, Alejandro J. Mercado, Yanghao Zhang, Panagiotis Kouvaros, Alessio Lomuscio
ECCV 2026

In brief

IoUCert is a formal verification method for assessing the robustness of object localisation in anchor-based object detectors. While most neural-network verification methods focus on classification, IoUCert verifies whether a detector continues to localise an object correctly throughout an entire region of possible inputs. The method enables, for the first time, robustness verification of realistic variants of widely used detector architectures including SSD, YOLOv2 and YOLOv3.

Problem and contribution

Object detection introduces substantial difficulties that are absent in classification. Detector outputs must be transformed into bounding-box coordinates through non-linear functions, and robustness is naturally expressed through Intersection over Union (IoU), itself a non-linear function of the predicted and target boxes. Applying standard bound-propagation techniques directly to these transformations produces bounds that rapidly become too loose to be useful in verification. IoUCert introduces a coordinate transformation that avoids these precision-degrading relaxations and allows bounds to be optimised directly with respect to the detector's anchor-box offsets. IoUCert also derives a specialised interval-bound-propagation procedure that computes optimal IoU bounds for the localisation problem.

Original runway image with green ground-truth box and blue YOLOv3 prediction box.Perturbed runway image with green ground-truth box and red YOLOv3 prediction box.
YOLOv3 runway counterexample: original and perturbed inputs. Prediction IoU changes from 0.89 to 0.11 (Figure 1).

Why it matters

IoUCert takes formal robustness analysis from the comparatively simple setting of image classification towards the richer perception pipelines required by autonomous systems. Experimentally, the new bounding method improves IoU-bound tightness by more than 50% across the evaluated regimes and, where conventional bounds are weakest, can eliminate over 95% of the verification branches that would otherwise need to be explored. The resulting framework can establish robustness for SSD and YOLO models under brightness, contrast and motion-blur perturbations on tasks drawn from LARD, Pascal VOC and COCO. This provides a formal yet practical basis for constructing safety envelopes around object-localisation components, rather than evaluating detectors only on finite test sets.

Technical direction and further work

The present work deliberately focuses on object localisation in single-object settings. The next step is to extend these guarantees to multiple objects, ultimately enabling verification of complete object-detection systems. This is particularly relevant to physical AI, where safety requires perception systems not merely to perform well on test data, but to remain robust to variations in the operating environment. Further work also includes scaling these methods to larger detectors such as YOLO11 and beyond, using approaches based on H²V.

Citation and BibTeX
@inproceedings{ioucert-2026,
  title = {IoUCert: Robustness Verification for Anchor-based Object Detectors},
  author = {Brückner, Benedikt and Mercado, Alejandro J. and Zhang, Yanghao and Kouvaros, Panagiotis and Lomuscio, Alessio},
  booktitle = {Proceedings of the 19th European Conference on Computer Vision},
  year = {2026},
  url = {https://arxiv.org/abs/2603.03043},
}