On the Scalability of Certified Adversarial Robustness with Generated Data
Thomas Altstidl, David Dobre, Arthur Kosmala, Bjoern M. Eskofier, Gauthier Gidel, Leo Schwinn
Abstract
Certified defenses against adversarial attacks offer formal guarantees on the robustness of a model, making them more reliable than empirical methods such as adversarial training, whose effectiveness is often later reduced by unseen attacks. Still, the limited certified robustness that is currently achievable has been a bottleneck for their practical adoption. Gowal et al. and Wang et al. have shown that generating additional training data using state-of-the-art diffusion models can considerably improve the robustness of adversarial training. In this work, we demonstrate that a similar approach can substantially improve deterministic certified defenses but also reveal notable differences in the scaling behavior between certified and empirical methods. In addition, we provide a list of recommendations to scale the robustness of certified training approaches. Our approach achieves state-of-the-art deterministic robustness certificates on CIFAR-10 for the ℓ 2 ( ϵ = 36 / 255 ) and ℓ ∞ ( ϵ = 8 / 255 ) threat models, outperforming the previous results by +3 . 95 and +1 . 39 percentage points, respectively. Furthermore, we report similar improvements for CIFAR-100.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on19
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- Elucidating the Design Space of Diffusion-Based Generative ModelsTero Karras, Miika Aittala, Timo Aila, Samuli LaineNeurIPS 2022 · 3,959 citations
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg et al.NeurIPS 2021 · 384 citations
- Better Diffusion Models Further Improve Adversarial TrainingZekai Wang, Tianyu Pang, Chao Du, Min Lin et al.ICML 2023 · 300 citations
Related papers
- (Certified!!) Adversarial Robustness for Free!Nicholas Carlini, Florian Tramèr, Krishnamurthy (Dj) Dvijotham, Leslie Rice et al.ICLR 2023 · 17 citations
- Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?Vikash Sehwag, Saeed Mahloujifar, Tinashe Handina, Sihui Dai et al.ICLR 2022 · 150 citations
- Fast Training of Provably Robust Neural Networks by SinglePropAkhilan Boopathy, Lily Weng, Sijia Liu, Pin-Yu Chen et al.AAAI 2021 · 8 citations
- Robust Classification via a Single Diffusion ModelHuanran Chen, Yinpeng Dong, Zhengyi Wang, Xiao Yang et al.ICML 2024 · 94 citations
- Diffusion Models are Certifiably Robust ClassifiersHuanran Chen, Yinpeng Dong, Shitong Shao, Zhongkai Hao et al.NeurIPS 2024 · 42 citations
