Adversarially Robust Conformal Prediction
Asaf Gendler, Tsui-Wei Weng, Luca Daniel, Yaniv Romano
Abstract
Conformal prediction is a model-agnostic tool for constructing prediction sets that are valid under the common i.i.d. assumption, which has been applied to quantify the prediction uncertainty of deep net classifiers. In this paper, we generalize this framework to the case where adversaries exist during inference time, under which the i.i.d. assumption is grossly violated. By combining conformal prediction with randomized smoothing, our proposed method forms a prediction set with finite-sample coverage guarantee that holds for any data distribution with 2norm bounded adversarial noise, generated by any adversarial attack algorithm. The core idea is to bound the Lipschitz constant of the non-conformity score by smoothing it with Gaussian noise and leverage this knowledge to account for the effect of the unknown adversarial perturbation. We demonstrate the necessity of our method in the adversarial setting and the validity of our theoretical guarantee on three widely used benchmark data sets: CIFAR10, CIFAR100, and ImageNet. However, the sets constructed by the vanilla conformal method may not have the right coverage when the training and test points violate the exchangeability assumption (
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 11c66259-67d6-47c2-af32-e4a25a237b11Cited by top-tier papers29
- Conformal Prediction for Deep Classifier via Label RankingJianguo Huang, Huajun Xi, Linjun Zhang, Huaxiu Yao et al.ICML 2024 · 50 citations
- Conformal Prediction Sets for Graph Neural NetworksSoroush H. Zargarbashi, Simone Antonelli, Aleksandar BojchevskiICML 2023 · 49 citations
- Provably Robust Conformal Prediction with Improved EfficiencyGe Yan, Yaniv Romano, Tsui-Wei WengICLR 2024 · 26 citations
- Conformal Prediction under Lévy-Prokhorov Distribution Shifts: Robustness to Local and Global PerturbationsLiviu Aolaritei, Julie Zhu, Zheyu Oliver Wang, Michael I. Jordan et al.NeurIPS 2025 · 20 citations
- Robust Yet Efficient Conformal Prediction SetsSoroush H. Zargarbashi, Mohammad Sadegh Akhondzadeh, Aleksandar BojchevskiICML 2024 · 19 citations
Builds on7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- WILDS: A Benchmark of in-the-Wild Distribution ShiftsPang Wei Koh, Shiori Sagawa, Henrik Marklund, Sang Michael Xie et al.ICML 2021 · 1,773 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Adaptive Conformal Inference Under Distribution ShiftIsaac Gibbs, Emmanuel J. CandèsNeurIPS 2021 · 665 citations
- Classification with Valid and Adaptive CoverageYaniv Romano, Matteo Sesia, Emmanuel J. CandèsNeurIPS 2020 · 586 citations
Related papers
- Verifiably Robust Conformal PredictionLinus Jeary, Tom Kuipers, Mehran Hosseini, Nicola PaolettiNeurIPS 2024 · 16 citations
- Efficient Robust Conformal Prediction via Lipschitz-Bounded NetworksThomas Massena, Léo Andéol, Thibaut Boissin, Franck Mamalet et al.ICML 2025
- Distribution-informed Online Conformal PredictionDongjian Hu, Junxi Wu, Shu-Tao Xia, Changliang ZouICLR 2026 · 2 citations
- Robust Conformal Prediction Using Privileged InformationShai Feldman, Yaniv RomanoNeurIPS 2024 · 7 citations
- Robust Conformal Prediction with a Single Binary CertificateSoroush H. Zargarbashi, Aleksandar BojchevskiICLR 2025
