Certify or Predict: Boosting Certified Robustness with Compositional Architectures
Mark Niklas Müller, Mislav Balunovic, Martin T. Vechev
Abstract
A core challenge with existing certified defense mechanisms is that while they improve certified robustness, they also tend to drastically decrease natural accuracy, making it difficult to use these methods in practice. In this work, we propose a new architecture which addresses this challenge and enables one to boost the certified robustness of any state-of-the-art deep network, while controlling the overall accuracy loss, without requiring retraining. The key idea is to combine this model with a (smaller) certified network where at inference time, an adaptive selection mechanism decides on the network to process the input sample. The approach is compositional: one can combine any pair of state-of-the-art (e.g., EfficientNet or ResNet) and certified networks, without restriction. The resulting architecture enables much higher natural accuracy than previously possible with certified defenses alone, while substantially boosting the certified robustness of deep networks. We demonstrate the effectiveness of this adaptive approach on a variety of datasets and architectures. For instance, on CIFAR-10 with an perturbation of 2/255, we are the first to obtain a high natural accuracy (90.1%) with non-trivial certified robustness (27.5%). Notably, prior state-of-the-art methods incur a substantial drop in accuracy for a similar certified robustness.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 359c8389-11e0-4b41-89b3-e61b5943eab7Cited by top-tier papers5
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che et al.NeurIPS 2022 · 56 citations
- Multi-scale Diffusion Denoised SmoothingJongheon Jeong, Jinwoo ShinNeurIPS 2023 · 15 citations
- Connecting Certified and Adversarial TrainingYuhao Mao, Mark Niklas Müller, Marc Fischer, Martin T. VechevNeurIPS 2023 · 14 citations
- Hierarchical Randomized SmoothingYan Scholten, Jan Schuchardt, Aleksandar Bojchevski, Stephan GünnemannNeurIPS 2023 · 14 citations
- Certified Training: Small Boxes are All You NeedMark Niklas Müller, Franziska Eckert, Marc Fischer, Martin T. VechevICLR 2023 · 10 citations
Related papers
- Adversarial Training and Provable Defenses: Bridging the GapMislav Balunovic, Martin T. VechevICLR 2020 · 186 citations
- Provably robust classification of adversarial examples with detectionFatemeh Sheikholeslami, Ali Lotfi, J. Zico KolterICLR 2021 · 27 citations
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang et al.AAAI 2020 · 13 citations
- Fast Training of Provably Robust Neural Networks by SinglePropAkhilan Boopathy, Lily Weng, Sijia Liu, Pin-Yu Chen et al.AAAI 2021 · 8 citations
- Accelerating Certified Robustness Training via Knowledge TransferPratik Vaishnavi, Kevin Eykholt, Amir RahmatiNeurIPS 2022 · 8 citations
