Certified Defense to Image Transformations via Randomized Smoothing
Marc Fischer, Maximilian Baader, Martin T. Vechev
Abstract
We extend randomized smoothing to cover parameterized transformations (e.g., rotations, translations) and certify robustness in the parameter space (e.g., rotation angle). This is particularly challenging as interpolation and rounding effects mean that image transformations do not compose, in turn preventing direct certification of the perturbed image (unlike certification with p norms). We address this challenge by introducing three different kinds of defenses, each with a different guarantee (heuristic, distributional and individual) stemming from the method used to bound the interpolation error. Importantly, we show how individual certificates can be obtained via either statistical error bounds or efficient online inverse computation of the image transformation. We provide an implementation of all methods at https://github.com/eth-sri/transformation-smoothing . Introduction Deep neural networks are vulnerable to adversarial examples [1] -small changes that preserve semantics (e.g., p -noise or geometric transformations such as rotations) [2], but can affect the output of a network in undesirable ways. As a result, there has been substantial recent interest in methods which aim to ensure the network is certifiably robust to adversarial examples [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] . Certification guarantees There are two principal robustness guarantees a certified defense can provide at inference time: (i) the (standard) distributional guarantee, where a robustness score is computed offline on the test set to be interpreted in expectation for images drawn from the data distribution, and (ii) an individual guarantee, where a certificate is computed online for the (possibly perturbed) input. The choice of guarantee depends on the application and regulatory constraints. Guarantees with p norms When considering p norms, existing certification methods can be directly used to obtain either of the above two guarantees: for an image x and adversarial noise δ, δ p < r, proving that a classifier f is r-robust around x := x + δ is enough to guarantee f (x) = f (x ). That is, it suffices to prove robustness of a perturbed input in order to certify that the perturbation did not change the classification, as the r-ball around x includes x. Key challenge: guarantees for geometric perturbations Perhaps not intuitively, however, for more complex perturbations such as geometric transformations, proving robustness around an image x via existing methods (e.g., [9] [10] [11] [12] ) does not imply that f (x) = f (x ) for the original image x. To illustrate this issue, consider the rotation R γ , by angle γ of an image x, followed by an interpolation I. Certifying that the classification of the rotated image x := I • R γ (x) for γ < r is robust under further rotations I • R β for β < r is not sufficient to imply that x and x classify the same, as rotating x back by β = -γ does not return the original image x due to interpolation. A central challenge then is to develop techniques that are able to handle more involved perturbations. 34th Conference on Neural Information Processing Systems (NeurIPS 2020),
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 47b712b1-a46c-421f-9bac-cf293f73e103Cited by top-tier papers33
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che et al.NeurIPS 2022 · 56 citations
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 56 citations
- Scalable Certified Segmentation via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevICML 2021 · 49 citations
- Improved, Deterministic Smoothing for L1 Certified RobustnessAlexander Levine, Soheil FeiziICML 2021 · 49 citations
- Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial AttacksXinyu Zhang, Hanbin Hong, Yuan Hong, Peng Huang et al.S&P 2024 · 41 citations
Builds on3
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified RadiusRuntian Zhai, Chen Dan, Di He, Huan Zhang et al.ICLR 2020 · 195 citations
Related papers
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
- (Provable) Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and MoreJan Schuchardt, Yan Scholten, Stephan GünnemannNeurIPS 2023 · 5 citations
- DeformRS: Certifying Input Deformations with Randomized SmoothingMotasem Alfarra, Adel Bibi, Naeemullah Khan, Philip H. S. Torr et al.AAAI 2022 · 23 citations
- Improving l1-Certified Robustness via Randomized Smoothing by Leveraging Box ConstraintsVáclav Vorácek, Matthias HeinICML 2023 · 11 citations
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen et al.NeurIPS 2020 · 51 citations
