CERTIFIED VS. EMPIRICAL ADVERSARIAL ROBUSTNESS VIA HYBRID CONVOLUTIONS WITH ATTENTION STOCHASTICITY
Joy Dhar, Song Xia, Manish Kumar Pandey, Maryam Haghighat, Azadeh Alavi, Ferdous Sohel, Wenyu Zhang, Nayyar Zaidi
Abstract
We introduce Hybrid Convolutions with Attention Stochasticity (HyCAS), an adversarial defense that narrows the long-standing gap between provable robustness under ℓ 2 certificates and empirical robustness against strong ℓ attacks, while preserving strong generalization across diverse imaging benchmarks. HyCAS unifies deterministic and randomized principles by coupling 1-Lipschitz, spectrally normalized convolutions with two stochastic components-spectral normalized random-projection filters and a randomized attention-noise mechanism-to realize a randomized defense. Injecting smoothing randomness inside the architecture yields an overall 2-Lipschitz network with formal certificates. Extensive experiments on diverse imaging benchmarks-including CIFAR-10/100, ImageNet-1k, NIH Chest X-ray, HAM10000-show that HyCAS surpasses prior leading certified and empirical defenses, boosting certified accuracy by up to 7.3% (on NIH Chest X-ray) and empirical robustness by up to 3.1% (on HAM10000), without sacrificing clean accuracy. These results show that a randomized Lipschitz constrained architecture can simultaneously improve both certified ℓ 2 and empirical ℓ adversarial robustness, thereby supporting safer deployment of deep models in high-stakes applications. Code: https://github.com/misti1203/HyCAS
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 610b4f2e-ebe2-4779-bdbe-c3dc7273a044Cited by top-tier papers2
- Advancing Multimodal Fusion on Heterogeneous Medical Data with Hybrid Geometry AttentionJoy Dhar, Manish Kumar Pandey, Nayyar Zaidi, Chen Chen et al.KDD 2026
- Does a Hybrid Space-Aware Randomized Defense Improve Empirical and Certified Adversarial Robustness?Joy Dhar, Manish Pandey, Behzad Bozorgtabar, Nayyar Zaidi et al.ICML 2026
Builds on30
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
Related papers
- Bridging Symmetry and Robustness: On the Role of Equivariance in Enhancing Adversarial RobustnessLongwei Wang, Ifrat Ikhtear Uddin, KC Santosh, Chaowei Zhang et al.NeurIPS 2025 · 12 citations
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang et al.AAAI 2020 · 13 citations
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
- Orthogonalizing Convolutional Layers with the Cayley TransformAsher Trockman, J. Zico KolterICLR 2021 · 137 citations
- Smoothed Embeddings for Certified Few-Shot LearningMikhail Pautov, Olesya Kuznetsova, Nurislam Tursynbek, Aleksandr Petiushko et al.NeurIPS 2022 · 10 citations
