Center Smoothing: Certified Robustness for Networks with Structured Outputs
Aounon Kumar, Tom Goldstein
Abstract
The study of provable adversarial robustness has mostly been limited to classification tasks and models with one-dimensional real-valued outputs. We extend the scope of certifiable robustness to problems with more general and structured outputs like sets, images, language, etc. We model the output space as a metric space under a distance/similarity function, such as intersection-over-union, perceptual similarity, total variation distance, etc. Such models are used in many machine learning problems like image segmentation, object detection, generative models, image/audio-to-text systems, etc. Based on a robustness technique called randomized smoothing, our procedure can produce models with the guarantee that the change in the output, as measured by the distance metric, remains small for any norm-bounded adversarial perturbation of the input. We apply our method to create certifiably robust models with disparate output spaces - from sets to images - and show that it yields meaningful certificates without significantly degrading the performance of the base model. Code for our experiments is available at: https://github.com/aounon/center-smoothing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- Endowing Pre-trained Graph Models with Provable FairnessZhongjian Zhang, Mengmei Zhang, Yue Yu, Cheng Yang et al.WWW 2024 · 16 citations
- LipSim: A Provably Robust Perceptual Similarity MetricSara Ghazanfari, Alexandre Araujo, Prashanth Krishnamurthy, Farshad Khorrami et al.ICLR 2024 · 14 citations
- Smoothed Embeddings for Certified Few-Shot LearningMikhail Pautov, Olesya Kuznetsova, Nurislam Tursynbek, Aleksandr Petiushko et al.NeurIPS 2022 · 10 citations
- Training on Foveated Images Improves Robustness to Adversarial AttacksMuhammad A. Shah, Aqsa Kashaf, Bhiksha RajNeurIPS 2023 · 9 citations
- Unified Mechanism-Specific Amplification by Subsampling and Group Privacy AmplificationJan Schuchardt, Mihail Stoian, Arthur Kosmala, Stephan GünnemannNeurIPS 2024 · 8 citations
Builds on10
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Adversarial Policies: Attacking Deep Reinforcement LearningAdam Gleave, Michael Dennis, Cody Wild, Neel Kant et al.ICLR 2020 · 415 citations
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu et al.ICLR 2020 · 194 citations
- (De)Randomized Smoothing for Certifiable Defense against Patch AttacksAlexander Levine, Soheil FeiziNeurIPS 2020 · 188 citations
- Robustness Certificates for Sparse Adversarial Attacks by Randomized AblationAlexander Levine, Soheil FeiziAAAI 2020 · 114 citations
Related papers
- Robustness Certification for Structured Prediction with General Inputs via Safe Region Modeling in the Semimetric Output SpaceHuaqing Shao, Lanjun Wang, Junchi YanKDD 2023 · 2 citations
- A Framework for robustness Certification of Smoothed Classifiers using F-DivergencesKrishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, J. Zico Kolter et al.ICLR 2020 · 74 citations
- (Provable) Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and MoreJan Schuchardt, Yan Scholten, Stephan GünnemannNeurIPS 2023 · 5 citations
- Localized Randomized Smoothing for Collective Robustness CertificationJan Schuchardt, Tom Wollschläger, Aleksandar Bojchevski, Stephan GünnemannICLR 2023
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
