Does a Hybrid Space-Aware Randomized Defense Improve Empirical and Certified Adversarial Robustness?
Joy Dhar, Manish Pandey, Behzad Bozorgtabar, Nayyar Zaidi, Wenyu Zhang, Weihong Li, Tingting Mu, Dwarikanath Mahapatra, Mahsa Baktashmotlagh, Trung Le, Chen Chen, Sajib Mistry
Abstract
We introduce Hybrid Space-aware Stochastic Convolution Attention Noise (HySCAN), a hybrid randomized defense that helps close the long-standing gap between provable robustness under ℓ 2 certificates and empirical robustness against strong ℓ ∞ attacks, while maintaining strong generalization across diverse imaging benchmarks. HySCAN jointly explores complementary sources of stochasticity at both training and inference: (i) implicit weight-space randomness via stochastic-aware Random Weights, and (ii) explicit feature-space randomness via Stochastic Attention Noise Injection modules. By incorporating randomness at both the parameter and representation levels, HySCAN enables meaningful certified guarantees while improving empirical robustness in practice. Comprehensive experiments on diverse imaging datasets e.g., CelebA, CIFAR-10 and CIFAR-100, ImageNet-1k, HAM10000, and NIH Chest X-ray demonstrate that HySCAN outperforms existing certified and empirical defenses, improving certified robustness by up to ≈ 9.6% and empirical robustness by up to ≈ 5% without reducing clean accuracy. Code-HySCAN
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a6a27ffa-33f6-4476-8018-b1351d417e61Builds on27
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- MMA Training: Direct Input Space Margin Maximization through Adversarial TrainingGavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, Ruitong HuangICLR 2020 · 308 citations
Related papers
- CERTIFIED VS. EMPIRICAL ADVERSARIAL ROBUSTNESS VIA HYBRID CONVOLUTIONS WITH ATTENTION STOCHASTICITYJoy Dhar, Song Xia, Manish Kumar Pandey, Maryam Haghighat et al.ICLR 2026
- Adversarial Robustness via Deformable Convolution with StochasticityYanxiang Ma, Zixuan Huang, Minjing Dong, Shan You et al.ICML 2025
- Robustness Certificates for Sparse Adversarial Attacks by Randomized AblationAlexander Levine, Soheil FeiziAAAI 2020 · 114 citations
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen et al.NeurIPS 2020 · 51 citations
- Black-Box Certification with Randomized Smoothing: A Functional Optimization Based FrameworkDinghuai Zhang, Mao Ye, Chengyue Gong, Zhanxing Zhu et al.NeurIPS 2020 · 71 citations
