Provably Adversarially Robust Nearest Prototype Classifiers
Václav Vorácek, Matthias Hein
Abstract
Nearest prototype classifiers (NPCs) assign to each input point the label of the nearest prototype with respect to a chosen distance metric. A direct advantage of NPCs is that the decisions are interpretable. Previous work could provide lower bounds on the minimal adversarial perturbation in the (cid:96) p -threat model when using the same (cid:96) p distance for the NPCs. In this paper we provide a complete discussion on the complexity when using (cid:96) p -distances for decision and (cid:96) q -threat models for certification for p, q ∈ 1 , 2 , ∞ . In particular we provide scalable algorithms for the exact computation of the minimal adversarial perturbation when using (cid:96) 2 -distance and improved lower bounds in other cases. Using efficient improved lower bounds we train our P rovably adversarially robust NPC (PNPC), for MNIST which have better (cid:96) 2 -robustness guarantees than neural networks. Additionally, we show up to our knowledge the first certification results w.r.t. to the LPIPS perceptual metric which has been argued to be a more realistic threat model for image classification than (cid:96) p -balls. Our PNPC has on CIFAR10 higher certified robust accuracy than the empirical robust accuracy reported in (Laidlaw et al., 2021). The code is available in our repository.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aac3fa68-4ada-465a-8e8d-5be11b56f347Cited by top-tier papers5
- Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessAmbar Pal, Jeremias Sulam, René VidalNeurIPS 2023 · 15 citations
- Improving l1-Certified Robustness via Randomized Smoothing by Leveraging Box ConstraintsVáclav Vorácek, Matthias HeinICML 2023 · 11 citations
- A Robust Prototype-Based Network with Interpretable RBF Classifier FoundationsSascha Saralajew, Ashish Rana, Thomas Villmann, Ammar ShakerAAAI 2025 · 7 citations
- Sound Randomized Smoothing in Floating-Point ArithmeticVáclav Vorácek, Matthias HeinICLR 2023 · 1 citation
- SoK: Certified Robustness for Deep Neural NetworksLinyi Li, Tao Xie, Bo LiS&P 2023
Builds on11
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal et al.ICLR 2020 · 384 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
- Globally-Robust Neural NetworksKlas Leino, Zifan Wang, Matt FredriksonICML 2021 · 150 citations
Related papers
- Fast Adversarial Robustness Certification of Nearest Prototype Classifiers for Arbitrary SeminormsSascha Saralajew, Lars Holdijk, Thomas VillmannNeurIPS 2020 · 27 citations
- Towards Verifying Robustness of Neural Networks Against A Family of Semantic PerturbationsJeet Mohapatra, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu et al.CVPR 2020
- Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist NeuronsBohang Zhang, Tianle Cai, Zhou Lu, Di He et al.ICML 2021 · 62 citations
- Confidence-Calibrated Adversarial Training: Generalizing to Unseen AttacksDavid Stutz, Matthias Hein, Bernt SchieleICML 2020 · 158 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
