TSS: Transformation-Specific Smoothing for Robustness Certification
Linyi Li, Maurice Weber, Xiaojun Xu, Luka Rimanic, Bhavya Kailkhura, Tao Xie, Ce Zhang, Bo Li
Abstract
As machine learning (ML) systems become pervasive, safeguarding their security is critical. However, recently it has been demonstrated that motivated adversaries are able to mislead ML systems by perturbing test data using semantic transformations. While there exists a rich body of research providing provable robustness guarantees for ML models against Lp bounded adversarial perturbations, guarantees against semantic perturbations remain largely underexplored. In this paper, we provide TSS-a unified framework for certifying ML robustness against general adversarial semantic transformations. First, depending on the properties of each transformation, we divide common transformations into two categories, namely resolvable (e.g., Gaussian blur) and differentially resolvable (e.g., rotation) transformations. For the former, we propose transformation-specific randomized smoothing strategies and obtain strong robustness certification. The latter category covers transformations that involve interpolation errors, and we propose a novel approach based on stratified sampling to certify the robustness. Our framework TSS leverages these certification strategies and combines with consistency-enhanced training to provide rigorous certification of robustness. We conduct extensive experiments on over ten types of challenging semantic transformations and show that TSS significantly outperforms the state of the art. Moreover, to the best of our knowledge, TSS is the first approach that achieves nontrivial certified robustness on the large-scale ImageNet dataset. For instance, our framework achieves 30.4% certified robust accuracy against rotation attack (within ±30°) on ImageNet. Moreover, to consider a broader range of transformations, we show TSS is also robust against adaptive attacks and unforeseen image corruptions such as CIFAR-10-C and ImageNet-C.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b1ee64ca-2598-44f2-b148-7113c5fd8330Cited by top-tier papers33
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 56 citations
- Scalable Certified Segmentation via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevICML 2021 · 49 citations
- LOT: Layer-wise Orthogonal Training on Improving l2 Certified RobustnessXiaojun Xu, Linyi Li, Bo LiNeurIPS 2022 · 42 citations
- Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial AttacksXinyu Zhang, Hanbin Hong, Yuan Hong, Peng Huang et al.S&P 2024 · 41 citations
- Double Sampling Randomized SmoothingLinyi Li, Jiawei Zhang, Tao Xie, Bo LiICML 2022 · 29 citations
Builds on20
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang et al.NeurIPS 2020 · 415 citations
Related papers
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
- TPC: Transformation-Specific Smoothing for Point Cloud ModelsWenda Chu, Linyi Li, Bo LiICML 2022 · 14 citations
- CC-CERT: A Probabilistic Approach to Certify General Robustness of Neural NetworksMikhail Pautov, Nurislam Tursynbek, Marina Munkhoeva, Nikita Muravev et al.AAAI 2022 · 27 citations
- Certified Defense to Image Transformations via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevNeurIPS 2020 · 78 citations
- COMMIT: Certifying Robustness of Multi-Sensor Fusion Systems Against Semantic AttacksZijian Huang, Wenda Chu, Linyi Li, Chejian Xu et al.AAAI 2025 · 2 citations
