Relaxing Local Robustness
Klas Leino, Matt Fredrikson
Abstract
Certifiable local robustness, which rigorously precludes small-norm adversarial examples, has received significant attention as a means of addressing security concerns in deep learning. However, for some classification problems, local robustness is not a natural objective, even in the presence of adversaries; for example, if an image contains two classes of subjects, the correct label for the image may be considered arbitrary between the two, and thus enforcing strict separation between them is unnecessary. In this work, we introduce two relaxed safety properties for classifiers that address this observation: (1) relaxed top-k robustness, which serves as the analogue of top-k accuracy; and (2) affinity robustness, which specifies which sets of labels must be separated by a robustness margin, and which can be -close in space. We show how to construct models that can be efficiently certified against each relaxed robustness property, and trained with very little overhead relative to standard gradient descent. Finally, we demonstrate experimentally that these relaxed variants of robustness are well-suited to several significant classification problems, leading to lower rejection rates and higher certified accuracies than can be obtained when certifying"standard"local robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Unlocking Deterministic Robustness Certification on ImageNetKai Hu, Andy Zou, Zifan Wang, Klas Leino et al.NeurIPS 2023 · 18 citations
- Improved techniques for deterministic l2 robustnessSahil Singla, Soheil FeiziNeurIPS 2022 · 13 citations
- Formal Reasoning About Confidence and Automated Verification of Neural NetworksMohammad Afzal, S. Akshay, Blaise Genest, Ashutosh GuptaFM 2026
Builds on7
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Globally-Robust Neural NetworksKlas Leino, Zifan Wang, Matt FredriksonICML 2021 · 150 citations
- Certified Robustness for Top-k Predictions against Adversarial Perturbations via Randomized SmoothingJinyuan Jia, Xiaoyu Cao, Binghui Wang, Neil Zhenqiang GongICLR 2020 · 107 citations
- Fast Geometric Projections for Local Robustness CertificationAymeric Fromherz, Klas Leino, Matt Fredrikson, Bryan Parno et al.ICLR 2021 · 34 citations
Related papers
- Almost Tight L0-norm Certified Robustness of Top-k Predictions against Adversarial PerturbationsJinyuan Jia, Binghui Wang, Xiaoyu Cao, Hongbin Liu et al.ICLR 2022 · 26 citations
- Robustness and Accuracy Could Be Reconcilable by (Proper) DefinitionTianyu Pang, Min Lin, Xiao Yang, Jun Zhu et al.ICML 2022 · 168 citations
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang et al.AAAI 2020 · 13 citations
- Probably Approximately Global Robustness CertificationPeter Blohm, Patrick Indri, Thomas Gärtner, Sagar MalhotraICML 2025
- Localized Randomized Smoothing for Collective Robustness CertificationJan Schuchardt, Tom Wollschläger, Aleksandar Bojchevski, Stephan GünnemannICLR 2023
