On the Certified Robustness for Ensemble Models and Beyond
Zhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura, Tao Xie, Bo Li
Abstract
Recent studies show that deep neural networks (DNN) are vulnerable to adversarial examples, which aim to mislead DNNs by adding perturbations with small magnitude. To defend against such attacks, both empirical and theoretical defense approaches have been extensively studied for a single ML model. In this work, we aim to analyze and provide the certified robustness for ensemble ML models, together with the sufficient and necessary conditions of robustness for different ensemble protocols. Although ensemble models are shown more robust than a single model empirically; surprisingly, we find that in terms of the certified robustness the standard ensemble models only achieve marginal improvement compared to a single model. Thus, to explore the conditions that guarantee to provide certifiably robust ensemble ML models, we first prove that diversified gradient and large confidence margin are sufficient and necessary conditions for certifiably robust ensemble models under the model-smoothness assumption. We then provide the bounded model-smoothness analysis based on the proposed Ensemble-before-Smoothing strategy. We also prove that an ensemble model can always achieve higher certified robustness than a single base model under mild conditions. Inspired by the theoretical findings, we propose the lightweight Diversity Regularized Training (DRT) to train certifiably robust ensemble ML models. Extensive experiments show that our DRT enhanced ensembles can consistently achieve higher certified robustness than existing single and ensemble ML models, demonstrating the state-of-the-art certified L 2 -robustness on MNIST, CIFAR-10, and ImageNet datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db139a59-c763-4a9b-8d19-9ae5602fff47Cited by top-tier papers25
- LOT: Layer-wise Orthogonal Training on Improving l2 Certified RobustnessXiaojun Xu, Linyi Li, Bo LiNeurIPS 2022 · 42 citations
- Boosting the Certified Robustness of L-infinity Distance NetsBohang Zhang, Du Jiang, Di He, Liwei WangICLR 2022 · 36 citations
- Quantifying and Enhancing Multi-modal Robustness with Modality PreferenceZequn Yang, Yake Wei, Ce Liang, Di HuICLR 2024 · 27 citations
- Building Robust Ensembles via Margin BoostingDinghuai Zhang, Hongyang Zhang, Aaron C. Courville, Yoshua Bengio et al.ICML 2022 · 18 citations
- (Certified!!) Adversarial Robustness for Free!Nicholas Carlini, Florian Tramèr, Krishnamurthy (Dj) Dvijotham, Leslie Rice et al.ICLR 2023 · 17 citations
Builds on19
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning AttacksAmbra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski et al.USENIX Security 2019 · 466 citations
Related papers
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo et al.NeurIPS 2021 · 76 citations
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang et al.AAAI 2020 · 13 citations
- Exploiting Joint Robustness to Adversarial PerturbationsAli Dabouei, Sobhan Soleymani, Fariborz Taherkhani, Jeremy M. Dawson et al.CVPR 2020
- Self-ensemble Adversarial Training for Improved RobustnessHongjun Wang, Yisen WangICLR 2022 · 61 citations
- Adversarial Defence by Diversified Simultaneous Training of Deep EnsemblesBo Huang, Zhiwei Ke, Yi Wang, Wei Wang et al.AAAI 2021 · 20 citations
