(De)Randomized Smoothing for Certifiable Defense against Patch Attacks
Alexander Levine, Soheil Feizi
Abstract
Patch adversarial attacks on images, in which the attacker can distort pixels within a region of bounded size, are an important threat model since they provide a quantitative model for physical adversarial attacks. In this paper, we introduce a certifiable defense against patch attacks that guarantees for a given image and patch attack size, no patch adversarial examples exist. Our method is related to the broad class of randomized smoothing robustness schemes which provide high-confidence probabilistic robustness certificates. By exploiting the fact that patch attacks are more constrained than general sparse attacks, we derive meaningfully large robustness certificates. Additionally, the algorithm we propose is de-randomized, providing deterministic certificates. To the best of our knowledge, there exists only one prior method for certifiable defense against patch attacks, which relies on interval bound propagation. While this sole existing method performs well on MNIST, it has several limitations: it requires computationally expensive training, does not scale to ImageNet, and performs poorly on CIFAR-10. In contrast, our proposed method effectively addresses all of these issues: our classifier can be trained quickly, achieves high clean and certified robust accuracy on CIFAR-10, and provides certificates at the ImageNet scale. For example, for a 5*5 patch attack on CIFAR-10, our method achieves up to around 57.8% certified accuracy (with a classifier around 83.9% clean accuracy), compared to at most 30.3% certified accuracy for the existing method (with a classifier with around 47.8% clean accuracy), effectively establishing a new state-of-the-art. Code is available at this https URL.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e5043ba3-69b9-44ca-bdbb-e5402a33488eCited by top-tier papers45
- BadEncoder: Backdoor Attacks to Pre-trained Encoders in Self-Supervised LearningJinyuan Jia, Yupei Liu, Neil Zhenqiang GongS&P 2022 · 200 citations
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 172 citations
- Curse of Dimensionality on Randomized Smoothing for Certifiable RobustnessAounon Kumar, Alexander Levine, Tom Goldstein, Soheil FeiziICML 2020 · 102 citations
- Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch DetectionJiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa et al.CVPR 2022 · 99 citations
- Towards Practical Certifiable Patch Defense with Vision TransformerZhaoyu Chen, Bo Li, Jianghe Xu, Shuang Wu et al.CVPR 2022 · 60 citations
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu et al.ICLR 2020 · 194 citations
- Certified Robustness to Label-Flipping Attacks via Randomized SmoothingElan Rosenfeld, Ezra Winston, Pradeep Ravikumar, J. Zico KolterICML 2020 · 182 citations
- Robustness Certificates for Sparse Adversarial Attacks by Randomized AblationAlexander Levine, Soheil FeiziAAAI 2020 · 114 citations
Related papers
- PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image ClassifierChong Xiang, Saeed Mahloujifar, Prateek MittalUSENIX Security 2022
- CertMask: Certifiable Defense Against Adversarial Patches via Theoretically Optimal Mask CoverageXuntao Lyu, Ching-Chi Lin, Abdullah Al Arafat, Georg von der Brüggen et al.AAAI 2026
- ScaleCert: Scalable Certified Defense against Adversarial Patches with Sparse Superficial LayersHusheng Han, Kaidi Xu, Xing Hu, Xiaobing Chen et al.NeurIPS 2021 · 27 citations
- Certified Defences Against Adversarial Patch Attacks on Semantic SegmentationMaksym Yatsura, Kaspar Sakmann, N. Grace Hua, Matthias Hein et al.ICLR 2023 · 3 citations
- DorPatch: Distributed and Occlusion-Robust Adversarial Patch to Evade Certifiable DefensesChaoxiang He, Xiaojing Ma, Bin B. Zhu, Yimiao Zeng et al.NDSS 2024
