Sound Randomized Smoothing in Floating-Point Arithmetic
Václav Vorácek, Matthias Hein
Abstract
Randomized smoothing is sound when using infinite precision. However, we show that randomized smoothing is no longer sound for limited floating-point precision. We present a simple example where randomized smoothing certifies a radius of 1.26 around a point, even though there is an adversarial example in the distance 0.8 and show how this can be abused to give false certificates for CIFAR10. We discuss the implicit assumptions of randomized smoothing and show that they do not apply to generic image classification models whose smoothed versions are commonly certified. In order to overcome this problem, we propose a sound approach to randomized smoothing when using floating-point precision with essentially equal speed for quantized input. It yields sound certificates for image classifiers which for the ones tested so far are very similar to the unsound practice of randomized smoothing. Our only assumption is that we have access to a fair coin.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext feddee76-95ca-42b5-a48a-5e594e4ce64bCited by top-tier papers1
Ask how each one uses itBuilds on16
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- The Discrete Gaussian for Differential PrivacyClément L. Canonne, Gautam Kamath, Thomas SteinkeNeurIPS 2020 · 355 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
Related papers
- Improving l1-Certified Robustness via Randomized Smoothing by Leveraging Box ConstraintsVáclav Vorácek, Matthias HeinICML 2023 · 11 citations
- Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step DefencesSaiyue Lyu, Shadab Shaikh, Frederick Shpilevskiy, Evan Shelhamer et al.NeurIPS 2024 · 15 citations
- Certifying Confidence via Randomized SmoothingAounon Kumar, Alexander Levine, Soheil Feizi, Tom GoldsteinNeurIPS 2020 · 44 citations
- Integer-arithmetic-only Certified Robustness for Quantized Neural NetworksHaowen Lin, Jian Lou, Li Xiong, Cyrus ShahabiICCV 2021 · 18 citations
- Certified Robustness for Top-k Predictions against Adversarial Perturbations via Randomized SmoothingJinyuan Jia, Xiaoyu Cao, Binghui Wang, Neil Zhenqiang GongICLR 2020 · 107 citations
