Higher-Order Certification For Randomized Smoothing
Jeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu, Luca Daniel
摘要
Randomized smoothing is a recently proposed defense against adversarial attacks that has achieved state-of-the-art provable robustness against 2 perturbations. A number of publications have extended the guarantees to other metrics, such as 1 or ∞ , by using different smoothing measures. Although the current framework has been shown to yield near-optimal p radii, the total safety region certified by the current framework can be arbitrarily small compared to the optimal. In this work, we propose a framework to improve the certified safety region for these smoothed classifiers without changing the underlying smoothing scheme. The theoretical contributions are as follows: 1) We generalize the certification for randomized smoothing by reformulating certified radius calculation as a nested optimization problem over a class of functions. 2) We provide a method to calculate the certified safety region using zeroth-order and first-order information for Gaussian-smoothed classifiers. We also provide a framework that generalizes the calculation for certification using higher-order information. 3) We design efficient, high-confidence estimators for the relevant statistics of the first-order information. Combining the theoretical contribution 2) and 3) allows us to certify safety region that are significantly larger than the ones provided by the current methods. On CIFAR10 and Imagenet datasets, the new regions certified by our approach achieve significant improvements on general 1 certified radii and on the 2 certified radii for color-space attacks ( 2 perturbation restricted to only one color/channel) while also achieving smaller improvements on the general 2 certified radii. As discussed in the future works section, our framework can also provide a way to circumvent the current impossibility results on achieving higher magnitudes of certified radii without requiring the use of data-dependent smoothing techniques. Randomized smoothing is a recently-proposed defense [3, 4, 5] that has achieved state-of-the-art robustness guarantees. Given any classifier f , denoted as a base classifier, randomized smoothing Preprint. Under review.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper23
- SmoothMix: Training Confidence-calibrated Smoothed Classifiers for Certified RobustnessJongheon Jeong, Sejun Park, Minkyu Kim, Heung-Chang Lee 等NeurIPS 2021 · 被引用 70 次
- On the Certified Robustness for Ensemble Models and BeyondZhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura 等ICLR 2022 · 被引用 57 次
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che 等NeurIPS 2022 · 被引用 56 次
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 被引用 56 次
- Scalable Certified Segmentation via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevICML 2021 · 被引用 49 次
它引用的顶会 Paper4
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Randomized Smoothing of All Shapes and SizesGreg Yang, Tony Duan, J. Edward Hu, Hadi Salman 等ICML 2020 · 被引用 237 次
- Curse of Dimensionality on Randomized Smoothing for Certifiable RobustnessAounon Kumar, Alexander Levine, Tom Goldstein, Soheil FeiziICML 2020 · 被引用 102 次
- A Framework for robustness Certification of Smoothed Classifiers using F-DivergencesKrishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, J. Zico Kolter 等ICLR 2020 · 被引用 74 次
相关 Paper
- Black-Box Certification with Randomized Smoothing: A Functional Optimization Based FrameworkDinghuai Zhang, Mao Ye, Chengyue Gong, Zhanxing Zhu 等NeurIPS 2020 · 被引用 71 次
- Certified Robustness for Top-k Predictions against Adversarial Perturbations via Randomized SmoothingJinyuan Jia, Xiaoyu Cao, Binghui Wang, Neil Zhenqiang GongICLR 2020 · 被引用 107 次
- Improving l1-Certified Robustness via Randomized Smoothing by Leveraging Box ConstraintsVáclav Vorácek, Matthias HeinICML 2023 · 被引用 11 次
- Robustness Certificates for Sparse Adversarial Attacks by Randomized AblationAlexander Levine, Soheil FeiziAAAI 2020 · 被引用 114 次
- Detection as Regression: Certified Object Detection with Median SmoothingPing-yeh Chiang, Michael J. Curry, Ahmed Abdelkader, Aounon Kumar 等NeurIPS 2020 · 被引用 15 次
