Adversarially Robust Conformal Prediction
Asaf Gendler, Tsui-Wei Weng, Luca Daniel, Yaniv Romano
摘要
Conformal prediction is a model-agnostic tool for constructing prediction sets that are valid under the common i.i.d. assumption, which has been applied to quantify the prediction uncertainty of deep net classifiers. In this paper, we generalize this framework to the case where adversaries exist during inference time, under which the i.i.d. assumption is grossly violated. By combining conformal prediction with randomized smoothing, our proposed method forms a prediction set with finite-sample coverage guarantee that holds for any data distribution with 2norm bounded adversarial noise, generated by any adversarial attack algorithm. The core idea is to bound the Lipschitz constant of the non-conformity score by smoothing it with Gaussian noise and leverage this knowledge to account for the effect of the unknown adversarial perturbation. We demonstrate the necessity of our method in the adversarial setting and the validity of our theoretical guarantee on three widely used benchmark data sets: CIFAR10, CIFAR100, and ImageNet. However, the sets constructed by the vanilla conformal method may not have the right coverage when the training and test points violate the exchangeability assumption (
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper29
- Conformal Prediction for Deep Classifier via Label RankingJianguo Huang, Huajun Xi, Linjun Zhang, Huaxiu Yao 等ICML 2024 · 被引用 50 次
- Conformal Prediction Sets for Graph Neural NetworksSoroush H. Zargarbashi, Simone Antonelli, Aleksandar BojchevskiICML 2023 · 被引用 49 次
- Provably Robust Conformal Prediction with Improved EfficiencyGe Yan, Yaniv Romano, Tsui-Wei WengICLR 2024 · 被引用 26 次
- Conformal Prediction under Lévy-Prokhorov Distribution Shifts: Robustness to Local and Global PerturbationsLiviu Aolaritei, Julie Zhu, Zheyu Oliver Wang, Michael I. Jordan 等NeurIPS 2025 · 被引用 20 次
- Robust Yet Efficient Conformal Prediction SetsSoroush H. Zargarbashi, Mohammad Sadegh Akhondzadeh, Aleksandar BojchevskiICML 2024 · 被引用 19 次
它引用的顶会 Paper7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- WILDS: A Benchmark of in-the-Wild Distribution ShiftsPang Wei Koh, Shiori Sagawa, Henrik Marklund, Sang Michael Xie 等ICML 2021 · 被引用 1,773 次
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Adaptive Conformal Inference Under Distribution ShiftIsaac Gibbs, Emmanuel J. CandèsNeurIPS 2021 · 被引用 665 次
- Classification with Valid and Adaptive CoverageYaniv Romano, Matteo Sesia, Emmanuel J. CandèsNeurIPS 2020 · 被引用 586 次
相关 Paper
- Verifiably Robust Conformal PredictionLinus Jeary, Tom Kuipers, Mehran Hosseini, Nicola PaolettiNeurIPS 2024 · 被引用 16 次
- Efficient Robust Conformal Prediction via Lipschitz-Bounded NetworksThomas Massena, Léo Andéol, Thibaut Boissin, Franck Mamalet 等ICML 2025
- Distribution-informed Online Conformal PredictionDongjian Hu, Junxi Wu, Shu-Tao Xia, Changliang ZouICLR 2026 · 被引用 2 次
- Robust Conformal Prediction Using Privileged InformationShai Feldman, Yaniv RomanoNeurIPS 2024 · 被引用 7 次
- Robust Conformal Prediction with a Single Binary CertificateSoroush H. Zargarbashi, Aleksandar BojchevskiICLR 2025
