Lune

ICLR2022顶会

Almost Tight L0-norm Certified Robustness of Top-k Predictions against Adversarial Perturbations

Jinyuan Jia, Binghui Wang, Xiaoyu Cao, Hongbin Liu, Neil Zhenqiang Gong

2022年份
26被引次数
9顶会引用

摘要

Top-kk predictions are used in many real-world applications such as machine learning as a service, recommender systems, and web searches. ℓ0\ell_0-norm adversarial perturbation characterizes an attack that arbitrarily modifies some features of an input such that a classifier makes an incorrect prediction for the perturbed input. ℓ0\ell_0-norm adversarial perturbation is easy to interpret and can be implemented in the physical world. Therefore, certifying robustness of top-kk predictions against ℓ0\ell_0-norm adversarial perturbation is important. However, existing studies either focused on certifying ℓ0\ell_0-norm robustness of top-11 predictions or ℓ2\ell_2-norm robustness of top-kk predictions. In this work, we aim to bridge the gap. Our approach is based on randomized smoothing, which builds a provably robust classifier from an arbitrary classifier via randomizing an input. Our major theoretical contribution is an almost tight ℓ0\ell_0-norm certified robustness guarantee for top-kk predictions. We empirically evaluate our method on CIFAR10 and ImageNet. For instance, our method can build a classifier that achieves a certified top-3 accuracy of 69.2% on ImageNet when an attacker can arbitrarily perturb 5 pixels of a testing image.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext 36e1eaba-91c2-4e3c-b657-bf0b670dfa03

引用它的顶会 Paper9

问问它们各自怎么用它

它引用的顶会 Paper13

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖