Certified Defense to Image Transformations via Randomized Smoothing
Marc Fischer, Maximilian Baader, Martin T. Vechev
摘要
We extend randomized smoothing to cover parameterized transformations (e.g., rotations, translations) and certify robustness in the parameter space (e.g., rotation angle). This is particularly challenging as interpolation and rounding effects mean that image transformations do not compose, in turn preventing direct certification of the perturbed image (unlike certification with p norms). We address this challenge by introducing three different kinds of defenses, each with a different guarantee (heuristic, distributional and individual) stemming from the method used to bound the interpolation error. Importantly, we show how individual certificates can be obtained via either statistical error bounds or efficient online inverse computation of the image transformation. We provide an implementation of all methods at https://github.com/eth-sri/transformation-smoothing . Introduction Deep neural networks are vulnerable to adversarial examples [1] -small changes that preserve semantics (e.g., p -noise or geometric transformations such as rotations) [2], but can affect the output of a network in undesirable ways. As a result, there has been substantial recent interest in methods which aim to ensure the network is certifiably robust to adversarial examples [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] . Certification guarantees There are two principal robustness guarantees a certified defense can provide at inference time: (i) the (standard) distributional guarantee, where a robustness score is computed offline on the test set to be interpreted in expectation for images drawn from the data distribution, and (ii) an individual guarantee, where a certificate is computed online for the (possibly perturbed) input. The choice of guarantee depends on the application and regulatory constraints. Guarantees with p norms When considering p norms, existing certification methods can be directly used to obtain either of the above two guarantees: for an image x and adversarial noise δ, δ p < r, proving that a classifier f is r-robust around x := x + δ is enough to guarantee f (x) = f (x ). That is, it suffices to prove robustness of a perturbed input in order to certify that the perturbation did not change the classification, as the r-ball around x includes x. Key challenge: guarantees for geometric perturbations Perhaps not intuitively, however, for more complex perturbations such as geometric transformations, proving robustness around an image x via existing methods (e.g., [9] [10] [11] [12] ) does not imply that f (x) = f (x ) for the original image x. To illustrate this issue, consider the rotation R γ , by angle γ of an image x, followed by an interpolation I. Certifying that the classification of the rotated image x := I • R γ (x) for γ < r is robust under further rotations I • R β for β < r is not sufficient to imply that x and x classify the same, as rotating x back by β = -γ does not return the original image x due to interpolation. A central challenge then is to develop techniques that are able to handle more involved perturbations. 34th Conference on Neural Information Processing Systems (NeurIPS 2020),
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper33
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che 等NeurIPS 2022 · 被引用 56 次
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 被引用 56 次
- Scalable Certified Segmentation via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevICML 2021 · 被引用 49 次
- Improved, Deterministic Smoothing for L1 Certified RobustnessAlexander Levine, Soheil FeiziICML 2021 · 被引用 49 次
- Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial AttacksXinyu Zhang, Hanbin Hong, Yuan Hong, Peng Huang 等S&P 2024 · 被引用 41 次
它引用的顶会 Paper3
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov 等S&P 2018 · 被引用 987 次
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified RadiusRuntian Zhai, Chen Dan, Di He, Huan Zhang 等ICLR 2020 · 被引用 195 次
相关 Paper
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su 等ICML 2022 · 被引用 27 次
- (Provable) Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and MoreJan Schuchardt, Yan Scholten, Stephan GünnemannNeurIPS 2023 · 被引用 5 次
- DeformRS: Certifying Input Deformations with Randomized SmoothingMotasem Alfarra, Adel Bibi, Naeemullah Khan, Philip H. S. Torr 等AAAI 2022 · 被引用 23 次
- Improving l1-Certified Robustness via Randomized Smoothing by Leveraging Box ConstraintsVáclav Vorácek, Matthias HeinICML 2023 · 被引用 11 次
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen 等NeurIPS 2020 · 被引用 51 次
