Input-Specific Robustness Certification for Randomized Smoothing
Ruoxin Chen, Jie Li, Junchi Yan, Ping Li, Bin Sheng
摘要
Although randomized smoothing has demonstrated high certified robustness and superior scalability to other certified defenses, the high computational overhead of the robustness certification bottlenecks the practical applicability, as it depends heavily on the large sample approximation for estimating the confidence interval. In existing works, the sample size for the confidence interval is universally set and agnostic to the input for prediction. This Input-Agnostic Sampling (IAS) scheme may yield a poor Average Certified Radius (ACR)-runtime trade-off which calls for improvement. In this paper, we propose Input-Specific Sampling (ISS) acceleration to achieve the cost-effectiveness for robustness certification, in an adaptive way of reducing the sampling size based on the input characteristic. Furthermore, our method universally controls the certified radius decline from the ISS sample size reduction. The empirical results on CIFAR-10 and ImageNet show that ISS can speed up the certification by more than three times at a limited cost of 0.05 certified radius. Meanwhile, ISS surpasses IAS on the average certified radius across the extensive hyperparameter settings. Specifically, ISS achieves ACR=0.958 on ImageNet (σ = 1.0) in 250 minutes, compared to ACR=0.917 by IAS under the same condition. We release our code in https://github.com/roy-ch/Input-Specific-Certification .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che 等NeurIPS 2022 · 被引用 56 次
- Treatment of Statistical Estimation Problems in Randomized Smoothing for Adversarial RobustnessVáclav VorácekNeurIPS 2024 · 被引用 12 次
- On-the-fly Improving Performance of Deep Code Models via Input DenoisingZhao Tian, Junjie Chen, Xiangyu ZhangASE 2023 · 被引用 8 次
- Randomized Smoothing Meets Vision-Language ModelsEmmanouil Seferis, Changshun Wu, Stefanos Kollias, Saddek Bensalem 等EMNLP 2025 · 被引用 1 次
它引用的顶会 Paper8
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified RadiusRuntian Zhai, Chen Dan, Di He, Huan Zhang 等ICLR 2020 · 被引用 195 次
- AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine LearningJinyuan Jia, Neil Zhenqiang GongUSENIX Security 2018 · 被引用 194 次
- Robustness Certificates for Sparse Adversarial Attacks by Randomized AblationAlexander Levine, Soheil FeiziAAAI 2020 · 被引用 114 次
- Certified Robustness for Top-k Predictions against Adversarial Perturbations via Randomized SmoothingJinyuan Jia, Xiaoyu Cao, Binghui Wang, Neil Zhenqiang GongICLR 2020 · 被引用 107 次
- Consistency Regularization for Certified Robustness of Smoothed ClassifiersJongheon Jeong, Jinwoo ShinNeurIPS 2020 · 被引用 103 次
相关 Paper
- ACS-Boot: Efficient Randomized Smoothing for Robustness Certification on Resource-Constrained Edge DevicesMiao Lin, Junrui Zhang, Jian Li, Feng Yu 等INFOCOM 2026
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 被引用 56 次
- Dual Randomized Smoothing: Beyond Global Noise VarianceChenhao Sun, Yuhao Mao, Martin VechevICLR 2026 · 被引用 1 次
- Double Sampling Randomized SmoothingLinyi Li, Jiawei Zhang, Tao Xie, Bo LiICML 2022 · 被引用 29 次
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen 等NeurIPS 2020 · 被引用 51 次
