Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness
Aounon Kumar, Alexander Levine, Tom Goldstein, Soheil Feizi
摘要
Randomized smoothing, using just a simple isotropic Gaussian distribution, has been shown to produce good robustness guarantees against -norm bounded adversaries. In this work, we show that extending the smoothing technique to defend against other attack models can be challenging, especially in the high-dimensional regime. In particular, for a vast class of i.i.d. smoothing distributions, we prove that the largest -radius that can be certified decreases as with dimension for . Notably, for , this dependence on is no better than that of the -radius that can be certified using isotropic Gaussian smoothing, essentially putting a matching lower bound on the robustness radius. When restricted to generalized Gaussian smoothing, these two bounds can be shown to be within a constant factor of each other in an asymptotic sense, establishing that Gaussian smoothing provides the best possible results, up to a constant factor, when . We present experimental results on CIFAR to validate our theory. For other smoothing distributions, such as, a uniform distribution within an or an -norm ball, we show upper bounds of the form and respectively, which have an even worse dependence on .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper46
- Randomized Smoothing of All Shapes and SizesGreg Yang, Tony Duan, J. Edward Hu, Hadi Salman 等ICML 2020 · 被引用 237 次
- Rethinking Lipschitz Neural Networks and Certified Robustness: A Boolean Function PerspectiveBohang Zhang, Du Jiang, Di He, Liwei WangNeurIPS 2022 · 被引用 88 次
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 被引用 77 次
- Skew Orthogonal ConvolutionsSahil Singla, Soheil FeiziICML 2021 · 被引用 76 次
- Fast Certified Robust Training with Short WarmupZhouxing Shi, Yihan Wang, Huan Zhang, Jinfeng Yi 等NeurIPS 2021 · 被引用 74 次
它引用的顶会 Paper6
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu 等ICLR 2020 · 被引用 194 次
- (De)Randomized Smoothing for Certifiable Defense against Patch AttacksAlexander Levine, Soheil FeiziNeurIPS 2020 · 被引用 188 次
- Robustness Certificates for Sparse Adversarial Attacks by Randomized AblationAlexander Levine, Soheil FeiziAAAI 2020 · 被引用 114 次
- Black-Box Certification with Randomized Smoothing: A Functional Optimization Based FrameworkDinghuai Zhang, Mao Ye, Chengyue Gong, Zhanxing Zhu 等NeurIPS 2020 · 被引用 71 次
相关 Paper
- Effects of Exponential Gaussian Distribution on (Double Sampling) Randomized SmoothingYouwei Shu, Xi Xiao, Derui Wang, Yuxin Cao 等ICML 2024 · 被引用 2 次
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen 等NeurIPS 2020 · 被引用 51 次
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su 等ICML 2022 · 被引用 27 次
- Double Sampling Randomized SmoothingLinyi Li, Jiawei Zhang, Tao Xie, Bo LiICML 2022 · 被引用 29 次
- Mitigating the Curse of Dimensionality for Certified Robustness via Dual Randomized SmoothingSong Xia, Yi Yu, Xudong Jiang, Henghui DingICLR 2024 · 被引用 18 次
