Lune

NeurIPS2020顶会

Denoised Smoothing: A Provable Defense for Pretrained Classifiers

Hadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor, J. Zico Kolter

出版方
2020年份
191被引次数
55顶会引用

摘要

We present a method for provably defending any pretrained image classifier against p adversarial attacks. This method, for instance, allows public vision API providers and users to seamlessly convert pretrained non-robust classification services into provably robust ones. By prepending a custom-trained denoiser to any off-theshelf image classifier and using randomized smoothing, we effectively create a new classifier that is guaranteed to be p -robust to adversarial examples, without modifying the pretrained classifier. Our approach applies to both the white-box and the black-box settings of the pretrained classifier. We refer to this defense as denoised smoothing, and we demonstrate its effectiveness through extensive experimentation on ImageNet and CIFAR-10. Finally, we use our approach to provably defend the Azure, Google, AWS, and ClarifAI image classification APIs. Our code replicating all the experiments in the paper can be found at: https: //github.com/microsoft/denoised-smoothing 1 .

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext b2f7d136-a0cb-4842-a64a-e4551fa4b8b7

引用它的顶会 Paper55

问问它们各自怎么用它

它引用的顶会 Paper8

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖