SmoothMix: Training Confidence-calibrated Smoothed Classifiers for Certified Robustness
Jongheon Jeong, Sejun Park, Minkyu Kim, Heung-Chang Lee, Do-Guk Kim, Jinwoo Shin
摘要
Randomized smoothing is currently a state-of-the-art method to construct a certifiably robust classifier from neural networks against 2 -adversarial perturbations. Under the paradigm, the robustness of a classifier is aligned with the prediction confidence, i.e., the higher confidence from a smoothed classifier implies the better robustness. This motivates us to rethink the fundamental trade-off between accuracy and robustness in terms of calibrating confidences of a smoothed classifier. In this paper, we propose a simple training scheme, coined SmoothMix, to control the robustness of smoothed classifiers via self-mixup: it trains on convex combinations of samples along the direction of adversarial perturbation for each input. The proposed procedure effectively identifies over-confident, near off-class samples as a cause of limited robustness in case of smoothed classifiers, and offers an intuitive way to adaptively set a new decision boundary between these samples for better robustness. Our experimental results demonstrate that the proposed method can significantly improve the certified 2 -robustness of smoothed classifiers compared to existing state-of-the-art robust training methods. 3 * Work done at KAIST. † Work done at Kakao Enterprise. 3 Code is available at https://github.com/jh-jeong/smoothmix .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Diffusion Models are Certifiably Robust ClassifiersHuanran Chen, Yinpeng Dong, Shitong Shao, Zhongkai Hao 等NeurIPS 2024 · 被引用 42 次
- Adversarial AutoMixupHuafeng Qin, Xin Jin, Yun Jiang, Mounîm A. El-Yacoubi 等ICLR 2024 · 被引用 19 次
- Unlocking Deterministic Robustness Certification on ImageNetKai Hu, Andy Zou, Zifan Wang, Klas Leino 等NeurIPS 2023 · 被引用 18 次
- DensePure: Understanding Diffusion Models for Adversarial RobustnessChaowei Xiao, Zhongzhu Chen, Kun Jin, Jiongxiao Wang 等ICLR 2023 · 被引用 18 次
- (Certified!!) Adversarial Robustness for Free!Nicholas Carlini, Florian Tramèr, Krishnamurthy (Dj) Dvijotham, Leslie Rice 等ICLR 2023 · 被引用 17 次
它引用的顶会 Paper23
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh 等ICCV 2019 · 被引用 5,843 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov 等S&P 2018 · 被引用 987 次
相关 Paper
- Confidence-Aware Training of Smoothed Classifiers for Certified RobustnessJongheon Jeong, Seojin Kim, Jinwoo ShinAAAI 2023 · 被引用 14 次
- Consistency Regularization for Certified Robustness of Smoothed ClassifiersJongheon Jeong, Jinwoo ShinNeurIPS 2020 · 被引用 103 次
- Adversarial Unlearning: Reducing Confidence Along Adversarial DirectionsAmrith Setlur, Benjamin Eysenbach, Virginia Smith, Sergey LevineNeurIPS 2022 · 被引用 26 次
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 被引用 7 次
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen 等NeurIPS 2020 · 被引用 51 次
