Average Certified Radius is a Poor Metric for Randomized Smoothing
Chenhao Sun, Yuhao Mao, Mark Niklas Müller, Martin T. Vechev
摘要
Randomized smoothing is a popular approach for providing certified robustness guarantees against adversarial attacks, and has become a very active area of research. Over the past years, the average certified radius (ACR) has emerged as the single most important metric for comparing methods and tracking progress in the field. However, in this work, we show that ACR is an exceptionally poor metric for evaluating robustness guarantees provided by randomized smoothing. We theoretically show not only that a trivial classifier can have arbitrarily large ACR, but also that ACR is much more sensitive to improvements on easy samples than on hard ones. Empirically, we confirm that existing training strategies that improve ACR reduce the model's robustness on hard samples. Further, we show that by focusing on easy samples, we can effectively replicate the increase in ACR. We develop strategies, including explicitly discarding hard samples, reweighing the dataset with certified radius, and extreme optimization for easy samples, to achieve state-of-the-art ACR, although these strategies ignore robustness for the general data distribution. Overall, our results suggest that ACR has introduced a strong undesired bias to the field, and better metrics are required to holistically evaluate randomized smoothing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Expressiveness of Multi-Neuron Convex Relaxations in Neural Network CertificationYuhao Mao, Yani Zhang, Martin T. VechevICLR 2026 · 被引用 4 次
- Dual Randomized Smoothing: Beyond Global Noise VarianceChenhao Sun, Yuhao Mao, Martin VechevICLR 2026 · 被引用 1 次
它引用的顶会 Paper14
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified RadiusRuntian Zhai, Chen Dan, Di He, Huan Zhang 等ICLR 2020 · 被引用 195 次
- Denoised Smoothing: A Provable Defense for Pretrained ClassifiersHadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor 等NeurIPS 2020 · 被引用 191 次
- Consistency Regularization for Certified Robustness of Smoothed ClassifiersJongheon Jeong, Jinwoo ShinNeurIPS 2020 · 被引用 103 次
- Fast Certified Robust Training with Short WarmupZhouxing Shi, Yihan Wang, Huan Zhang, Jinfeng Yi 等NeurIPS 2021 · 被引用 74 次
相关 Paper
- Boosting Randomized Smoothing with Variance Reduced ClassifiersMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2022 · 被引用 56 次
- Confidence-Aware Training of Smoothed Classifiers for Certified RobustnessJongheon Jeong, Seojin Kim, Jinwoo ShinAAAI 2023 · 被引用 14 次
- Higher-Order Certification For Randomized SmoothingJeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen 等NeurIPS 2020 · 被引用 51 次
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 被引用 7 次
- The Lipschitz-Variance-Margin Tradeoff for Enhanced Randomized SmoothingBlaise Delattre, Alexandre Araujo, Quentin Barthélemy, Alexandre AllauzenICLR 2024 · 被引用 7 次
