paper-with-me

홈 › Papers

Certified Distributional Robustness on Smoothed Classifiers

2020-10-21 · Jungang Yang, Liyao Xiang, Ruidong Chen, Yukun Wang, Wei Wang, Xinbing Wang

The robustness of deep neural networks (DNNs) against adversarial example attacks has raised wide attention. For smoothed classifiers, we propose the worst-case adversarial loss over input distributions as a robustness certificate. Compared with previous certificates, our certificate better describes the empirical performance of the smoothed classifiers. By exploiting duality and the smoothness property, we provide an easy-to-compute upper bound as a surrogate for the certificate. We adopt a noisy adversarial learning procedure to minimize the surrogate loss to improve model robustness. We show that our training method provides a theoretically tighter bound over the distributional robust base classifiers. Experiments on a variety of datasets further demonstrate superior robustness performance of our method over the state-of-the-art certified or heuristic methods.

📄 PDF Abstract BibTeX arXiv:2010.10987

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Certified Distributional Robustness via Smoothed Classifiers

2021-01-01 · Jungang Yang, Liyao Xiang, Ruidong Chen, Yukun Wang 외

The robustness of deep neural networks against adversarial example attacks has received much attention recently. We focus on certified robustness of smoothed classifiers in this work, and propose to use the worst-case po…

Principal Eigenvalue Regularization for Improved Worst-Class Certified Robustness of Smoothed Classifiers

2025-03-21 · Gaojie Jin, Tianjin Huang, Ronghui Mu, Xiaowei Huang

Recent studies have identified a critical challenge in deep neural networks (DNNs) known as ``robust fairness", where models exhibit significant disparities in robust accuracy across different classes. While prior work h…

Adversarial RobustnessFairness

SmoothMix: Training Confidence-calibrated Smoothed Classifiers for Certified Adversarial Robustness

2021-06-18 · ICML Workshop AML 2021 7 · Jongheon Jeong, Sejun Park, Minkyu Kim, Heung-Chang Lee 외

Randomized smoothing is currently a state-of-the-art method to construct a certifiably robust classifier from neural networks against $\ell_2$-adversarial perturbations. Under the paradigm, the robustness of a classifier…

Adversarial Robustness

SmoothMix: Training Confidence-calibrated Smoothed Classifiers for Certified Robustness

2021-11-17 · NeurIPS 2021 12 · Jongheon Jeong, Sejun Park, Minkyu Kim, Heung-Chang Lee 외

Randomized smoothing is currently a state-of-the-art method to construct a certifiably robust classifier from neural networks against $\ell_2$-adversarial perturbations. Under the paradigm, the robustness of a classifier…

Consistency Regularization for Certified Robustness of Smoothed Classifiers

2020-06-07 · NeurIPS 2020 12 · Jongheon Jeong, Jinwoo Shin

A recent technique of randomized smoothing has shown that the worst-case (adversarial) $\ell_2$-robustness can be transformed into the average-case Gaussian-robustness by "smoothing" a classifier, i.e., by considering th…

Adversarial Robustness