paper-with-me

홈 › Papers

Tight Certificates of Adversarial Robustness for Randomly Smoothed Classifiers

2019-06-12 · NeurIPS 2019 12 · Guang-He Lee, Yang Yuan, Shiyu Chang, Tommi S. Jaakkola

Strong theoretical guarantees of robustness can be given for ensembles of classifiers generated by input randomization. Specifically, an $\ell_2$ bounded adversary cannot alter the ensemble prediction generated by an additive isotropic Gaussian noise, where the radius for the adversary depends on both the variance of the distribution as well as the ensemble margin at the point of interest. We build on and considerably expand this work across broad classes of distributions. In particular, we offer adversarial robustness guarantees and associated algorithms for the discrete case where the adversary is $\ell_0$ bounded. Moreover, we exemplify how the guarantees can be tightened with specific assumptions about the function class of the classifier such as a decision tree. We empirically illustrate these results with and without functional restrictions across image and molecule datasets.

📄 PDF Abstract BibTeX arXiv:1906.04948

Code (1)

guanghelee/Randomized_Smoothing pytorch

Tasks

Adversarial Robustness

Similar Papers 제목 키워드 기반

Tight Second-Order Certificates for Randomized Smoothing

2020-10-20 · Alexander Levine, Aounon Kumar, Thomas Goldstein, Soheil Feizi

Randomized smoothing is a popular way of providing robustness guarantees against adversarial attacks: randomly-smoothed functions have a universal Lipschitz-like bound, allowing for robustness certificates to be easily c…

$\ell_1$ Adversarial Robustness Certificates: a Randomized Smoothing Approach

2019-09-25 · Jiaye Teng, Guang-He Lee, Yang Yuan

Robustness is an important property to guarantee the security of machine learning models. It has recently been demonstrated that strong robustness certificates can be obtained on ensemble classifiers generated by input r…

Adversarial Robustness

Certified Distributional Robustness on Smoothed Classifiers

2020-10-21 · Jungang Yang, Liyao Xiang, Ruidong Chen, Yukun Wang 외

The robustness of deep neural networks (DNNs) against adversarial example attacks has raised wide attention. For smoothed classifiers, we propose the worst-case adversarial loss over input distributions as a robustness c…

Higher-Order Certified Robustness for Regression

2026-07-06 · Jie Zhang, Natalie Frank arxiv

Randomized smoothing has emerged as a scalable technique for certifying the adversarial robustness of classifiers. However, its application to regression remains under-explored and faces unique challenges. Existing regre…

Adversarial Robustness

Robustness Certificates for Sparse Adversarial Attacks by Randomized Ablation

2019-11-21 · Alexander Levine, Soheil Feizi

Recently, techniques have been developed to provably guarantee the robustness of a classifier to adversarial perturbations of bounded L_1 and L_2 magnitudes by using randomized smoothing: the robust classification is a c…

Robust classification