paper-with-me

홈 › Papers

Enhanced Estimation Techniques for Certified Radii in Randomized Smoothing

2025-03-11 · Zixuan Liang

This paper presents novel methods for estimating certified radii in randomized smoothing, a technique crucial for certifying the robustness of neural networks against adversarial perturbations. Our proposed techniques significantly improve the accuracy of certified test-set accuracy by providing tighter bounds on the certified radii. We introduce advanced algorithms for both discrete and continuous domains, demonstrating their effectiveness on CIFAR-10 and ImageNet datasets. The new methods show considerable improvements over existing approaches, particularly in reducing discrepancies in certified radii estimates. We also explore the impact of various hyperparameters, including sample size, standard deviation, and temperature, on the performance of these methods. Our findings highlight the potential for more efficient certification processes and pave the way for future research on tighter confidence sequences and improved theoretical frameworks. The study concludes with a discussion of potential future directions, including enhanced estimation techniques for discrete domains and further theoretical advancements to bridge the gap between empirical and theoretical performance in randomized smoothing.

📄 PDF Abstract BibTeX arXiv:2503.08801

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Higher-Order Certification for Randomized Smoothing

2020-10-13 · NeurIPS 2020 12 · Jeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen 외

Randomized smoothing is a recently proposed defense against adversarial attacks that has achieved SOTA provable robustness against $\ell_2$ perturbations. A number of publications have extended the guarantees to other me…

Towards Large Certified Radius in Randomized Smoothing using Quasiconcave Optimization

2023-02-01 · Bo-Han Kung, Shang-Tse Chen

Randomized smoothing is currently the state-of-the-art method that provides certified robustness for deep neural networks. However, due to its excessively conservative nature, this method of incomplete verification often…

Randomized Smoothing of All Shapes and Sizes

2020-02-19 · ICML 2020 1 · Greg Yang, Tony Duan, J. Edward Hu, Hadi Salman 외

Randomized smoothing is the current state-of-the-art defense with provable robustness against $\ell_2$ adversarial attacks. Many works have devised new randomized smoothing schemes for other metrics, such as $\ell_1$ or …

All

Certifying Confidence via Randomized Smoothing

2020-09-17 · NeurIPS 2020 12 · Aounon Kumar, Alexander Levine, Soheil Feizi, Tom Goldstein

Randomized smoothing has been shown to provide good certified-robustness guarantees for high-dimensional classification problems. It uses the probabilities of predicting the top two most-likely classes around an input po…

LEMMAPrediction

Dual Randomized Smoothing: Beyond Global Noise Variance

2025-12-01 · Chenhao Sun, Yuhao Mao, Martin Vechev arxiv

Randomized Smoothing (RS) is a prominent technique for certifying the robustness of neural networks against adversarial perturbations. With RS, achieving high accuracy at small radii requires a small noise variance, whil…