paper-with-me

Papers

Robustness Certificates for Sparse Adversarial Attacks by Randomized Ablation

2019-11-21 · Alexander Levine, Soheil Feizi

Recently, techniques have been developed to provably guarantee the robustness of a classifier to adversarial perturbations of bounded L_1 and L_2 magnitudes by using randomized smoothing: the robust classification is a consensus of base classifications on randomly noised samples where the noise is additive. In this paper, we extend this technique to the L_0 threat model. We propose an efficient and certifiably robust defense against sparse adversarial attacks by randomly ablating input features, rather than using additive noise. Experimentally, on MNIST, we can certify the classifications of over 50% of images to be robust to any distortion of at most 8 pixels. This is comparable to the observed empirical robustness of unprotected classifiers on MNIST to modern L_0 attacks, demonstrating the tightness of the proposed robustness certificate. We also evaluate our certificate on ImageNet and CIFAR-10. Our certificates represent an improvement on those provided in a concurrent work (Lee et al. 2019) which uses random noise rather than ablation (median certificates of 8 pixels versus 4 pixels on MNIST; 16 pixels versus 1 pixel on ImageNet.) Additionally, we empirically demonstrate that our classifier is highly robust to modern sparse adversarial attacks on MNIST. Our classifications are robust, in median, to adversarial perturbations of up to 31 pixels, compared to 22 pixels reported as the state-of-the-art defense, at the cost of a slight decrease (around 2.3%) in the classification accuracy. Code is available at https://github.com/alevine0/randomizedAblation/.

📄 PDF Abstract BibTeX arXiv:1911.09272

Code (1)

alevine0/randomizedAblation 공식 구현 pytorch

Tasks

Robust classification

Similar Papers 제목 키워드 기반

(De)Randomized Smoothing for Certifiable Defense against Patch Attacks

2020-02-25 · NeurIPS 2020 12 · Alexander Levine, Soheil Feizi

Patch adversarial attacks on images, in which the attacker can distort pixels within a region of bounded size, are an important threat model since they provide a quantitative model for physical adversarial attacks. In th…

Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural Networks

2023-01-05 · Yan Scholten, Jan Schuchardt, Simon Geisler, Aleksandar Bojchevski 외

Randomized smoothing is one of the most promising frameworks for certifying the adversarial robustness of machine learning models, including Graph Neural Networks (GNNs). Yet, existing randomized smoothing certificates f…

Adversarial Robustness

Provable Robustness Against a Union of $\ell_0$ Adversarial Attacks

2023-02-22 · Zayd Hammoudeh, Daniel Lowd

Sparse or $\ell_0$ adversarial attacks arbitrarily perturb an unknown subset of the features. $\ell_0$ robustness analysis is particularly well-suited for heterogeneous (tabular) data where features have different types …

Tight Second-Order Certificates for Randomized Smoothing

2020-10-20 · Alexander Levine, Aounon Kumar, Thomas Goldstein, Soheil Feizi

Randomized smoothing is a popular way of providing robustness guarantees against adversarial attacks: randomly-smoothed functions have a universal Lipschitz-like bound, allowing for robustness certificates to be easily c…

Fast and Flexible Robustness Certificates for Semantic Segmentation

2025-12-03 · Thomas Massena, Corentin Friedrich, Franck Mamalet, Mathieu Serrurier arxiv

Deep Neural Networks are vulnerable to small perturbations that can drastically alter their predictions for perceptually unchanged inputs. The literature on adversarially robust Deep Learning attempts to either enhance t…

Computational EfficiencySemantic Segmentation