ANCER: Anisotropic Certification via Sample-wise Volume Maximization

07/09/2021
by   Francisco Eiras, et al.
3

Randomized smoothing has recently emerged as an effective tool that enables certification of deep neural network classifiers at scale. All prior art on randomized smoothing has focused on isotropic ℓ_p certification, which has the advantage of yielding certificates that can be easily compared among isotropic methods via ℓ_p-norm radius. However, isotropic certification limits the region that can be certified around an input to worst-case adversaries, it cannot reason about other "close", potentially large, constant prediction safe regions. To alleviate this issue, (i) we theoretically extend the isotropic randomized smoothing ℓ_1 and ℓ_2 certificates to their generalized anisotropic counterparts following a simplified analysis. Moreover, (ii) we propose evaluation metrics allowing for the comparison of general certificates - a certificate is superior to another if it certifies a superset region - with the quantification of each certificate through the volume of the certified region. We introduce ANCER, a practical framework for obtaining anisotropic certificates for a given test set sample via volume maximization. Our empirical results demonstrate that ANCER achieves state-of-the-art ℓ_1 and ℓ_2 certified accuracy on both CIFAR-10 and ImageNet at multiple radii, while certifying substantially larger regions in terms of volume, thus highlighting the benefits of moving away from isotropic analysis. Code used in our experiments is available in https://github.com/MotasemAlfarra/ANCER.

READ FULL TEXT

page 2

page 3

page 10

page 17

research
06/16/2022

Double Sampling Randomized Smoothing

Neural networks (NNs) are known to be vulnerable against adversarial per...
research
12/08/2020

Data Dependent Randomized Smoothing

Randomized smoothing is a recent technique that achieves state-of-art pe...
research
12/21/2021

Input-Specific Robustness Certification for Randomized Smoothing

Although randomized smoothing has demonstrated high certified robustness...
research
02/01/2023

QCRS: Improve Randomized Smoothing using Quasi-Concave Optimization

Randomized smoothing is currently the state-of-the-art method that provi...
research
10/13/2020

Higher-Order Certification for Randomized Smoothing

Randomized smoothing is a recently proposed defense against adversarial ...
research
10/11/2021

Intriguing Properties of Input-dependent Randomized Smoothing

Randomized smoothing is currently considered the state-of-the-art method...
research
07/16/2022

Certified Neural Network Watermarks with Randomized Smoothing

Watermarking is a commonly used strategy to protect creators' rights to ...

Please sign up or login with your details

Forgot password? Click here to reset