Certified Defense via Latent Space Randomized Smoothing with Orthogonal Encoders

08/01/2021
by   Huimin Zeng, et al.
0

Randomized Smoothing (RS), being one of few provable defenses, has been showing great effectiveness and scalability in terms of defending against ℓ_2-norm adversarial perturbations. However, the cost of MC sampling needed in RS for evaluation is high and computationally expensive. To address this issue, we investigate the possibility of performing randomized smoothing and establishing the robust certification in the latent space of a network, so that the overall dimensionality of tensors involved in computation could be drastically reduced. To this end, we propose Latent Space Randomized Smoothing. Another important aspect is that we use orthogonal modules, whose Lipschitz property is known for free by design, to propagate the certified radius estimated in the latent space back to the input space, providing valid certifiable regions for the test samples in the input space. Experiments on CIFAR10 and ImageNet show that our method achieves competitive certified robustness but with a significant improvement of efficiency during the test phase.

READ FULL TEXT

page 2

page 7

research
06/16/2022

Double Sampling Randomized Smoothing

Neural networks (NNs) are known to be vulnerable against adversarial per...
research
02/19/2020

Randomized Smoothing of All Shapes and Sizes

Randomized smoothing is a recently proposed defense against adversarial ...
research
04/01/2022

Robust and Accurate – Compositional Architectures for Randomized Smoothing

Randomized Smoothing (RS) is considered the state-of-the-art approach to...
research
06/21/2022

Riemannian data-dependent randomized smoothing for neural networks certification

Certification of neural networks is an important and challenging problem...
research
06/13/2021

Boosting Randomized Smoothing with Variance Reduced Classifiers

Randomized Smoothing (RS) is a promising method for obtaining robustness...
research
12/21/2021

Input-Specific Robustness Certification for Randomized Smoothing

Although randomized smoothing has demonstrated high certified robustness...
research
10/13/2020

Higher-Order Certification for Randomized Smoothing

Randomized smoothing is a recently proposed defense against adversarial ...

Please sign up or login with your details

Forgot password? Click here to reset