Consistency Regularization for Certified Robustness of Smoothed Classifiers

06/07/2020
by   Jongheon Jeong, et al.
7

A recent technique of randomized smoothing has shown that the worst-case (adversarial) ℓ_2-robustness can be transformed into the average-case Gaussian-robustness by "smoothing" a classifier, i.e., by considering the averaged prediction over Gaussian noise. In this paradigm, one should rethink the notion of adversarial robustness in terms of generalization ability of a classifier under noisy observations. We found that the trade-off between accuracy and certified robustness of smoothed classifiers can be greatly controlled by simply regularizing the prediction consistency over noise. This relationship allows us to design a robust training objective without approximating a non-existing smoothed classifier, e.g., via soft smoothing. Our experiments under various deep neural network architectures and datasets demonstrate that the "certified" ℓ_2-robustness can be dramatically improved with the proposed regularization, even achieving better or comparable results to the state-of-the-art approaches with significantly less training costs and hyperparameters.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/18/2022

Confidence-aware Training of Smoothed Classifiers for Certified Robustness

Any classifier can be "smoothed out" under Gaussian noise to build a new...
research
11/17/2021

SmoothMix: Training Confidence-calibrated Smoothed Classifiers for Certified Robustness

Randomized smoothing is currently a state-of-the-art method to construct...
research
01/29/2023

Improving the Accuracy-Robustness Trade-off of Classifiers via Adaptive Smoothing

While it is shown in the literature that simultaneously accurate and rob...
research
04/02/2021

Misclassification-Aware Gaussian Smoothing improves Robustness against Domain Shifts

Deep neural networks achieve high prediction accuracy when the train and...
research
10/30/2019

Network Classifiers With Output Smoothing

This work introduces two strategies for training network classifiers wit...
research
02/17/2020

Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable Robustness

Recently smoothing deep neural network based classifiers via isotropic G...
research
08/31/2016

Robustness of classifiers: from adversarial to random noise

Several recent works have shown that state-of-the-art classifiers are vu...

Please sign up or login with your details

Forgot password? Click here to reset