Deterministic Certification to Adversarial Attacks via Bernstein Polynomial Approximation

11/28/2020
by   Ching-Chia Kao, et al.
0

Randomized smoothing has established state-of-the-art provable robustness against ℓ_2 norm adversarial attacks with high probability. However, the introduced Gaussian data augmentation causes a severe decrease in natural accuracy. We come up with a question, "Is it possible to construct a smoothed classifier without randomization while maintaining natural accuracy?". We find the answer is definitely yes. We study how to transform any classifier into a certified robust classifier based on a popular and elegant mathematical tool, Bernstein polynomial. Our method provides a deterministic algorithm for decision boundary smoothing. We also introduce a distinctive approach of norm-independent certified robustness via numerical solutions of nonlinear systems of equations. Theoretical analyses and experimental results indicate that our method is promising for classifier smoothing and robustness certification.

READ FULL TEXT
research
03/17/2021

Improved, Deterministic Smoothing for L1 Certified Robustness

Randomized smoothing is a general technique for computing sample-depende...
research
02/14/2023

Randomization for adversarial robustness: the Good, the Bad and the Ugly

Deep neural networks are known to be vulnerable to adversarial attacks: ...
research
02/26/2020

Randomization matters. How to defend against strong adversarial attacks

Is there a classifier that ensures optimal robustness against all advers...
research
02/27/2020

Certification of Semantic Perturbations via Randomized Smoothing

We introduce a novel certification method for parametrized perturbations...
research
06/03/2022

Towards Evading the Limits of Randomized Smoothing: A Theoretical Analysis

Randomized smoothing is the dominant standard for provable defenses agai...
research
05/08/2023

Understanding Noise-Augmented Training for Randomized Smoothing

Randomized smoothing is a technique for providing provable robustness gu...
research
05/27/2022

(De-)Randomized Smoothing for Decision Stump Ensembles

Tree-based models are used in many high-stakes application domains such ...

Please sign up or login with your details

Forgot password? Click here to reset