Enhancing Certified Robustness of Smoothed Classifiers via Weighted Model Ensembling

05/19/2020
by   Chizhou Liu, et al.
0

Randomized smoothing has achieved state-of-the-art certified robustness against l_2-norm adversarial attacks. However, it also leads to accuracy drop compared to the normally trained models. In this work, we employ a Smoothed WEighted ENsembling (SWEEN) scheme to improve the performance of randomized smoothed classifiers. We characterize the optimal certified robustness attainable by SWEEN models. We show the accessibility of SWEEN models attaining the lowest risk w.r.t. a surrogate loss function. We also develop an adaptive prediction algorithm to reduce the prediction and certification cost of SWEEN models. Extensive experiments show that SWEEN models outperform the upper envelope of their corresponding base models by a large margin. Moreover, SWEEN models constructed using a few small models are able to achieve comparable performance to a single large model with notably reduced training time.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/09/2019

Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers

Recent works have shown the effectiveness of randomized smoothing as a s...
research
11/17/2019

Smoothed Inference for Adversarially-Trained Models

Deep neural networks are known to be vulnerable to inputs with malicious...
research
02/09/2021

Adversarially Robust Classifier with Covariate Shift Adaptation

Existing adversarially trained models typically perform inference on tes...
research
02/22/2021

On the robustness of randomized classifiers to adversarial examples

This paper investigates the theory of robustness against adversarial att...
research
03/02/2020

Rethinking Randomized Smoothing for Adversarial Robustness

The fragility of modern machine learning models has drawn a considerable...
research
06/02/2022

Robustness Evaluation and Adversarial Training of an Instance Segmentation Model

To evaluate the robustness of non-classifier models, we propose probabil...
research
06/09/2022

GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized Smoothing

Certified defenses such as randomized smoothing have shown promise towar...

Please sign up or login with your details

Forgot password? Click here to reset