Extensions and limitations of randomized smoothing for robustness guarantees

06/07/2020
by   Jamie Hayes, et al.
0

Randomized smoothing, a method to certify a classifier's decision on an input is invariant under adversarial noise, offers attractive advantages over other certification methods. It operates in a black-box and so certification is not constrained by the size of the classifier's architecture. Here, we extend the work of Li et al. <cit.>, studying how the choice of divergence between smoothing measures affects the final robustness guarantee, and how the choice of smoothing measure itself can lead to guarantees in differing threat models. To this end, we develop a method to certify robustness against any ℓ_p (p∈N_>0) minimized adversarial perturbation. We then demonstrate a negative result, that randomized smoothing suffers from the curse of dimensionality; as p increases, the effective radius around an input one can certify vanishes.

READ FULL TEXT
research
04/28/2022

Randomized Smoothing under Attack: How Good is it in Pratice?

Randomized smoothing is a recent and celebrated solution to certify the ...
research
06/03/2022

Towards Evading the Limits of Randomized Smoothing: A Theoretical Analysis

Randomized smoothing is the dominant standard for provable defenses agai...
research
03/02/2020

Rethinking Randomized Smoothing for Adversarial Robustness

The fragility of modern machine learning models has drawn a considerable...
research
11/25/2022

Invariance-Aware Randomized Smoothing Certificates

Building models that comply with the invariances inherent to different d...
research
09/17/2020

Certifying Confidence via Randomized Smoothing

Randomized smoothing has been shown to provide good certified-robustness...
research
05/08/2023

Understanding Noise-Augmented Training for Randomized Smoothing

Randomized smoothing is a technique for providing provable robustness gu...
research
06/28/2021

Certified Robustness via Randomized Smoothing over Multiplicative Parameters

We propose a novel approach of randomized smoothing over multiplicative ...

Please sign up or login with your details

Forgot password? Click here to reset