Intriguing Properties of Input-dependent Randomized Smoothing

10/11/2021
by   Peter Súkeník, et al.
0

Randomized smoothing is currently considered the state-of-the-art method to obtain certifiably robust classifiers. Despite its remarkable performance, the method is associated with various serious problems such as “certified accuracy waterfalls”, certification vs. accuracy trade-off, or even fairness issues. Input-dependent smoothing approaches have been proposed to overcome these flaws. However, we demonstrate that these methods lack formal guarantees and so the resulting certificates are not justified. We show that the input-dependent smoothing, in general, suffers from the curse of dimensionality, forcing the variance function to have low semi-elasticity. On the other hand, we provide a theoretical and practical framework that enables the usage of input-dependent smoothing even in the presence of the curse of dimensionality, under strict restrictions. We present one concrete design of the smoothing variance and test it on CIFAR10 and MNIST. Our design solves some of the problems of classical smoothing and is formally underlined, yet further improvement of the design is still necessary.

READ FULL TEXT

page 4

page 15

research
12/08/2020

Data Dependent Randomized Smoothing

Randomized smoothing is a recent technique that achieves state-of-art pe...
research
02/19/2021

Center Smoothing for Certifiably Robust Vector-Valued Functions

Randomized smoothing has been successfully applied in high-dimensional i...
research
06/21/2022

Riemannian data-dependent randomized smoothing for neural networks certification

Certification of neural networks is an important and challenging problem...
research
04/28/2022

Randomized Smoothing under Attack: How Good is it in Pratice?

Randomized smoothing is a recent and celebrated solution to certify the ...
research
07/01/2021

Scalable Certified Segmentation via Randomized Smoothing

We present a new certification method for image and point cloud segmenta...
research
07/02/2021

DeformRS: Certifying Input Deformations with Randomized Smoothing

Deep neural networks are vulnerable to input deformations in the form of...
research
07/09/2021

ANCER: Anisotropic Certification via Sample-wise Volume Maximization

Randomized smoothing has recently emerged as an effective tool that enab...

Please sign up or login with your details

Forgot password? Click here to reset