Random Smoothing Might be Unable to Certify $\ell_\infty$ Robustness for High-Dimensional Images

02/14/2020
by   Hongyang Zhang, et al.
0

We show a hardness result for random smoothing to achieve certified adversarial robustness against attacks in the $\ell_p$ ball of radius $\epsilon$ when $p>2$. Although random smoothing has been well understood for the $\ell_2$ case using the Gaussian distribution, much remains unknown concerning the existence of a noise distribution that works for the case of $p>2$. This has been posed as an open problem by Cohen et al. (2019) and includes many significant paradigms such as the $\ell_\infty$ threat model. In this work, we show that for certain base classifiers, any noise distribution $\mathcal{D}$ over $\mathbb{R}^d$ that provides $\ell_p$ robustness with $p>2$ must satisfy $\mathbb{E}\eta_i^2=\Omega(d^{1-2/p}\epsilon^2(1-\delta)^2/\delta^2)$ for 99% of the features (pixels) of vector $\eta$ drawn from $\mathcal{D}$, where $\epsilon$ is the robust radius and $\delta$ measures the score gap between the highest score and the runner-up. Therefore, for high-dimensional images with pixel values bounded in $[0,255]$, the required noise will eventually dominate the useful information in the images, leading to trivial smoothed classifiers.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/10/2020

Random Smoothing Might be Unable to Certify ℓ_∞ Robustness for High-Dimensional Images

We show a hardness result for random smoothing to achieve certified adve...
research
02/08/2020

Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness

Randomized smoothing, using just a simple isotropic Gaussian distributio...
research
09/17/2020

Certifying Confidence via Randomized Smoothing

Randomized smoothing has been shown to provide good certified-robustness...
research
11/21/2019

Robustness Certificates for Sparse Adversarial Attacks by Randomized Ablation

Recently, techniques have been developed to provably guarantee the robus...
research
06/28/2021

Certified Robustness via Randomized Smoothing over Multiplicative Parameters

We propose a novel approach of randomized smoothing over multiplicative ...
research
02/22/2018

Robustness of classifiers to uniform ℓ_p and Gaussian noise

We study the robustness of classifiers to various kinds of random noise ...
research
05/08/2023

Understanding Noise-Augmented Training for Randomized Smoothing

Randomized smoothing is a technique for providing provable robustness gu...

Please sign up or login with your details

Forgot password? Click here to reset