Incremental Randomized Smoothing Certification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ugare, Shubham, Suresh, Tarun, Banerjee, Debangshu, Singh, Gagandeep, Misailovic, Sasa
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929309902438400
author Ugare, Shubham
Suresh, Tarun
Banerjee, Debangshu
Singh, Gagandeep
Misailovic, Sasa
author_facet Ugare, Shubham
Suresh, Tarun
Banerjee, Debangshu
Singh, Gagandeep
Misailovic, Sasa
contents Randomized smoothing-based certification is an effective approach for obtaining robustness certificates of deep neural networks (DNNs) against adversarial attacks. This method constructs a smoothed DNN model and certifies its robustness through statistical sampling, but it is computationally expensive, especially when certifying with a large number of samples. Furthermore, when the smoothed model is modified (e.g., quantized or pruned), certification guarantees may not hold for the modified DNN, and recertifying from scratch can be prohibitively expensive. We present the first approach for incremental robustness certification for randomized smoothing, IRS. We show how to reuse the certification guarantees for the original smoothed model to certify an approximated model with very few samples. IRS significantly reduces the computational cost of certifying modified DNNs while maintaining strong robustness guarantees. We experimentally demonstrate the effectiveness of our approach, showing up to 3x certification speedup over the certification that applies randomized smoothing of the approximate model from scratch.
format Preprint
id arxiv_https___arxiv_org_abs_2305_19521
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Incremental Randomized Smoothing Certification
Ugare, Shubham
Suresh, Tarun
Banerjee, Debangshu
Singh, Gagandeep
Misailovic, Sasa
Machine Learning
Cryptography and Security
Programming Languages
Randomized smoothing-based certification is an effective approach for obtaining robustness certificates of deep neural networks (DNNs) against adversarial attacks. This method constructs a smoothed DNN model and certifies its robustness through statistical sampling, but it is computationally expensive, especially when certifying with a large number of samples. Furthermore, when the smoothed model is modified (e.g., quantized or pruned), certification guarantees may not hold for the modified DNN, and recertifying from scratch can be prohibitively expensive. We present the first approach for incremental robustness certification for randomized smoothing, IRS. We show how to reuse the certification guarantees for the original smoothed model to certify an approximated model with very few samples. IRS significantly reduces the computational cost of certifying modified DNNs while maintaining strong robustness guarantees. We experimentally demonstrate the effectiveness of our approach, showing up to 3x certification speedup over the certification that applies randomized smoothing of the approximate model from scratch.
title Incremental Randomized Smoothing Certification
topic Machine Learning
Cryptography and Security
Programming Languages
url https://arxiv.org/abs/2305.19521