Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lyu, Saiyue, Shaikh, Shadab, Shpilevskiy, Frederick, Shelhamer, Evan, Lécuyer, Mathias
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908443596554240
author Lyu, Saiyue
Shaikh, Shadab
Shpilevskiy, Frederick
Shelhamer, Evan
Lécuyer, Mathias
author_facet Lyu, Saiyue
Shaikh, Shadab
Shpilevskiy, Frederick
Shelhamer, Evan
Lécuyer, Mathias
contents We propose Adaptive Randomized Smoothing (ARS) to certify the predictions of our test-time adaptive models against adversarial examples. ARS extends the analysis of randomized smoothing using $f$-Differential Privacy to certify the adaptive composition of multiple steps. For the first time, our theory covers the sound adaptive composition of general and high-dimensional functions of noisy inputs. We instantiate ARS on deep image classification to certify predictions against adversarial examples of bounded $L_{\infty}$ norm. In the $L_{\infty}$ threat model, ARS enables flexible adaptation through high-dimensional input-dependent masking. We design adaptivity benchmarks, based on CIFAR-10 and CelebA, and show that ARS improves standard test accuracy by $1$ to $15\%$ points. On ImageNet, ARS improves certified test accuracy by up to $1.6\%$ points over standard RS without adaptivity. Our code is available at https://github.com/ubc-systopia/adaptive-randomized-smoothing .
format Preprint
id arxiv_https___arxiv_org_abs_2406_10427
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences
Lyu, Saiyue
Shaikh, Shadab
Shpilevskiy, Frederick
Shelhamer, Evan
Lécuyer, Mathias
Machine Learning
Cryptography and Security
We propose Adaptive Randomized Smoothing (ARS) to certify the predictions of our test-time adaptive models against adversarial examples. ARS extends the analysis of randomized smoothing using $f$-Differential Privacy to certify the adaptive composition of multiple steps. For the first time, our theory covers the sound adaptive composition of general and high-dimensional functions of noisy inputs. We instantiate ARS on deep image classification to certify predictions against adversarial examples of bounded $L_{\infty}$ norm. In the $L_{\infty}$ threat model, ARS enables flexible adaptation through high-dimensional input-dependent masking. We design adaptivity benchmarks, based on CIFAR-10 and CelebA, and show that ARS improves standard test accuracy by $1$ to $15\%$ points. On ImageNet, ARS improves certified test accuracy by up to $1.6\%$ points over standard RS without adaptivity. Our code is available at https://github.com/ubc-systopia/adaptive-randomized-smoothing .
title Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2406.10427