Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866908443596554240 |
|---|---|
| author | Lyu, Saiyue Shaikh, Shadab Shpilevskiy, Frederick Shelhamer, Evan Lécuyer, Mathias |
| author_facet | Lyu, Saiyue Shaikh, Shadab Shpilevskiy, Frederick Shelhamer, Evan Lécuyer, Mathias |
| contents | We propose Adaptive Randomized Smoothing (ARS) to certify the predictions of our test-time adaptive models against adversarial examples. ARS extends the analysis of randomized smoothing using $f$-Differential Privacy to certify the adaptive composition of multiple steps. For the first time, our theory covers the sound adaptive composition of general and high-dimensional functions of noisy inputs. We instantiate ARS on deep image classification to certify predictions against adversarial examples of bounded $L_{\infty}$ norm. In the $L_{\infty}$ threat model, ARS enables flexible adaptation through high-dimensional input-dependent masking. We design adaptivity benchmarks, based on CIFAR-10 and CelebA, and show that ARS improves standard test accuracy by $1$ to $15\%$ points. On ImageNet, ARS improves certified test accuracy by up to $1.6\%$ points over standard RS without adaptivity. Our code is available at https://github.com/ubc-systopia/adaptive-randomized-smoothing . |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2406_10427 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences Lyu, Saiyue Shaikh, Shadab Shpilevskiy, Frederick Shelhamer, Evan Lécuyer, Mathias Machine Learning Cryptography and Security We propose Adaptive Randomized Smoothing (ARS) to certify the predictions of our test-time adaptive models against adversarial examples. ARS extends the analysis of randomized smoothing using $f$-Differential Privacy to certify the adaptive composition of multiple steps. For the first time, our theory covers the sound adaptive composition of general and high-dimensional functions of noisy inputs. We instantiate ARS on deep image classification to certify predictions against adversarial examples of bounded $L_{\infty}$ norm. In the $L_{\infty}$ threat model, ARS enables flexible adaptation through high-dimensional input-dependent masking. We design adaptivity benchmarks, based on CIFAR-10 and CelebA, and show that ARS improves standard test accuracy by $1$ to $15\%$ points. On ImageNet, ARS improves certified test accuracy by up to $1.6\%$ points over standard RS without adaptivity. Our code is available at https://github.com/ubc-systopia/adaptive-randomized-smoothing . |
| title | Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences |
| topic | Machine Learning Cryptography and Security |
| url | https://arxiv.org/abs/2406.10427 |