Treatment of Statistical Estimation Problems in Randomized Smoothing for Adversarial Robustness

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autor principal: Voracek, Vaclav
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866917897532604416
author Voracek, Vaclav
author_facet Voracek, Vaclav
contents Randomized smoothing is a popular certified defense against adversarial attacks. In its essence, we need to solve a problem of statistical estimation which is usually very time-consuming since we need to perform numerous (usually $10^5$) forward passes of the classifier for every point to be certified. In this paper, we review the statistical estimation problems for randomized smoothing to find out if the computational burden is necessary. In particular, we consider the (standard) task of adversarial robustness where we need to decide if a point is robust at a certain radius or not using as few samples as possible while maintaining statistical guarantees. We present estimation procedures employing confidence sequences enjoying the same statistical guarantees as the standard methods, with the optimal sample complexities for the estimation task and empirically demonstrate their good performance. Additionally, we provide a randomized version of Clopper-Pearson confidence intervals resulting in strictly stronger certificates.
format Preprint
id arxiv_https___arxiv_org_abs_2406_17830
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Treatment of Statistical Estimation Problems in Randomized Smoothing for Adversarial Robustness
Voracek, Vaclav
Machine Learning
Randomized smoothing is a popular certified defense against adversarial attacks. In its essence, we need to solve a problem of statistical estimation which is usually very time-consuming since we need to perform numerous (usually $10^5$) forward passes of the classifier for every point to be certified. In this paper, we review the statistical estimation problems for randomized smoothing to find out if the computational burden is necessary. In particular, we consider the (standard) task of adversarial robustness where we need to decide if a point is robust at a certain radius or not using as few samples as possible while maintaining statistical guarantees. We present estimation procedures employing confidence sequences enjoying the same statistical guarantees as the standard methods, with the optimal sample complexities for the estimation task and empirically demonstrate their good performance. Additionally, we provide a randomized version of Clopper-Pearson confidence intervals resulting in strictly stronger certificates.
title Treatment of Statistical Estimation Problems in Randomized Smoothing for Adversarial Robustness
topic Machine Learning
url https://arxiv.org/abs/2406.17830