Variational Randomized Smoothing for Sample-Wise Adversarial Robustness
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866916326380929024 |
|---|---|
| author | Hase, Ryo Wang, Ye Koike-Akino, Toshiaki Liu, Jing Parsons, Kieran |
| author_facet | Hase, Ryo Wang, Ye Koike-Akino, Toshiaki Liu, Jing Parsons, Kieran |
| contents | Randomized smoothing is a defensive technique to achieve enhanced robustness against adversarial examples which are small input perturbations that degrade the performance of neural network models. Conventional randomized smoothing adds random noise with a fixed noise level for every input sample to smooth out adversarial perturbations. This paper proposes a new variational framework that uses a per-sample noise level suitable for each input by introducing a noise level selector. Our experimental results demonstrate enhancement of empirical robustness against adversarial attacks. We also provide and analyze the certified robustness for our sample-wise smoothing method. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2407_11844 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Variational Randomized Smoothing for Sample-Wise Adversarial Robustness Hase, Ryo Wang, Ye Koike-Akino, Toshiaki Liu, Jing Parsons, Kieran Machine Learning Artificial Intelligence Cryptography and Security Randomized smoothing is a defensive technique to achieve enhanced robustness against adversarial examples which are small input perturbations that degrade the performance of neural network models. Conventional randomized smoothing adds random noise with a fixed noise level for every input sample to smooth out adversarial perturbations. This paper proposes a new variational framework that uses a per-sample noise level suitable for each input by introducing a noise level selector. Our experimental results demonstrate enhancement of empirical robustness against adversarial attacks. We also provide and analyze the certified robustness for our sample-wise smoothing method. |
| title | Variational Randomized Smoothing for Sample-Wise Adversarial Robustness |
| topic | Machine Learning Artificial Intelligence Cryptography and Security |
| url | https://arxiv.org/abs/2407.11844 |