Variational Randomized Smoothing for Sample-Wise Adversarial Robustness

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hase, Ryo, Wang, Ye, Koike-Akino, Toshiaki, Liu, Jing, Parsons, Kieran
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916326380929024
author Hase, Ryo
Wang, Ye
Koike-Akino, Toshiaki
Liu, Jing
Parsons, Kieran
author_facet Hase, Ryo
Wang, Ye
Koike-Akino, Toshiaki
Liu, Jing
Parsons, Kieran
contents Randomized smoothing is a defensive technique to achieve enhanced robustness against adversarial examples which are small input perturbations that degrade the performance of neural network models. Conventional randomized smoothing adds random noise with a fixed noise level for every input sample to smooth out adversarial perturbations. This paper proposes a new variational framework that uses a per-sample noise level suitable for each input by introducing a noise level selector. Our experimental results demonstrate enhancement of empirical robustness against adversarial attacks. We also provide and analyze the certified robustness for our sample-wise smoothing method.
format Preprint
id arxiv_https___arxiv_org_abs_2407_11844
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Variational Randomized Smoothing for Sample-Wise Adversarial Robustness
Hase, Ryo
Wang, Ye
Koike-Akino, Toshiaki
Liu, Jing
Parsons, Kieran
Machine Learning
Artificial Intelligence
Cryptography and Security
Randomized smoothing is a defensive technique to achieve enhanced robustness against adversarial examples which are small input perturbations that degrade the performance of neural network models. Conventional randomized smoothing adds random noise with a fixed noise level for every input sample to smooth out adversarial perturbations. This paper proposes a new variational framework that uses a per-sample noise level suitable for each input by introducing a noise level selector. Our experimental results demonstrate enhancement of empirical robustness against adversarial attacks. We also provide and analyze the certified robustness for our sample-wise smoothing method.
title Variational Randomized Smoothing for Sample-Wise Adversarial Robustness
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2407.11844