Bridging the Theoretical Gap in Randomized Smoothing

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Delattre, Blaise, Caillon, Paul, Barthélemy, Quentin, Fagnou, Erwan, Allauzen, Alexandre
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913784337006592
author Delattre, Blaise
Caillon, Paul
Barthélemy, Quentin
Fagnou, Erwan
Allauzen, Alexandre
author_facet Delattre, Blaise
Caillon, Paul
Barthélemy, Quentin
Fagnou, Erwan
Allauzen, Alexandre
contents Randomized smoothing has become a leading approach for certifying adversarial robustness in machine learning models. However, a persistent gap remains between theoretical certified robustness and empirical robustness accuracy. This paper introduces a new framework that bridges this gap by leveraging Lipschitz continuity for certification and proposing a novel, less conservative method for computing confidence intervals in randomized smoothing. Our approach tightens the bounds of certified robustness, offering a more accurate reflection of model robustness in practice. Through rigorous experimentation we show that our method improves the robust accuracy, compressing the gap between empirical findings and previous theoretical results. We argue that investigating local Lipschitz constants and designing ad-hoc confidence intervals can further enhance the performance of randomized smoothing. These results pave the way for a deeper understanding of the relationship between Lipschitz continuity and certified robustness.
format Preprint
id arxiv_https___arxiv_org_abs_2504_02412
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Bridging the Theoretical Gap in Randomized Smoothing
Delattre, Blaise
Caillon, Paul
Barthélemy, Quentin
Fagnou, Erwan
Allauzen, Alexandre
Machine Learning
Randomized smoothing has become a leading approach for certifying adversarial robustness in machine learning models. However, a persistent gap remains between theoretical certified robustness and empirical robustness accuracy. This paper introduces a new framework that bridges this gap by leveraging Lipschitz continuity for certification and proposing a novel, less conservative method for computing confidence intervals in randomized smoothing. Our approach tightens the bounds of certified robustness, offering a more accurate reflection of model robustness in practice. Through rigorous experimentation we show that our method improves the robust accuracy, compressing the gap between empirical findings and previous theoretical results. We argue that investigating local Lipschitz constants and designing ad-hoc confidence intervals can further enhance the performance of randomized smoothing. These results pave the way for a deeper understanding of the relationship between Lipschitz continuity and certified robustness.
title Bridging the Theoretical Gap in Randomized Smoothing
topic Machine Learning
url https://arxiv.org/abs/2504.02412