Adaptive Diffusion Denoised Smoothing : Certified Robustness via Randomized Smoothing with Differentially Private Guided Denoising Diffusion

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shpilevskiy, Frederick, Lyu, Saiyue, Dvijotham, Krishnamurthy Dj, Lécuyer, Mathias, Noël, Pierre-André
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912475889270784
author Shpilevskiy, Frederick
Lyu, Saiyue
Dvijotham, Krishnamurthy Dj
Lécuyer, Mathias
Noël, Pierre-André
author_facet Shpilevskiy, Frederick
Lyu, Saiyue
Dvijotham, Krishnamurthy Dj
Lécuyer, Mathias
Noël, Pierre-André
contents We propose Adaptive Diffusion Denoised Smoothing, a method for certifying the predictions of a vision model against adversarial examples, while adapting to the input. Our key insight is to reinterpret a guided denoising diffusion model as a long sequence of adaptive Gaussian Differentially Private (GDP) mechanisms refining a pure noise sample into an image. We show that these adaptive mechanisms can be composed through a GDP privacy filter to analyze the end-to-end robustness of the guided denoising process, yielding a provable certification that extends the adaptive randomized smoothing analysis. We demonstrate that our design, under a specific guiding strategy, can improve both certified accuracy and standard accuracy on ImageNet for an $\ell_2$ threat model.
format Preprint
id arxiv_https___arxiv_org_abs_2507_08163
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adaptive Diffusion Denoised Smoothing : Certified Robustness via Randomized Smoothing with Differentially Private Guided Denoising Diffusion
Shpilevskiy, Frederick
Lyu, Saiyue
Dvijotham, Krishnamurthy Dj
Lécuyer, Mathias
Noël, Pierre-André
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
We propose Adaptive Diffusion Denoised Smoothing, a method for certifying the predictions of a vision model against adversarial examples, while adapting to the input. Our key insight is to reinterpret a guided denoising diffusion model as a long sequence of adaptive Gaussian Differentially Private (GDP) mechanisms refining a pure noise sample into an image. We show that these adaptive mechanisms can be composed through a GDP privacy filter to analyze the end-to-end robustness of the guided denoising process, yielding a provable certification that extends the adaptive randomized smoothing analysis. We demonstrate that our design, under a specific guiding strategy, can improve both certified accuracy and standard accuracy on ImageNet for an $\ell_2$ threat model.
title Adaptive Diffusion Denoised Smoothing : Certified Robustness via Randomized Smoothing with Differentially Private Guided Denoising Diffusion
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2507.08163