Randomized Smoothing Meets Vision-Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Seferis, Emmanouil, Wu, Changshun, Kollias, Stefanos, Bensalem, Saddek, Cheng, Chih-Hong
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918144473300992
author Seferis, Emmanouil
Wu, Changshun
Kollias, Stefanos
Bensalem, Saddek
Cheng, Chih-Hong
author_facet Seferis, Emmanouil
Wu, Changshun
Kollias, Stefanos
Bensalem, Saddek
Cheng, Chih-Hong
contents Randomized smoothing (RS) is one of the prominent techniques to ensure the correctness of machine learning models, where point-wise robustness certificates can be derived analytically. While RS is well understood for classification, its application to generative models is unclear, since their outputs are sequences rather than labels. We resolve this by connecting generative outputs to an oracle classification task and showing that RS can still be enabled: the final response can be classified as a discrete action (e.g., service-robot commands in VLAs), as harmful vs. harmless (content moderation or toxicity detection in VLMs), or even applying oracles to cluster answers into semantically equivalent ones. Provided that the error rate for the oracle classifier comparison is bounded, we develop the theory that associates the number of samples with the corresponding robustness radius. We further derive improved scaling laws analytically relating the certified radius and accuracy to the number of samples, showing that the earlier result of 2 to 3 orders of magnitude fewer samples sufficing with minimal loss remains valid even under weaker assumptions. Together, these advances make robustness certification both well-defined and computationally feasible for state-of-the-art VLMs, as validated against recent jailbreak-style adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2509_16088
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Randomized Smoothing Meets Vision-Language Models
Seferis, Emmanouil
Wu, Changshun
Kollias, Stefanos
Bensalem, Saddek
Cheng, Chih-Hong
Machine Learning
Randomized smoothing (RS) is one of the prominent techniques to ensure the correctness of machine learning models, where point-wise robustness certificates can be derived analytically. While RS is well understood for classification, its application to generative models is unclear, since their outputs are sequences rather than labels. We resolve this by connecting generative outputs to an oracle classification task and showing that RS can still be enabled: the final response can be classified as a discrete action (e.g., service-robot commands in VLAs), as harmful vs. harmless (content moderation or toxicity detection in VLMs), or even applying oracles to cluster answers into semantically equivalent ones. Provided that the error rate for the oracle classifier comparison is bounded, we develop the theory that associates the number of samples with the corresponding robustness radius. We further derive improved scaling laws analytically relating the certified radius and accuracy to the number of samples, showing that the earlier result of 2 to 3 orders of magnitude fewer samples sufficing with minimal loss remains valid even under weaker assumptions. Together, these advances make robustness certification both well-defined and computationally feasible for state-of-the-art VLMs, as validated against recent jailbreak-style adversarial attacks.
title Randomized Smoothing Meets Vision-Language Models
topic Machine Learning
url https://arxiv.org/abs/2509.16088