Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
129 tokens/sec
GPT-4o
28 tokens/sec
Gemini 2.5 Pro Pro
42 tokens/sec
o3 Pro
4 tokens/sec
GPT-4.1 Pro
38 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Mitigating the Curse of Dimensionality for Certified Robustness via Dual Randomized Smoothing (2404.09586v4)

Published 15 Apr 2024 in cs.CV and cs.LG

Abstract: Randomized Smoothing (RS) has been proven a promising method for endowing an arbitrary image classifier with certified robustness. However, the substantial uncertainty inherent in the high-dimensional isotropic Gaussian noise imposes the curse of dimensionality on RS. Specifically, the upper bound of ${\ell_2}$ certified robustness radius provided by RS exhibits a diminishing trend with the expansion of the input dimension $d$, proportionally decreasing at a rate of $1/\sqrt{d}$. This paper explores the feasibility of providing ${\ell_2}$ certified robustness for high-dimensional input through the utilization of dual smoothing in the lower-dimensional space. The proposed Dual Randomized Smoothing (DRS) down-samples the input image into two sub-images and smooths the two sub-images in lower dimensions. Theoretically, we prove that DRS guarantees a tight ${\ell_2}$ certified robustness radius for the original input and reveal that DRS attains a superior upper bound on the ${\ell_2}$ robustness radius, which decreases proportionally at a rate of $(1/\sqrt m + 1/\sqrt n )$ with $m+n=d$. Extensive experiments demonstrate the generalizability and effectiveness of DRS, which exhibits a notable capability to integrate with established methodologies, yielding substantial improvements in both accuracy and ${\ell_2}$ certified robustness baselines of RS on the CIFAR-10 and ImageNet datasets. Code is available at https://github.com/xiasong0501/DRS.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (49)
  1. Evasion attacks against machine learning at test time. In Joint European conference on machine learning and knowledge discovery in databases, 2013.
  2. Towards evaluating the robustness of neural networks. In IEEE symposium on security and privacy, 2017.
  3. (certified!!) adversarial robustness for free! In Proc. Int’l Conf. Learning Representations, 2023.
  4. Adversarial training of self-supervised monocular depth estimation against physical-world attacks. In Proc. Int’l Conf. Learning Representations, 2023.
  5. Certified adversarial robustness via randomized smoothing. In Proc. Int’l Conf. Machine Learning, 2019.
  6. Imagenet: A large-scale hierarchical image database. In Proc. IEEE Int’l Conf. Computer Vision and Pattern Recognition, 2009.
  7. Mma training: Direct input space margin maximization through adversarial training. In Proc. Int’l Conf. Learning Representations, 2019.
  8. MeViS: A large-scale benchmark for video segmentation with motion expressions. In Proc. IEEE Int’l Conf. Computer Vision, 2023a.
  9. MOSE: A new dataset for video object segmentation in complex scenes. In Proc. IEEE Int’l Conf. Computer Vision, 2023b.
  10. VLT: Vision-language transformer and query generation for referring segmentation. IEEE Trans. on Pattern Analysis and Machine Intelligence, 2023c.
  11. Advdrop: Adversarial attack to dnns by dropping information. In Proc. IEEE Int’l Conf. Computer Vision, 2021.
  12. Gsmooth: Certified robustness against semantic transformations via generalized randomized smoothing. In Proc. Int’l Conf. Machine Learning, 2022.
  13. Deep residual learning for image recognition. In Proc. IEEE Int’l Conf. Computer Vision and Pattern Recognition, 2016.
  14. Natural adversarial examples. In Proc. IEEE Int’l Conf. Computer Vision and Pattern Recognition, 2021.
  15. Boosting randomized smoothing with variance reduced classifiers. In Proc. Int’l Conf. Learning Representations, 2022.
  16. Consistency regularization for certified robustness of smoothed classifiers. In Proc. Annual Conf. Neural Information Processing Systems, 2020.
  17. Gr-psn: Learning to estimate surface normal and reconstruct photometric stereo images. IEEE Trans. on Visualization and Computer Graphics, 2023.
  18. Certified defense for content based image retrieval. In Proc. IEEE Int’l Conf. Computer Vision and Pattern Recognition, pp.  4561–4570, 2023.
  19. Reluplex: An efficient smt solver for verifying deep neural networks. In International conference on computer aided verification, 2017.
  20. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980, 2014.
  21. Detect and locate: Exposing face manipulation by semantic-and noise-level telltales. IEEE Trans. on Information Forensics and Security, 2022.
  22. Learning multiple layers of features from tiny images. Master’s thesis, University of Tront, 2009.
  23. Curse of dimensionality on randomized smoothing for certifiable robustness. In Proc. Int’l Conf. Machine Learning, 2020.
  24. Certified robustness to adversarial examples with differential privacy. In IEEE Symposium on Security and Privacy, 2019.
  25. Making substitute models more bayesian can enhance transferability of adversarial examples. In Proc. Int’l Conf. Learning Representations, 2023.
  26. An approach to reachability analysis for feed-forward relu neural networks. arXiv preprint arXiv:1706.07351, 2017.
  27. Beyond the prior forgery knowledge: Mining critical clues for general face forgery detection. IEEE Trans. on Information Forensics and Security, 2023.
  28. Towards deep learning models resistant to adversarial attacks. In Proc. Int’l Conf. Learning Representations, 2018.
  29. Ix. on the problem of the most efficient tests of statistical hypotheses. Philosophical Transactions of the Royal Society of London. Series A, Containing Papers of a Mathematical or Physical Character, 1933.
  30. Improved denoising diffusion probabilistic models. In Proc. Int’l Conf. Machine Learning, 2021.
  31. Projected randomized smoothing for certified adversarial robustness. Transactions on Machine Learning Research, 2023.
  32. Certified defenses against adversarial examples. In Proc. Int’l Conf. Learning Representations, 2018.
  33. Provably robust deep learning via adversarially trained smoothed classifiers. In Proc. Annual Conf. Neural Information Processing Systems, 2019.
  34. Denoised smoothing: A provable defense for pretrained classifiers. Proc. Annual Conf. Neural Information Processing Systems, 2020.
  35. Adversarial training for free! In Proc. Annual Conf. Neural Information Processing Systems, 2019.
  36. Towards efficient and effective adversarial training. In Proc. Annual Conf. Neural Information Processing Systems, 2021.
  37. Intriguing properties of input-dependent randomized smoothing. In Proc. Int’l Conf. Machine Learning, 2022.
  38. Intriguing properties of neural networks. In Proc. Int’l Conf. Learning Representations, 2014.
  39. Evaluating robustness of neural networks with mixed integer programming. In Proc. Int’l Conf. Learning Representations, 2018.
  40. On adaptive attacks to adversarial example defenses. In Proc. Annual Conf. Neural Information Processing Systems, 2020.
  41. Efficient formal safety analysis of neural networks. In Proc. Annual Conf. Neural Information Processing Systems, 2018.
  42. Provable defenses against adversarial examples via the convex outer adversarial polytope. In Proc. Int’l Conf. Machine Learning, 2018.
  43. Towards open vocabulary learning: A survey. IEEE Trans. on Pattern Analysis and Machine Intelligence, 2024.
  44. Completing the picture: Randomized smoothing suffers from the curse of dimensionality for a large family of distributions. In International Conference on Artificial Intelligence and Statistics, 2021.
  45. Randomized smoothing of all shapes and sizes. In Proc. Int’l Conf. Learning Representations, 2020.
  46. Towards robust rain removal against adversarial attacks: A comprehensive benchmark analysis and beyond. In Proc. IEEE Int’l Conf. Computer Vision and Pattern Recognition, pp.  6013–6022, 2022.
  47. Backdoor attacks against deep image compression via adaptive frequency trigger. In Proc. IEEE Int’l Conf. Computer Vision and Pattern Recognition, pp.  12250–12259, 2023.
  48. Meta gradient adversarial attack. In Proc. IEEE Int’l Conf. Computer Vision, 2021.
  49. Macer: Attack-free and scalable robust training via maximizing certified radius. In Proc. Int’l Conf. Learning Representations, 2019.
Citations (6)

Summary

We haven't generated a summary for this paper yet.