UniCR: Universally Approximated Certified Robustness via Randomized Smoothing

UniCR: Universally Approximated Certified Robustness via Randomized Smoothing
复制标题

DOI:
10.48550/arxiv.2207.02152
复制
发表时间:
2022-07
期刊:
ArXiv
影响因子:
--
通讯作者:
Hanbin Hong;Binghui Wang;Yuan Hong
Hanbin Hong;Binghui Wang;Yuan Hong
中科院分区:
其他
文献类型:
--
作者:
Hanbin Hong;Binghui Wang;Yuan Hong

文献摘要

相似文献

我们研究了机器学习分类器对对抗性扰动的鲁棒性。特别是,我们提出了第一个普遍近似认证的鲁棒性(UniCR)框架,它可以近似的鲁棒性认证的任何输入对任何分类器对任何$\ell_p$扰动与噪声产生的任何连续概率分布。与最先进的认证防御相比,UniCR提供了许多显著的好处:(1)第一个通用的鲁棒性认证框架,适用于上述4个“任何”;(2)自动鲁棒性认证,避免了逐个案例的分析,(3)认证鲁棒性的紧密性验证,以及(4)随机平滑所使用的噪声分布的最优性验证。我们进行了大量的实验,以验证UniCR的上述好处和UniCR的优势,国家的最先进的认证防御对$\ell_p$扰动。
We study certified robustness of machine learning classifiers against adversarial perturbations. In particular, we propose the first universally approximated certified robustness (UniCR) framework, which can approximate the robustness certification of any input on any classifier against any $\ell_p$ perturbations with noise generated by any continuous probability distribution. Compared with the state-of-the-art certified defenses, UniCR provides many significant benefits: (1) the first universal robustness certification framework for the above 4 'any's; (2) automatic robustness certification that avoids case-by-case analysis, (3) tightness validation of certified robustness, and (4) optimality validation of noise distributions used by randomized smoothing. We conduct extensive experiments to validate the above benefits of UniCR and the advantages of UniCR over state-of-the-art certified defenses against $\ell_p$ perturbations.