Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness

02/08/2020
by   Aounon Kumar, et al.
0

Randomized smoothing, using just a simple isotropic Gaussian distribution, has been shown to produce good robustness guarantees against ℓ_2-norm bounded adversaries. In this work, we show that extending the smoothing technique to defend against other attack models can be challenging, especially in the high-dimensional regime. In particular, for a vast class of i.i.d. smoothing distributions, we prove that the largest ℓ_p-radius that can be certified decreases as O(1/d^1/2 - 1/p) with dimension d for p > 2. Notably, for p ≥ 2, this dependence on d is no better than that of the ℓ_p-radius that can be certified using isotropic Gaussian smoothing, essentially putting a matching lower bound on the robustness radius. When restricted to generalized Gaussian smoothing, these two bounds can be shown to be within a constant factor of each other in an asymptotic sense, establishing that Gaussian smoothing provides the best possible results, up to a constant factor, when p ≥ 2. We present experimental results on CIFAR to validate our theory. For other smoothing distributions, such as, a uniform distribution within an ℓ_1 or an ℓ_∞-norm ball, we show upper bounds of the form O(1 / d) and O(1 / d^1 - 1/p) respectively, which have an even worse dependence on d.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/16/2022

Double Sampling Randomized Smoothing

Neural networks (NNs) are known to be vulnerable against adversarial per...
research
09/17/2020

Certifying Confidence via Randomized Smoothing

Randomized smoothing has been shown to provide good certified-robustness...
research
10/12/2022

Double Bubble, Toil and Trouble: Enhancing Certified Robustness through Transitivity

In response to subtle adversarial examples flipping classifications of n...
research
02/10/2020

Random Smoothing Might be Unable to Certify ℓ_∞ Robustness for High-Dimensional Images

We show a hardness result for random smoothing to achieve certified adve...
research
02/14/2020

Random Smoothing Might be Unable to Certify $\ell_\infty$ Robustness for High-Dimensional Images

We show a hardness result for random smoothing to achieve certified adve...
research
10/20/2020

Tight Second-Order Certificates for Randomized Smoothing

Randomized smoothing is a popular way of providing robustness guarantees...
research
05/15/2020

Towards Assessment of Randomized Smoothing Mechanisms for Certifying Adversarial Robustness

As a certified defensive technique, randomized smoothing has received co...

Please sign up or login with your details

Forgot password? Click here to reset