QCRS: Improve Randomized Smoothing using Quasi-Concave Optimization

02/01/2023
by   Bo-Han Kung, et al.
0

Randomized smoothing is currently the state-of-the-art method that provides certified robustness for deep neural networks. However, it often cannot achieve an adequate certified region on real-world datasets. One way to obtain a larger certified region is to use an input-specific algorithm instead of using a fixed Gaussian filter for all data points. Several methods based on this idea have been proposed, but they either suffer from high computational costs or gain marginal improvement in certified radius. In this work, we show that by exploiting the quasiconvex problem structure, we can find the optimal certified radii for most data points with slight computational overhead. This observation leads to an efficient and effective input-specific randomized smoothing algorithm. We conduct extensive experiments and empirical analysis on Cifar10 and ImageNet. The results show that the proposed method significantly enhances the certified radii with low computational overhead.

READ FULL TEXT
research
12/21/2021

Input-Specific Robustness Certification for Randomized Smoothing

Although randomized smoothing has demonstrated high certified robustness...
research
12/08/2020

Data Dependent Randomized Smoothing

Randomized smoothing is a recent technique that achieves state-of-art pe...
research
10/13/2020

Higher-Order Certification for Randomized Smoothing

Randomized smoothing is a recently proposed defense against adversarial ...
research
07/02/2021

DeformRS: Certifying Input Deformations with Randomized Smoothing

Deep neural networks are vulnerable to input deformations in the form of...
research
02/12/2021

Learning Deep Neural Networks under Agnostic Corrupted Supervision

Training deep neural models in the presence of corrupted supervision is ...
research
07/24/2023

Towards Generalizable Deepfake Detection by Primary Region Regularization

The existing deepfake detection methods have reached a bottleneck in gen...
research
07/09/2021

ANCER: Anisotropic Certification via Sample-wise Volume Maximization

Randomized smoothing has recently emerged as an effective tool that enab...

Please sign up or login with your details

Forgot password? Click here to reset