Input-Specific Robustness Certification for Randomized Smoothing

12/21/2021
by   Ruoxin Chen, et al.
6

Although randomized smoothing has demonstrated high certified robustness and superior scalability to other certified defenses, the high computational overhead of the robustness certification bottlenecks the practical applicability, as it depends heavily on the large sample approximation for estimating the confidence interval. In existing works, the sample size for the confidence interval is universally set and agnostic to the input for prediction. This Input-Agnostic Sampling (IAS) scheme may yield a poor Average Certified Radius (ACR)-runtime trade-off which calls for improvement. In this paper, we propose Input-Specific Sampling (ISS) acceleration to achieve the cost-effectiveness for robustness certification, in an adaptive way of reducing the sampling size based on the input characteristic. Furthermore, our method universally controls the certified radius decline from the ISS sample size reduction. The empirical results on CIFAR-10 and ImageNet show that ISS can speed up the certification by more than three times at a limited cost of 0.05 certified radius. Meanwhile, ISS surpasses IAS on the average certified radius across the extensive hyperparameter settings. Specifically, ISS achieves ACR=0.958 on ImageNet (σ=1.0) in 250 minutes, compared to ACR=0.917 by IAS under the same condition. We release our code in <https://github.com/roy-ch/Input-Specific-Certification>.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/17/2020

Certifying Confidence via Randomized Smoothing

Randomized smoothing has been shown to provide good certified-robustness...
research
02/01/2023

QCRS: Improve Randomized Smoothing using Quasi-Concave Optimization

Randomized smoothing is currently the state-of-the-art method that provi...
research
04/13/2021

Simpler Certified Radius Maximization by Propagating Covariances

One strategy for adversarially training a robust model is to maximize it...
research
07/09/2021

ANCER: Anisotropic Certification via Sample-wise Volume Maximization

Randomized smoothing has recently emerged as an effective tool that enab...
research
08/01/2021

Certified Defense via Latent Space Randomized Smoothing with Orthogonal Encoders

Randomized Smoothing (RS), being one of few provable defenses, has been ...
research
01/08/2020

MACER: Attack-free and Scalable Robust Training via Maximizing Certified Radius

Adversarial training is one of the most popular ways to learn robust mod...
research
06/13/2021

Boosting Randomized Smoothing with Variance Reduced Classifiers

Randomized Smoothing (RS) is a promising method for obtaining robustness...

Please sign up or login with your details

Forgot password? Click here to reset