Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences

๐Ÿ“… 2024-06-14
๐Ÿ›๏ธ Neural Information Processing Systems
๐Ÿ“ˆ Citations: 1
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This work addresses the challenge of certifying robustness against multi-step, input-dependent noise perturbations under test-time adaptive defensesโ€”a setting where conventional randomized smoothing fails due to its inability to handle structured, adaptive disturbances. We propose the first adaptive randomized smoothing framework grounded in *f*-differential privacy, enabling provably sound compositional certification for high-dimensional input-dependent masking and multi-step dynamic noise injection. Our method integrates *f*-DP analysis, adaptive noise modeling, and a novel multi-step smoothing certification mechanism. Evaluated on CIFAR-10 and CelebA, it improves standard accuracy by 1โ€“15 percentage points; on ImageNet, certified accuracy increases by up to 1.6 percentage points. The framework significantly enhances both adversarial robustness and practical deployability under adaptive defenses.

Technology Category

Computer Vision: Adversarial Attacks & RobustnessMachine Learning: Adversarial Learning & RobustnessNatural Language Processing: Safety and Robustness

Application Category

Security and Privacy: Large-scale security measurementsResponsible Web: Data and user privacy-enhancing technologies for the WebUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systems
๐Ÿ“ Abstract
We propose Adaptive Randomized Smoothing (ARS) to certify the predictions of our test-time adaptive models against adversarial examples. ARS extends the analysis of randomized smoothing using $f$-Differential Privacy to certify the adaptive composition of multiple steps. For the first time, our theory covers the sound adaptive composition of general and high-dimensional functions of noisy inputs. We instantiate ARS on deep image classification to certify predictions against adversarial examples of bounded $L_{infty}$ norm. In the $L_{infty}$ threat model, ARS enables flexible adaptation through high-dimensional input-dependent masking. We design adaptivity benchmarks, based on CIFAR-10 and CelebA, and show that ARS improves standard test accuracy by $1$ to $15%$ points. On ImageNet, ARS improves certified test accuracy by up to $1.6%$ points over standard RS without adaptivity. Our code is available at https://github.com/ubc-systopia/adaptive-randomized-smoothing .
Problem

Research questions and friction points this paper is trying to address.

Certify predictions against adversarial examples adaptively
Extend randomized smoothing for multi-step defense analysis
Improve certified accuracy in high-dimensional threat models
Innovation

Methods, ideas, or system contributions that make the work stand out.

Adaptive Randomized Smoothing certifies adversarial robustness
Extends analysis with f-Differential Privacy
Enables high-dimensional input-dependent masking
๐Ÿ”Ž Similar Papers
University of British Columbia | Google DeepMind
S
Saiyue Lyu
University of British Columbia
S
Shadab Shaikh
University of British Columbia
F
Frederick Shpilevskiy
University of British Columbia
Evan Shelhamer
Evan Shelhamer
UBC / Vector Institute / CIFAR AI Chair
computer visionmachine learningdeep learning
M
M. Lรฉcuyer
University of British Columbia