🤖 AI Summary
This study addresses the failure of randomized smoothing certification radii caused by feasibility filtering and the decision boundary risks introduced by conditional probability ratios. We propose an analytical framework that decouples geometric and certification analyses. By revealing the geometric deficiencies of conditional substitution, we establish a geometric control theory for convex and non-convex sets, and design a method combining retention-label probabilities with covariance bounds to obtain valid certification radii. Furthermore, this work integrates Rényi divergence bounds with adaptive Gaussian composition to optimize finite-sample certification bounds. Experiments demonstrate that our approach significantly outperforms existing union mass bounds on image classification tasks, successfully validating the effectiveness of non-convex filters while uncovering label-shifting phenomena in previously published filters.
📝 Abstract
Randomized smoothing certifies the probability of a fixed output event as the center of Gaussian noise moves. Feasibility or confidence filtering reports label probabilities only among retained proposals, producing a ratio. Its numerator is a fixed Gaussian event mass, while its denominator is the probability of retention and can change with the center. Substituting this ratio into the ordinary smoothing formula can therefore certify a ball that contains a decision boundary. We separate the problem into a geometric question and a certification question. Geometry determines when conditioning preserves Gaussian comparisons. Convex retained sets preserve the full comparison, while general sets require geometric control of the retained law as the center moves. Without such control, conditional probabilities imply no positive universal radius. Joint retention-and-label probabilities always yield a valid certificate for the same filtered predictor. A uniform covariance bound transfers divergence certificates to the retained law and can yield larger radii even when the Gaussian event comparison fails. Both methods admit finite-sample bounds. For a learned image classifier with a training-selected nonconvex filter, conditional Rényi bounds certify more images than joint-mass bounds without additional model evaluations. A released confidence filter exhibits verified label changes inside radii obtained by conditional substitution. An application of adaptive Gaussian composition covers causal finite-horizon executions with history-dependent center shifts under a pathwise energy bound.