提升随机平滑的认证半径估计精度,让神经网络抗干扰能力更可信。
Enhanced Estimation Techniques for Certified Radii in Randomized Smoothing
- 提出针对离散与连续域的新算法,优化认证半径计算
- 在CIFAR-10和ImageNet上显著缩小认证半径误差
- 适合关注模型鲁棒性验证的研究者与实践者
本文提出新型方法以改进随机平滑中的认证半径估计,该技术对认证神经网络对抗扰动的鲁棒性至关重要。所提方法显著提升了认证测试集准确率,通过提供更紧的认证半径边界实现。针对离散与连续域设计了先进算法,并在CIFAR-10和ImageNet数据集上验证其有效性。新方法相比现有方法有明显改进,尤其在降低认证半径估计偏差方面表现突出。研究还探讨了样本量、标准差和温度等超参数对性能的影响。结果表明,该方法有望实现更高效的认证流程,并为未来研究更紧置信序列及改进理论框架铺路。论文最后讨论了未来方向,包括离散域的增强估计技术与理论进展,以弥合随机平滑中经验与理论表现的差距。
原文摘要 · Abstract (English)
This paper presents novel methods for estimating certified radii in randomized smoothing, a technique crucial for certifying the robustness of neural networks against adversarial perturbations. Our proposed techniques significantly improve the accuracy of certified test-set accuracy by providing tighter bounds on the certified radii. We introduce advanced algorithms for both discrete and continuous domains, demonstrating their effectiveness on CIFAR-10 and ImageNet datasets. The new methods show considerable improvements over existing approaches, particularly in reducing discrepancies in certified radii estimates. We also explore the impact of various hyperparameters, including sample size, standard deviation, and temperature, on the performance of these methods. Our findings highlight the potential for more efficient certification processes and pave the way for future research on tighter confidence sequences and improved theoretical frameworks. The study concludes with a discussion of potential future directions, including enhanced estimation techniques for discrete domains and further theoretical advancements to bridge the gap between empirical and theoretical performance in randomized smoothing.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。