提出新方法提升随机平滑的认证鲁棒性,缩小理论与实际差距。
Bridging the Theoretical Gap in Randomized Smoothing
- 利用Lipschitz连续性改进认证框架
- 设计更紧致的置信区间,提升鲁棒性认证精度
- 适合关注模型安全认证的研究者
随机平滑已成为机器学习模型认证对抗鲁棒性的主流方法。然而,理论认证鲁棒性与实际经验鲁棒性之间仍存在显著差距。本文提出一个新框架,通过引入Lipschitz连续性进行认证,并设计一种更少保守的置信区间计算方法,从而收紧认证边界,更准确反映模型实际鲁棒性。通过严格实验验证,该方法提升了鲁棒性准确率,显著缩小了经验结果与先前理论结果之间的差距。研究指出,深入分析局部Lipschitz常数并设计针对性置信区间,可进一步提升随机平滑性能。这些成果为理解Lipschitz连续性与认证鲁棒性间关系提供了新视角。
原文摘要 · Abstract (English)
Randomized smoothing has become a leading approach for certifying adversarial robustness in machine learning models. However, a persistent gap remains between theoretical certified robustness and empirical robustness accuracy. This paper introduces a new framework that bridges this gap by leveraging Lipschitz continuity for certification and proposing a novel, less conservative method for computing confidence intervals in randomized smoothing. Our approach tightens the bounds of certified robustness, offering a more accurate reflection of model robustness in practice. Through rigorous experimentation we show that our method improves the robust accuracy, compressing the gap between empirical findings and previous theoretical results. We argue that investigating local Lipschitz constants and designing ad-hoc confidence intervals can further enhance the performance of randomized smoothing. These results pave the way for a deeper understanding of the relationship between Lipschitz continuity and certified robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。