arXiv:2510.19977cs.LGcs.CR2025-10中稿 · CSF 2026, 39th IEE…被引 1

用非均匀噪声提升模型抗攻击能力,显著增强认证鲁棒性。

Towards Strong Certified Defense with Universal Asymmetric Randomization

  • 通过自适应非均匀噪声替代原有均匀噪声,实现更精准的防御。
  • 在MNIST、CIFAR10和ImageNet上,认证准确率最高提升182.6%。
  • 适用于任意分类器和多种ℓ_p范数,可灵活调整防御强度。

随机平滑已成为实现机器学习模型认证对抗鲁棒性的关键方法。然而,现有方法多采用各向同性噪声分布,在所有数据维度(如图像像素)上保持一致,忽略了输入和维度间的异质性,限制了鲁棒性认证的效果。为此,我们提出UCAN:一种通用的非均匀噪声认证方法,可将任意现有随机平滑方法从对称(各向同性)转变为非对称(各向异性)噪声分布,提供更定制化的防御策略。其理论框架支持多种噪声分布,适用于不同ℓ_p-范数,并通过定制化噪声注入,为任意分类器提供扰动输入下预测结果的可证明鲁棒性边界。此外,我们设计了三种新型噪声参数生成器(NPG),可针对不同数据维度最优调参,灵活实现不同程度的鲁棒性增强。实验表明,UCAN在多项基准测试中性能显著超越现有最先进方法,在大认证半径下于MNIST、CIFAR10和ImageNet上认证准确率最高提升182.6%。

原文摘要 · Abstract (English)

Randomized smoothing has become essential for achieving certified adversarial robustness in machine learning models. However, current methods primarily use isotropic noise distributions that are uniform across all data dimensions, such as image pixels, limiting the effectiveness of robustness certification by ignoring the heterogeneity of inputs and data dimensions. To address this limitation, we propose UCAN: a novel technique that \underline{U}niversally \underline{C}ertifies adversarial robustness with \underline{A}nisotropic \underline{N}oise. UCAN is designed to enhance any existing randomized smoothing method, transforming it from symmetric (isotropic) to asymmetric (anisotropic) noise distributions, thereby offering a more tailored defense against adversarial attacks. Our theoretical framework is versatile, supporting a wide array of noise distributions for certified robustness in different $\ell_p$-norms and applicable to any arbitrary classifier by guaranteeing the classifier's prediction over perturbed inputs with provable robustness bounds through tailored noise injection. Additionally, we develop a novel framework equipped with three exemplary noise parameter generators (NPGs) to optimally fine-tune the anisotropic noise parameters for different data dimensions, allowing for pursuing different levels of robustness enhancements in practice.Empirical evaluations underscore the significant leap in UCAN's performance over existing state-of-the-art methods, demonstrating up to $182.6\%$ improvement in certified accuracy at large certified radii on MNIST, CIFAR10, and ImageNet datasets.\footnote{Code is anonymously available at \href{https://github.com/youbin2014/UCAN/}{https://github.com/youbin2014/UCAN/}}

对抗鲁棒性随机平滑非均匀噪声认证防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。