提出可动态节省计算量的鲁棒性认证方法,效率提升20倍
Halt Fast! Early Stopping for Certified Robustness
- 用轻量元学习预测图像先验,自适应调整采样次数
- 相比传统方法样本量减少20倍,仍保持严格统计保证
- 支持按风险阈值动态分配算力,适合实时安全场景
随机平滑(Randomized Smoothing, RS)为神经网络提供无需结构限制的严格鲁棒性保证,但其应用受限于极高的计算开销。标准RS需对每个输入进行数万次模型评估,且要求预先固定采样数量。本文提出一种新型元学习框架,实现任意时间有效的认证,能自适应调配计算资源。通过轻量级元学习器为序列式E过程预测图像相关先验,相比传统方法将样本复杂度降低20倍,同时维持严格的统计保证。该方法不仅显著提升效率,还支持根据应用场景的风险阈值动态分配计算资源,实现传统认证框架无法实现的资源调度。实验表明,该方法在保持相似认证性能的同时,为实时、安全关键场景的部署提供了可行路径。
原文摘要 · Abstract (English)
Randomized Smoothing (RS) provides rigorous robustness guarantees for neural networks without architectural constraints, yet its adoption is limited by extreme computational costs. Standard RS requires tens of thousands of model evaluations per input and forces practitioners to commit to fixed sample sizes a priori. In this work, we present a novel meta-learning framework for anytime-valid certified robustness that adaptively deploys computational resources. By using a lightweight meta-learner to predict image-specific priors for a sequential E-process, we achieve a 20-fold reduction in sample complexity compared to traditional methods while maintaining rigorous statistical guarantees. Beyond raw efficiency, we demonstrate how anytime-validity enables adaptively allocating compute based upon application-specific risk thresholds, a form of resource triage impossible under classic certification frameworks. That this is achievable while also providing similar certification performance demonstrates that our approach provides a pathway for real-time, safety-critical certification deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。