Dual Randomized Smoothing: Beyond Global Noise Variance
arxiv.org·1w
📊Rate-Distortion Theory
Preview
Report Post

View PDF HTML (experimental)

Abstract:Randomized Smoothing (RS) is a prominent technique for certifying the robustness of neural networks against adversarial perturbations. With RS, achieving high accuracy at small radii requires a small noise variance, while achieving high accuracy at large radii requires a large noise variance. However, the global noise variance used in the standard RS formulation leads to a fundamental limitation: there exists no global noise variance that simultaneously achieves strong performance at both small and large radii. To break through the global variance limitation, we propose a dual RS framework which enables input-dependent noise variances. To achieve that, we first prove …

Similar Posts

Loading similar posts...