Certified defenses against adversarial attacks offer formal guarantees on the robustness of a model, making them more reliable than empirical methods such as adversarial training, whose effectiveness is often later reduced by unseen attacks. Still, the limited certified robustness that is currently achievable has been a bottleneck for their practical adoption. Gowal et al. and Wang et al. have shown that generating additional training data using state-of-the-art diffusion models can considerably improve the robustness of adversarial training. In this work, we demonstrate that a similar approach can substantially improve deterministic certified defenses. In addition, we provide a list of recommendations to scale the robustness of certified training approaches. One of our main insights is that the generalization gap, i.e., the difference between the training and test accuracy of the original model, is a good predictor of the magnitude of the robustness improvement when using additional generated data. Our approach achieves state-of-the-art deterministic robustness certificates on CIFAR-10 for the $\ell_2$ ($\epsilon = 36/255$) and $\ell_\infty$ ($\epsilon = 8/255$) threat models, outperforming the previous best results by $+3.95\%$ and $+1.39\%$, respectively. Furthermore, we report similar improvements for CIFAR-100.
翻译:针对对抗攻击的认证防御方法能够为模型鲁棒性提供形式化保证,相较于对抗训练等经验性方法(其有效性常因未见攻击而降低)更为可靠。然而,当前可实现的有限认证鲁棒性一直是其实际应用的主要瓶颈。Gowal等人与Wang等人的研究表明,利用最先进的扩散模型生成额外训练数据可显著提升对抗训练的鲁棒性。本文证明类似方法能有效改善确定性认证防御的性能。此外,我们提出一系列建议以扩展认证训练方法的鲁棒性规模。核心发现之一是:泛化差距(即原始模型训练精度与测试精度之差)可作为使用额外生成数据时鲁棒性提升幅度的良好预测指标。我们的方法在CIFAR-10数据集上针对$\ell_2$($\epsilon = 36/255$)和$\ell_\infty$($\epsilon = 8/255$)威胁模型取得了最先进的确定性鲁棒性认证,分别以$+3.95\%$和$+1.39\%$的优势超越先前最佳结果。此外,我们在CIFAR-100数据集上也报告了类似的性能提升。