Real-life applications of deep neural networks are hindered by their unsteady predictions when faced with noisy inputs and adversarial attacks. The certified radius in this context is a crucial indicator of the robustness of models. However how to design an efficient classifier with an associated certified radius? Randomized smoothing provides a promising framework by relying on noise injection into the inputs to obtain a smoothed and robust classifier. In this paper, we first show that the variance introduced by the Monte-Carlo sampling in the randomized smoothing procedure estimate closely interacts with two other important properties of the classifier, \textit{i.e.} its Lipschitz constant and margin. More precisely, our work emphasizes the dual impact of the Lipschitz constant of the base classifier, on both the smoothed classifier and the empirical variance. To increase the certified robust radius, we introduce a different way to convert logits to probability vectors for the base classifier to leverage the variance-margin trade-off. We leverage the use of Bernstein's concentration inequality along with enhanced Lipschitz bounds for randomized smoothing. Experimental results show a significant improvement in certified accuracy compared to current state-of-the-art methods. Our novel certification procedure allows us to use pre-trained models with randomized smoothing, effectively improving the current certification radius in a zero-shot manner.
翻译:深度神经网络在实际应用中因面对噪声输入与对抗攻击时产生不稳定预测而受限。在此背景下,认证半径是衡量模型鲁棒性的关键指标。然而,如何设计具有关联认证半径的高效分类器?随机平滑框架通过向输入注入噪声以获得平滑且鲁棒的分类器,为此提供了有效途径。本文首先证明,随机平滑过程中蒙特卡洛采样引入的方差与分类器的另外两个重要属性——即Lipschitz常数和边界——存在紧密交互。具体而言,我们的工作强调了基分类器Lipschitz常数对平滑分类器及经验方差的双重影响。为扩大认证鲁棒半径,我们提出了一种将逻辑值转换为基分类器概率向量的新方法,以利用方差-边界权衡。我们结合Bernstein浓度不等式与增强的Lipschitz边界对随机平滑进行优化。实验结果表明,与当前最先进方法相比,认证准确率显著提升。我们的新型认证流程允许将预训练模型与随机平滑结合使用,以零样本方式有效改善现有认证半径。