Towards Robust Certified Defense via Improved Randomized Smoothing

Satyadwyoom Kumar, Apurva Narayan · 2022 International Joint Conference on Neural Networks (IJCNN) · 2022

Deep learning models change their prediction through a carefully optimized imperceptible change in the input termed as an adversarial perturbation. Researchers have been focusing on developing methods to counter such effects. Recently, randomized smoothing a highly scalable technique to develop a certified classifier was introduced. However, this technique involves training a neural network from scratch. In this paper we present an empirical insight into the technique of randomized smoothing and propose a framework for a generalizable defence that works on a novel way of adding gaussian noise to the randomized smoothing procedure and is applicable to black-box pre-trained classifiers. We perform extensive experimentation across a variety of classification models and multiple datasets such as Cifar10 and ImageNet. Our framework is model-agnostic and out-performs the recent state-of-the-art certified defence methods by a large margin without the requirement of any intensive training, thus achieving high certified as well as unperturbed performance.

Read the paper · More papers on PaperTik