2020/06/07 by Jongheon Jeong, Jinwoo Shin, Jeong, Jongheon +1 · 4 citations
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Domain Adaptation and Few-Shot Learning
paper · pdf · doi:10.48550/arxiv.2006.04062
A recent technique of randomized smoothing has shown that the worst-case\n(adversarial) \ℓ2-robustness can be transformed into the average-case\nGaussian-robustness by "smoothing" a classifier, i.e., by considering the\naveraged prediction over Gaussian noise. In this paradigm, one should rethink\nthe notion of adversarial robustness in terms of generalization ability of a\nclassifier under noisy observations. We found that the trade-off between\naccuracy and certified robustness of smoothed classifiers can be greatly\ncontrolled by simply regularizing the prediction consistency over noise. This\nrelationship allows us to design a robust training objective without\napproximating a non-existing smoothed classifier, e.g., via soft smoothing. Our\nexperiments under various deep neural network architectures and datasets show\nthat the "certified" \ℓ2-robustness can be dramatically improved with the\nproposed regularization, even achieving better or comparable results to the\nstate-of-the-art approaches with significantly less training costs and\nhyperparameters.\n