vix.ing · top · new · best · stats · spec

Consistency Regularization for Certified Robustness of Smoothed\n Classifiers

2020/06/07 by Jongheon Jeong, Jinwoo Shin, Jeong, Jongheon +1 · 4 citations
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Domain Adaptation and Few-Shot Learning

paper · pdf · doi:10.48550/arxiv.2006.04062

Abstract

A recent technique of randomized smoothing has shown that the worst-case\n(adversarial) \ℓ2-robustness can be transformed into the average-case\nGaussian-robustness by "smoothing" a classifier, i.e., by considering the\naveraged prediction over Gaussian noise. In this paradigm, one should rethink\nthe notion of adversarial robustness in terms of generalization ability of a\nclassifier under noisy observations. We found that the trade-off between\naccuracy and certified robustness of smoothed classifiers can be greatly\ncontrolled by simply regularizing the prediction consistency over noise. This\nrelationship allows us to design a robust training objective without\napproximating a non-existing smoothed classifier, e.g., via soft smoothing. Our\nexperiments under various deep neural network architectures and datasets show\nthat the "certified" \ℓ2-robustness can be dramatically improved with the\nproposed regularization, even achieving better or comparable results to the\nstate-of-the-art approaches with significantly less training costs and\nhyperparameters.\n

Citations

Cited by

Related