vix.ing · top · new · best · stats

Certified Robustness under Heterogeneous Perturbations via Hybrid Randomized Smoothing

2026/05/13 by Blaise Delattre, Hengyu Wu, Paul Caillon +2 · 1 voice
Computer Science · #Adversarial Robustness in Machine Learning #Certificate #Gaussian #Generative Adversarial Networks and Image Synthesis #Image Enhancement Techniques #Rendering (computer graphics) #Robustness (evolution) #Smoothing #cs.LG

paper · pdf · open access · doi:10.48550/arxiv.2605.12876

published in arXiv (Cornell University) (Cornell University)

openalex publication_date 2026/05/13 · arxiv published 2026/05/13 · arxiv updated 2026/05/13 · openalex created_date 2026/05/15 · openalex updated_date 2026/07/28

Abstract

Randomized smoothing provides strong, model-agnostic robustness certificates, but existing guarantees are limited to single modalities, treating continuous and discrete inputs in isolation. This limitation becomes critical in multimodal models, where decisions depend on cross-modal semantics and adversaries can jointly perturb heterogeneous inputs, rendering unimodal certificates insufficient. We introduce a unified randomized smoothing framework for mixed discrete--continuous inputs based on an analytically tractable Neyman--Pearson formulation of the joint worst-case problem. By analyzing the joint likelihood ordering induced by factorized discrete and continuous noise, our approach yields a closed-form, one-dimensional certificate that strictly generalizes both Gaussian (image-only) and discrete (text-only) randomized smoothing. We validate the framework on multimodal safety filtering, providing, to our knowledge, the first model-agnostic Neyman--Pearson certificate for joint discrete-token and continuous-image perturbations in interaction-dependent text--image safety filtering.

Citations

Discussions

Related