Pith. sign in

REVIEW 2 cited by

On Certifying Robustness against Backdoor Attacks via Randomized Smoothing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2002.11750 v4 pith:K7XRT5MV submitted 2020-02-26 cs.CR cs.LG

classification cs.CRcs.LG
keywords backdoorattacksrandomizedsmoothingrobustnesscertifyadversarialcat-and-mouse
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Backdoor attack is a severe security threat to deep neural networks (DNNs). We envision that, like adversarial examples, there will be a cat-and-mouse game for backdoor attacks, i.e., new empirical defenses are developed to defend against backdoor attacks but they are soon broken by strong adaptive backdoor attacks. To prevent such cat-and-mouse game, we take the first step towards certified defenses against backdoor attacks. Specifically, in this work, we study the feasibility and effectiveness of certifying robustness against backdoor attacks using a recent technique called randomized smoothing. Randomized smoothing was originally developed to certify robustness against adversarial examples. We generalize randomized smoothing to defend against backdoor attacks. Our results show the theoretical feasibility of using randomized smoothing to certify robustness against backdoor attacks. However, we also find that existing randomized smoothing methods have limited effectiveness at defending against backdoor attacks, which highlight the needs of new theory and methods to certify robustness against backdoor attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Robustness Certificates for Neural Networks Against Data Poisoning and Evasion Attacks

    cs.LG 2025-12 unverdicted novelty 6.0 of 10

    A neural-network barrier certificate over training trajectories certifies ℓ_p-bounded data-poisoning and evasion budgets, with PAC-style confidence, on MNIST, SVHN, and CIFAR-10.

  2. Certifying Language Model Robustness with Fuzzed Randomized Smoothing: An Efficient Defense Against Backdoor Attacks

    cs.LG 2025-02 reject novelty 5.0 of 10

    FRS targets backdoor triggers with MCTS-guided randomization and parameter smoothing, claiming a larger certified robustness radius that its own theory does not actually prove.

Pith tools