Pith. sign in

REVIEW 1 cited by

RS-Del: Edit Distance Robustness Certificates for Sequence Classifiers via Randomized Deletion

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2302.01757 v3 pith:JYE2AYOQ submitted 2023-01-31 cs.CR cs.LGstat.ML

classification cs.CRcs.LGstat.ML
keywords smoothingclassifiersrandomizeddeletioneditrobustnessrs-delwork
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Randomized smoothing is a leading approach for constructing classifiers that are certifiably robust against adversarial examples. Existing work on randomized smoothing has focused on classifiers with continuous inputs, such as images, where $\ell_p$-norm bounded adversaries are commonly studied. However, there has been limited work for classifiers with discrete or variable-size inputs, such as for source code, which require different threat models and smoothing mechanisms. In this work, we adapt randomized smoothing for discrete sequence classifiers to provide certified robustness against edit distance-bounded adversaries. Our proposed smoothing mechanism randomized deletion (RS-Del) applies random deletion edits, which are (perhaps surprisingly) sufficient to confer robustness against adversarial deletion, insertion and substitution edits. Our proof of certification deviates from the established Neyman-Pearson approach, which is intractable in our setting, and is instead organized around longest common subsequences. We present a case study on malware detection--a binary classification problem on byte sequences where classifier evasion is a well-established threat model. When applied to the popular MalConv malware detection model, our smoothing mechanism RS-Del achieves a certified accuracy of 91% at an edit distance radius of 128 bytes.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Certifiably robust malware detectors by design

    cs.CR 2025-08 reject novelty 4.0 of 10

    A new architecture joins a linear layer forced positive on attack perturbation vectors with a monotonic classifier, but the paper's theoretical characterization of robust detectors is mathematically trivial and does n...

Pith tools