Pith. sign in

REVIEW 2 cited by

SPLITZ: Certifiable Robustness via Split Lipschitz Randomized Smoothing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.02811 v3 pith:PONPCCGD submitted 2024-07-03 cs.LG cs.ITmath.IT

classification cs.LGcs.ITmath.IT
keywords splitzlipschitzrobustnesscertifiableclassifierrandomizedsmoothingaccuracy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Certifiable robustness gives the guarantee that small perturbations around an input to a classifier will not change the prediction. There are two approaches to provide certifiable robustness to adversarial examples: a) explicitly training classifiers with small Lipschitz constants, and b) Randomized smoothing, which adds random noise to the input to create a smooth classifier. We propose SPLITZ, a practical and novel approach which leverages the synergistic benefits of both the above ideas into a single framework. Our main idea is to split a classifier into two halves, constrain the Lipschitz constant of the first half, and smooth the second half via randomization. Motivation for SPLITZ comes from the observation that many standard deep networks exhibit heterogeneity in Lipschitz constants across layers. SPLITZ can exploit this heterogeneity while inheriting the scalability of randomized smoothing. We present a principled approach to train SPLITZ and provide theoretical analysis to derive certified robustness guarantees during inference. We present a comprehensive comparison of robustness-accuracy trade-offs and show that SPLITZ consistently improves on existing state-of-the-art approaches in the MNIST, CIFAR-10 and ImageNet datasets. For instance, with $\ell_2$ norm perturbation budget of $\epsilon=1$, SPLITZ achieves $43.2\%$ top-1 test accuracy on CIFAR-10 dataset compared to state-of-art top-1 test accuracy $39.8\%$.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Inference Privacy: Properties and Mechanisms

    cs.CR 2024-11 conditional novelty 3.0 of 10

    Inference Privacy requires that a model's output distributions for any two inputs within a chosen radius alpha are almost identical, and it is implemented by calibrating input or output noise with standard differentia...

  2. Learning Fair Robustness via Domain Mixup

    cs.LG 2024-11 reject novelty 3.0 of 10

    A claim that same-class mixup combined with adversarial training provably reduces class-wise robustness disparity, but the theoretical support is invalid because it evaluates the classifier on the wrong distribution a...

Pith tools