2019

Certified Adversarial Robustness via Randomized Smoothing

Cohen, Jeremy M, Rosenfeld, Elan, Kolter, J. Zico

Understand

We show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the $\ell_2$ norm.

  • This "randomized smoothing" technique has been proposed recently in the literature, but existing guarantees are loose.
  • We prove a tight robustness guarantee in $\ell_2$ norm for smoothing with Gaussian noise.
  • We use randomized smoothing to obtain an ImageNet classifier with e.g.

Reading the bibliography…