Random Smoothing Might be Unable to Certify ℓ_∞ Robustness for High-Dimensional Images

02/10/2020
by   Avrim Blum, et al.
16

We show a hardness result for random smoothing to achieve certified adversarial robustness against attacks in the ℓ_p ball of radius ϵ when p>2. Although random smoothing has been well understood for the ℓ_2 case using the Gaussian distribution, much remains unknown concerning the existence of a noise distribution that works for the case of p>2. This has been posed as an open problem by Cohen et al. (2019) and includes many significant paradigms such as the ℓ_∞ threat model. In this work, we show that under certain regularity conditions, any noise distribution D over R^d that provides ℓ_p robustness with p>2 must satisfy Eη_i^2=Ω(d^1-2/pϵ^2/δ^2) for 99 features (pixels) of vector η drawn from D, where ϵ is the robust radius and δ measures the score gap between the highest score and the runner-up. Therefore, for high-dimensional images with pixel values bounded in [0,255], the required noise will eventually dominate the useful information in the images, leading to trivial smoothed classifiers.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/14/2020

Random Smoothing Might be Unable to Certify $\ell_\infty$ Robustness for High-Dimensional Images

We show a hardness result for random smoothing to achieve certified adve...
research
02/08/2020

Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness

Randomized smoothing, using just a simple isotropic Gaussian distributio...
research
09/17/2020

Certifying Confidence via Randomized Smoothing

Randomized smoothing has been shown to provide good certified-robustness...
research
02/21/2020

Black-Box Certification with Randomized Smoothing: A Functional Optimization Based Framework

Randomized classifiers have been shown to provide a promising approach f...
research
06/28/2021

Certified Robustness via Randomized Smoothing over Multiplicative Parameters

We propose a novel approach of randomized smoothing over multiplicative ...
research
02/22/2018

Robustness of classifiers to uniform ℓ_p and Gaussian noise

We study the robustness of classifiers to various kinds of random noise ...

Please sign up or login with your details

Forgot password? Click here to reset