English

Certified Robustness under Heterogeneous Perturbations via Hybrid Randomized Smoothing

Machine Learning 2026-05-14 v1

Abstract

Randomized smoothing provides strong, model-agnostic robustness certificates, but existing guarantees are limited to single modalities, treating continuous and discrete inputs in isolation. This limitation becomes critical in multimodal models, where decisions depend on cross-modal semantics and adversaries can jointly perturb heterogeneous inputs, rendering unimodal certificates insufficient. We introduce a unified randomized smoothing framework for mixed discrete--continuous inputs based on an analytically tractable Neyman--Pearson formulation of the joint worst-case problem. By analyzing the joint likelihood ordering induced by factorized discrete and continuous noise, our approach yields a closed-form, one-dimensional certificate that strictly generalizes both Gaussian (image-only) and discrete (text-only) randomized smoothing. We validate the framework on multimodal safety filtering, providing, to our knowledge, the first model-agnostic Neyman--Pearson certificate for joint discrete-token and continuous-image perturbations in interaction-dependent text--image safety filtering.

Keywords

Cite

@article{arxiv.2605.12876,
  title  = {Certified Robustness under Heterogeneous Perturbations via Hybrid Randomized Smoothing},
  author = {Blaise Delattre and Hengyu Wu and Paul Caillon and Wei Yang Bryan Lim and Yang Cao},
  journal= {arXiv preprint arXiv:2605.12876},
  year   = {2026}
}

Comments

ICML 2026. Code: https://github.com/tdsai-lab/hybrid-randomized-smoothing

R2 v1 2026-07-22T07:09:00.962Z