Smoothed Embeddings for Certified Few-Shot Learning
Machine Learning
2023-06-06 v2 Artificial Intelligence
Abstract
Randomized smoothing is considered to be the state-of-the-art provable defense against adversarial perturbations. However, it heavily exploits the fact that classifiers map input objects to class probabilities and do not focus on the ones that learn a metric space in which classification is performed by computing distances to embeddings of classes prototypes. In this work, we extend randomized smoothing to few-shot learning models that map inputs to normalized embeddings. We provide analysis of Lipschitz continuity of such models and derive robustness certificate against -bounded perturbations that may be useful in few-shot learning scenarios. Our theoretical results are confirmed by experiments on different datasets.
Cite
@article{arxiv.2202.01186,
title = {Smoothed Embeddings for Certified Few-Shot Learning},
author = {Mikhail Pautov and Olesya Kuznetsova and Nurislam Tursynbek and Aleksandr Petiushko and Ivan Oseledets},
journal= {arXiv preprint arXiv:2202.01186},
year = {2023}
}