General Lipschitz:基于变换依赖随机平滑的可解析语义变换认证鲁棒性
计算机视觉与模式识别
2024-08-12 v2 人工智能
摘要
随机平滑是构建对有界幅度加性对抗扰动具有可证明鲁棒性的图像分类器的当前最优方法。然而,针对语义变换(如图像模糊、平移、伽马校正)及其组合构建合理的认证证书则更为复杂。本工作中,我们提出 \emph{General Lipschitz (GL)},一种用于认证神经网络抵御可组合可解析语义扰动的新型框架。在该框架内,我们分析了平滑分类器相对于变换参数的变换依赖 Lipschitz 连续性,并推导了相应的鲁棒性证书。我们的方法在 ImageNet 数据集上与当前最优方法表现相当。
引用
@article{arxiv.2309.16710,
title = {General Lipschitz: Certified Robustness Against Resolvable Semantic Transformations via Transformation-Dependent Randomized Smoothing},
author = {Dmitrii Korzh and Mikhail Pautov and Olga Tsymboi and Ivan Oseledets},
journal= {arXiv preprint arXiv:2309.16710},
year = {2024}
}