(De)Randomized Smoothing for Certifiable Defense against Patch Attacks
arXiv:2002.10733
Abstract
Patch adversarial attacks on images, in which the attacker can distort pixels within a region of bounded size, are an important threat model since they provide a quantitative model for physical adversarial attacks. In this paper, we introduce a certifiable defense against patch attacks that guarantees for a given image and patch attack size, no patch adversarial examples exist. Our method is related to the broad class of randomized smoothing robustness schemes which provide high-confidence probabilistic robustness certificates. By exploiting the fact that patch attacks are more constrained than general sparse attacks, we derive meaningfully large robustness certificates against them. Additionally, in contrast to smoothing-based defenses against L_p and sparse attacks, our defense method against patch attacks is de-randomized, yielding improved, deterministic certificates. Compared to the existing patch certification method proposed by Chiang et al. (2020), which relies on interval bound propagation, our method can be trained significantly faster, achieves high clean and certified robust accuracy on CIFAR-10, and provides certificates at ImageNet scale. For example, for a 5-by-5 patch attack on CIFAR-10, our method achieves up to around 57.6% certified accuracy (with a classifier with around 83.8% clean accuracy), compared to at most 30.3% certified accuracy for the existing method (with a classifier with around 47.8% clean accuracy). Our results effectively establish a new state-of-the-art of certifiable defense against patch attacks on CIFAR-10 and ImageNet. Code is available at https://github.com/alevine0/patchSmoothing.
NeurIPS 2020
References in corpus (7)
- Certified Adversarial Robustness via Randomized Smoothing
- Certified Defenses for Adversarial Patches
- Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness
- Randomized Smoothing of All Shapes and Sizes
- Certified Robustness to Label-Flipping Attacks via Randomized Smoothing
- Wasserstein Smoothing: Certified Robustness against Wasserstein Adversarial Attacks
- Random Smoothing Might be Unable to Certify Robustness for High-Dimensional Images
Cited by in corpus (13)
- Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking
- Mutual Adversarial Training: Learning together is better than going alone
- Defending Person Detection Against Adversarial Patch Attack by using Universal Defensive Frame
- PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier
- Deep Partition Aggregation: Provable Defense against General Poisoning Attacks
- Certifying Confidence via Randomized Smoothing
- Adversarial Patch Camouflage against Aerial Detection
- Provable Robustness Against a Union of Adversarial Attacks
- Detection as Regression: Certified Object Detection by Median Smoothing
- DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding Attacks
- 10 Security and Privacy Problems in Large Foundation Models
- Defenses Against Multi-Sticker Physical Domain Attacks on Classifiers