paper

Provable Robustness Against a Union of Adversarial Attacks

arXiv:2302.11628 · doi:10.1609/aaai.v38i19.30106

Abstract

Sparse or adversarial attacks arbitrarily perturb an unknown subset of the features. robustness analysis is particularly well-suited for heterogeneous (tabular) data where features have different types or scales. State-of-the-art certified defenses are based on randomized smoothing and apply to evasion attacks only. This paper proposes feature partition aggregation (FPA) -- a certified defense against the union of evasion, backdoor, and poisoning attacks. FPA generates its stronger robustness guarantees via an ensemble whose submodels are trained on disjoint feature sets. Compared to state-of-the-art defenses, FPA is up to 3,000 faster and provides larger median robustness guarantees (e.g., median certificates of 13 pixels over 10 for CIFAR10, 12 pixels over 10 for MNIST, 4 features over 1 for Weather, and 3 features over 1 for Ames), meaning FPA provides the additional dimensions of robustness essentially for free.

Accepted at AAAI 2024 -- Extended version including the supplementary material

References in corpus (12)

Cited by in corpus (2)