Provable Robustness Against a Union of Adversarial Attacks
arXiv:2302.11628 · doi:10.1609/aaai.v38i19.30106
Abstract
Sparse or adversarial attacks arbitrarily perturb an unknown subset of the features. robustness analysis is particularly well-suited for heterogeneous (tabular) data where features have different types or scales. State-of-the-art certified defenses are based on randomized smoothing and apply to evasion attacks only. This paper proposes feature partition aggregation (FPA) -- a certified defense against the union of evasion, backdoor, and poisoning attacks. FPA generates its stronger robustness guarantees via an ensemble whose submodels are trained on disjoint feature sets. Compared to state-of-the-art defenses, FPA is up to 3,000 faster and provides larger median robustness guarantees (e.g., median certificates of 13 pixels over 10 for CIFAR10, 12 pixels over 10 for MNIST, 4 features over 1 for Weather, and 3 features over 1 for Ames), meaning FPA provides the additional dimensions of robustness essentially for free.
Accepted at AAAI 2024 -- Extended version including the supplementary material
References in corpus (12)
- Poisoning Attacks against Support Vector Machines
- Certified Adversarial Robustness via Randomized Smoothing
- Vertical Federated Learning: Challenges, Methodologies and Experiments
- Efficient Certified Defenses Against Patch Attacks on Image Classifiers
- Privacy-Preserving Feature Selection with Secure Multiparty Computation
- Improved Certified Defenses against Data Poisoning with (Deterministic) Finite Aggregation
- Adapting and Evaluating Influence-Estimation Methods for Gradient-Boosted Decision Trees
- Run-Off Election: Improved Provable Defense against Data Poisoning Attacks
- On Collective Robustness of Bagging Against Data Poisoning
- Provable Adversarial Robustness for Fractional Lp Threat Models
- Reducing Certified Regression to Certified Classification for General Poisoning Attacks
- Lethal Dose Conjecture on Data Poisoning