Randomized Smoothing under Attack: How Good is it in Pratice? - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2022

Randomized Smoothing under Attack: How Good is it in Pratice?

Résumé

Randomized smoothing is a recent and celebrated solution to certify the robustness of any classifier. While it indeed provides a theoretical robustness against adversarial attacks, the dimensionality of current classifiers necessarily imposes Monte Carlo approaches for its application in practice. This paper questions the effectiveness of randomized smoothing as a defense, against state of the art black-box attacks. This is a novel perspective, as previous research works considered the certification as an unquestionable guarantee. We first formally highlight the mismatch between a theoretical certification and the practice of attacks on classifiers. We then perform attacks on randomized smoothing as a defense. Our main observation is that there is a major mismatch in the settings of the RS for obtaining high certified robustness or when defeating black box attacks while preserving the classifier accuracy.
Fichier principal
Vignette du fichier
main.pdf (305.99 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03591421 , version 1 (28-02-2022)

Identifiants

  • HAL Id : hal-03591421 , version 1

Citer

Thibault Maho, Teddy Furon, Erwan Le Merrer. Randomized Smoothing under Attack: How Good is it in Pratice?. ICASSP 2022 - IEEE International Conference on Acoustics, Speech and Signal Processing, May 2022, Singapore, Singapore. pp.1-5. ⟨hal-03591421⟩
86 Consultations
168 Téléchargements

Partager

Gmail Facebook X LinkedIn More