[論文レビュー] Higher-Order Certification for Randomized Smoothing
本稿は、勾配やヘッセ行列などの一次および高次情報(例:勾配、ヘッセ行列)を活用することで、従来の手法よりも顕著に拡大された認証可能ロバスト性半径を実現する、ランダムスムージングの高次認証フレームワークを提案する。認証をネスト型最適化問題に再定式化し、一次統計の高信頼性推定器を導入することで、CIFAR-10およびImageNetにおける$σ$-ガウススムージング分類器について、$σ$-ノルムおよび部分空間$σ$-ノルム攻撃において、最先端の認証精度を達成した。特に$σ$-ノルムおよび部分空間$σ$-ノルム攻撃において顕著な向上を示し、近似的に最適な$σ$-ノルム性能を維持した。
Randomized smoothing is a recently proposed defense against adversarial attacks that has achieved SOTA provable robustness against $\ell_2$ perturbations. A number of publications have extended the guarantees to other metrics, such as $\ell_1$ or $\ell_\infty$, by using different smoothing measures. Although the current framework has been shown to yield near-optimal $\ell_p$ radii, the total safety region certified by the current framework can be arbitrarily small compared to the optimal. In this work, we propose a framework to improve the certified safety region for these smoothed classifiers without changing the underlying smoothing scheme. The theoretical contributions are as follows: 1) We generalize the certification for randomized smoothing by reformulating certified radius calculation as a nested optimization problem over a class of functions. 2) We provide a method to calculate the certified safety region using $0^{th}$-order and $1^{st}$-order information for Gaussian-smoothed classifiers. We also provide a framework that generalizes the calculation for certification using higher-order information. 3) We design efficient, high-confidence estimators for the relevant statistics of the first-order information. Combining the theoretical contribution 2) and 3) allows us to certify safety region that are significantly larger than the ones provided by the current methods. On CIFAR10 and Imagenet datasets, the new regions certified by our approach achieve significant improvements on general $\ell_1$ certified radii and on the $\ell_2$ certified radii for color-space attacks ($\ell_2$ restricted to 1 channel) while also achieving smaller improvements on the general $\ell_2$ certified radii. Our framework can also provide a way to circumvent the current impossibility results on achieving higher magnitude of certified radii without requiring the use of data-dependent smoothing techniques.
研究の動機と目的
- 現在のランダムスムージングフレームワークには、$σ$-ノルム半径がほぼ最適であるにもかかわらず、認証可能領域が任意に小さくなるという限界があることに対処すること。
- 元のスムージング方式を変更せず、データ依存のスムージングを必要とせずに、認証可能ロバスト性を向上させること。
- 局所的分類器の性質(例:勾配、ヘッセ行列)を活用する、脅威モデルに依存しない認証フレームワークを構築すること。
- 実用的認証に向けた、一次情報の高信頼性・低サンプル複雑性推定器を設計すること。
提案手法
- 認証可能半径の計算を、関数のクラスに関するネスト型最適化問題に再定式化することで、高次情報の利用を可能にする。
- 零次および一次情報に基づき、$σ$-ノルム脅威モデル($p=1,2,\infty$)およびその部分空間バージョンにおける認証可能半径の解析的公式を導出する。
- ヘッセ行列などの高次情報の利用を可能にする、より高いロバスト性バウンドを改善するためのフレームワークを提唱する。
- サブガウス分布の濃縮と経験的モーメントバウンドを用いて、一次統計(例:勾配)の効率的かつ高信頼性の推定器を設計する。
- 信頼区間を伴うモンテカルロサンプリングを用いて、$y^{(0)}$および$y^{(1)}$の推定を低サンプル複雑性で行う。
- CIFAR-10およびImageNetにおいて、それぞれ$N=200,000$および$N=1,250,000$のサンプル、$\alpha=0.001$を用いて、手法の妥当性を検証した。
実験結果
リサーチクエスチョン
- RQ1スムージング測度を変更せずに、現在のランダムスムージング手法を著しく超える認証可能ロバスト性を達成できるか?
- RQ2スムージング分類器からの一次および高次情報を利用することで、より大きな認証可能安全領域を達成できるか?
- RQ3高次情報の活用によって、既存の$σ$-ノルム半径の拡大が理論的に不可能であるという事実を回避できるか?
- RQ4実用的認証に適した、一次統計の高信頼性・低サンプル複雑性推定器をどのように構築できるか?
- RQ5提案フレームワークは、他の脅威モデルにおける性能向上を達成する一方で、$σ$-ノルムロバスト性をほぼ最適に維持するか?
主な発見
- 提案手法は、CIFAR-10およびImageNetにおける$σ$-ノルムおよび部分空間$σ$-ノルム攻撃について、顕著に大きな認証可能半径を達成し、認証可能精度が大幅に向上した。
- $σ$-ノルム攻撃では、既存手法の近似的最適性に一致して、半径の向上は限定的であった。
- $σ$-ノルム部分空間攻撃(例:1つの色チャンネルに制限された摂動)では、ベースライン手法と比較して認証可能半径が顕著に増加した。
- 高次情報の利用により、ガウススムージング分類器に対して漸近的に最適な認証が可能となり、既存の不可能性結果を回避できた。
- より多くのサンプル($N=6.4M$)を用いることで、認証可能精度の向上範囲がより大きな半径にまで拡大したが、非常に大きな半径における利益は依然として限定的であった。
- $σ$-ノルム攻撃について、認証可能精度は維持またはわずかに向上し、あらゆる脅威モデルにおけるロバスト性が確認された。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。