ICLRFeb, 2021
实证鲁棒性与认证鲁棒性对抗对策间的缩小
Towards Bridging the gap between Empirical and Certified Robustness against Adversarial Examples
Jay Nandy, Sudipan Saha, Wynne Hsu, Mong Li Lee, Xiao Xiang Zhu
TL;DR本文介绍了一种新方法,即通过自适应实现认证,将经过对抗训练的模型转化为随机平滑分类器,在推理过程中提供 l2 范数的认证鲁棒性,同时不影响它们对抗攻击的经验鲁棒性。