TL;DR通过训练替代 Monte Carlo 抽样的替代神经网络,提供随机平滑分类器的近乎精确的近似,加速鲁棒半径认证过程,克服了传统随机平滑方法中的计算瓶颈。
Abstract
randomized smoothing has emerged as a potent certifiable defense against
adversarial attacks by employing smoothing noises from specific distributions
to ensure the robustness of a smoothed classifier. However, t