[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-160222-en":3,"doc-seo-160222-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},160222,1374391974564,"Clementine","https://ap-avatar.wpscdn.com/avatar/14000253aa45c000a9e?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779874745381141002",8,"Research & Report","Adversarial robustness via robust low rank representations","Adversarial robustness studies how easily a classifier can be fooled by imperceptible, test-time perturbations to its inputs. The work leverages natural low-rank representations commonly present in real data like images to train neural networks with certified robustness guarantees. It presents improved certified robustness for `2-norm perturbations over randomized smoothing-based state of the art. It also develops a method for certified robustness under `∞-norm perturbations using a representation-dependent quantity and a fast algorithm to upper-bound the required matrix operator norm.","Adversarial robustness via robust low rank  \nrepresentations  \nPranjal Awasthi  \nGoogle Research and Rutgers University.  \n[pranjal.awasthi@rutgers.edu](pranjal.awasthi@rutgers.edu).  \nHimanshu Jain  \nGoogle Research. [himj@google.com](himj@google.com).  \nAnkit Singh Rawat  \nGoogle Research. [ankitsrawat@google.com](ankitsrawat@google.com).  \nAravindan Vijayaraghavan  \nNorthwestern University. [aravindv@northwestern.edu](aravindv@northwestern.edu).  \nAbstract  \nAdversarial robustness measures the susceptibility of a classiﬁer to imperceptible perturbations made to the inputs at test time. In this work we highlight the beneﬁts of natural low rank representations that often exist for real data such as images, for training neural networks with certiﬁed robustness guarantees.  \nOur ﬁrst contribution is for certiﬁed robustness to perturbations measured in `2 norm. We exploit low rank data representations to provide improved guarantees over state-of-the-art randomized smoothing-based approaches on standard benchmark datasets such as CIFAR-10 and CIFAR-100 .  \nOur second contribution is for the more challenging setting of certiﬁed robustness to perturbations measured in `∞ norm. We demonstrate empirically that natural low rank representations have inherent robustness properties, that can be leveraged to provide signiﬁcantly better guarantees for certiﬁed robustness to `∞ perturbations in those representations. Our certiﬁcate of `∞ robustness relies on a natural quantity involving the ∞ → 2 matrix operator norm associated with the representation, to translate robustness guarantees from `2 to `∞ perturbations. A key technical ingredient for ourcertiﬁcation guarantees is a fast algorithm with provable guarantees based on the multiplicative weights update method to provide upper bounds on the above matrix norm. Our algorithmic guarantees improve upon the state of the art for this problem, and may be of independent interest.  \n1 Introduction  \nIt is now well established across several domains like images, audio and natural language, that small input perturbations that are imperceptible to humans can fool deep neural networks attest time [1, 2 , 3 , 4] . This phenomenon known as adversarial robustness has led to ﬂurry of research in recent years (see Section A for a discussion of related work) . Following most prior work in this area [5, 6 , 7 , 8 , 9], we will study the setting where adversarial perturbations to an input x are measured in an `p norm (p = 2 or p = ∞ ) .  \nIn this work, we study methods for certiﬁed adversarial robustness in the framework developed in [10, 11] . The goal is to output a classiﬁer f that on input x ∈ Rn outputs a prediction y in the label space Y, along with a certiﬁed radius rf (x) . The classiﬁer is guaranteed to be robust at x up to the radius rf (x) (with high probability), i.e. , ∀z : kz kp ≤ rf (x), f (x + z) = f(x) .  \n34th Conference on Neural Information Processing Systems (NeurIPS 2020), Vancouver, Canada.  \nFor an `p norm and ε > 0, the certiﬁed accuracy of a classiﬁer f is deﬁned as  \naccε(`p)(f ) = (x,yP)∼D 􀀂f(x) = y and rf (x) ≥ ε 􀀃 , (1)  \nwhere D is the data distribution generating test inputs. We call the radius rf (x) returned by the classiﬁer as the certiﬁed radius on x. When ε = 0 this is the natural accuracy of f.  \nFor certiﬁed adversarial robustness to `2 perturbations, the randomized smoothing procedure proposed in [10, 11] is a simple and eﬃcient method that can be applied to any neural network. Randomized smoothing works by creating a smoothed version of a given classiﬁer by adding Gaussian noise to the inputs (see Section 2) . The smoothed classiﬁer exhibits certain Lipschitzness properties, and one can derive good certiﬁed robustness guarantees from it. The study of randomized smoothing for certiﬁed `2 robustness is an active research area and the current best guarantees are obtained by incorporating the smoothed classiﬁer into the training process [12] (see Section A) .  \nIt seems","cbCaidLTxQLXaEqW","https://ap.wps.com/l/cbCaidLTxQLXaEqW","pdf",1994147,1,13,"English","en",105,"# Abstract\n# Introduction\n## Certified adversarial robustness framework\n## Randomized smoothing for `2 robustness\n## Challenges and translation to `∞ robustness\n## Contributions","[{\"question\":\"What problem does this paper address?\",\"answer\":\"The paper studies certified adversarial robustness, focusing on how much a classifier’s prediction remains unchanged under imperceptible input perturbations at test time.\"},{\"question\":\"How does the method improve certified robustness for `2 perturbations?\",\"answer\":\"It modifies randomized smoothing by selectively injecting more noise along specific directions derived from low-rank structure, improving the trade-off between natural and certified accuracy at higher radii.\"},{\"question\":\"What enables certified robustness for `∞ perturbations?\",\"answer\":\"The approach relies on a quantity tied to the ∞→2 matrix operator norm of the representation, translating certified guarantees from `2 robustness to `∞ robustness with a fast algorithm for bounding that norm.\"}]","Adversarial robustness via robust low rank representations | PDF",1788052460,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"adversarial-robustness-via-robust-low-rank-representations","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/adversarial-robustness-via-robust-low-rank-representations/160222/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-30",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does this paper address?","Question",{"text":75,"@type":76},"The paper studies certified adversarial robustness, focusing on how much a classifier’s prediction remains unchanged under imperceptible input perturbations at test time.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the method improve certified robustness for `2 perturbations?",{"text":80,"@type":76},"It modifies randomized smoothing by selectively injecting more noise along specific directions derived from low-rank structure, improving the trade-off between natural and certified accuracy at higher radii.",{"name":82,"@type":73,"acceptedAnswer":83},"What enables certified robustness for `∞ perturbations?",{"text":84,"@type":76},"The approach relies on a quantity tied to the ∞→2 matrix operator norm of the representation, translating certified guarantees from `2 robustness to `∞ robustness with a fast algorithm for bounding that norm.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]