Center Smoothing: Certified Robustness for Networks with Structured Outputs
–Neural Information Processing Systems
Let, y be a point in that intersection. Given z = ˆf(x), define a random variable Q = d(z, f(X)), where is X x + P. For m i.i.d. For functions with high-dimensional outputs, like high-resolution images, it might be difficult to compute the minimum enclosing ball (MEB) for a large number of points. It does not allow us to sample the n points in batches as is possible for the certification step. The rest of the procedure remains the same as algorithm 1.
Neural Information Processing Systems
Jun-2-2025, 11:39:00 GMT