Asymmetric certified robustness via feature-convex neural networks
This architecture composes a Lipschitz-continuous feature map with a learned convex function . Since is convex, it is globally underapproximated by its tangent plane at, yielding certified norm balls in the feature space. Lipschitzness of then yields appropriately scaled certificates in the original input space. TLDR: We propose the asymmetric certified robustness problem, which requires certified robustness for only one class and reflects real-world adversarial scenarios. This focused setting allows us to introduce feature-convex classifiers, which produce closed-form and deterministic certified radii on the order of milliseconds.
Dec-14-2023, 09:00:00 GMT