Effects of Exponential Gaussian Distribution on (Double Sampling) Randomized Smoothing
Youwei Shu, Xi Xiao, Derui Wang, Yuxin Cao, Siji Chen, Jason Xue, Linyi Li, Bo Li
TL;DR
The paper investigates how two distribution families, ESG and EGG, interact with Randomized Smoothing (RS) and Double Sampling RS (DSRS). It derives an analytic ESG-certified radius formula that aligns with Gaussian-based certs in high dimensions and shows ESG is largely agnostic to the exponent $\eta$, while introducing EGG and demonstrating potential DSRS improvements via concentration-based analysis, yielding tighter $\ell_2$ lower bounds when $\eta\in(0,2]$. Under a concentration framework, EGG can achieve $\Omega(d^{1/\eta})$ bounds (and hence $\Omega(\sqrt{d})$ for small $\eta$), suggesting a path to mitigating the curse of dimensionality in RS, with experiments reporting up to 6.4% gain in certified accuracy on ImageNet. Overall, ESG extends the set of smoothing distributions without sacrificing certification, and EGG provides a mechanism to enhance DSRS performance in high dimensions, contingent on classifier concentration properties.
Abstract
Randomized Smoothing (RS) is currently a scalable certified defense method providing robustness certification against adversarial examples. Although significant progress has been achieved in providing defenses against $\ell_p$ adversaries, the interaction between the smoothing distribution and the robustness certification still remains vague. In this work, we comprehensively study the effect of two families of distributions, named Exponential Standard Gaussian (ESG) and Exponential General Gaussian (EGG) distributions, on Randomized Smoothing and Double Sampling Randomized Smoothing (DSRS). We derive an analytic formula for ESG's certified radius, which converges to the origin formula of RS as the dimension $d$ increases. Additionally, we prove that EGG can provide tighter constant factors than DSRS in providing $Ω(\sqrt{d})$ lower bounds of $\ell_2$ certified radius, and thus further addresses the curse of dimensionality in RS. Our experiments on real-world datasets confirm our theoretical analysis of the ESG distributions, that they provide almost the same certification under different exponents $η$ for both RS and DSRS. In addition, EGG brings a significant improvement to the DSRS certification, but the mechanism can be different when the classifier properties are different. Compared to the primitive DSRS, the increase in certified accuracy provided by EGG is prominent, up to 6.4% on ImageNet.
