Certified Patch Robustness via Smoothed Vision Transformers

IEEE Conference on Computer Vision and Pattern Recognition(2022)

引用 50|浏览139
暂无评分
摘要
Certified patch defenses can guarantee robustness of an image classifier to arbitrary changes within a bounded contiguous region. But, currently, this robustness comes at a cost of degraded standard accuracies and slower inference times. We demonstrate how using vision transformers enables significantly better certified patch robustness that is also more computationally efficient and does not incur a substantial drop in standard accuracy. These improvements stem from the inherent ability of the vision transformer to gracefully handle largely masked images. 1 1 Our code is available at https://github.com/MadryLab/smoothed-vit..
更多
查看译文
关键词
Adversarial attack and defense
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要