0

Certified Patch Robustness via Smoothed Vision Transformers

Vision transformers provide improved certified patch robustness for image classifiers with reduced computational cost and minimal standard accuracy loss.

Year
2021
Venue
certified-patch-robustness-via-smoothed
Authors
4
Hosting
Abstract onlyARXIV-DEFAULT

Cite

Notes

Only stored in your browser.

Attribution

Abstract & full text
arxiv.org/abs/2110.07719ARXIV-DEFAULT
TL;DR
Semantic Scholar
Attribution policy →

Abstract

Certified patch defenses can guarantee robustness of an image classifier to arbitrary changes within a bounded contiguous region. But, currently, this robustness comes at a cost of degraded standard accuracies and slower inference times. We demonstrate how using vision transformers enables significantly better certified patch robustness that is also more computationally efficient and does not incur a substantial drop in standard accuracy. These improvements stem from the inherent ability of the vision transformer to gracefully handle largely masked images. Our code is available at https://github.com/MadryLab/smoothed-vit.

Authors

4