Methods › General › Robustness Methods › Denoised Smoothing

Denoised Smoothing

8 papers tagged archive 2025-07-28

Introduced by Hadi Salman et al. in Denoised Smoothing: A Provable Defense for Pretrained Classifiers

archive 2025-07-28 Description, source and code snippet are the archive's method entry.

Denoised Smoothing is a method for obtaining a provably robust classifier from a fixed pretrained one, without any additional training or fine-tuning of the latter. The basic idea is to prepend a custom-trained denoiser before the pretrained classifier, and then apply randomized smoothing. Randomized smoothing is a certified defense that converts any given classifier f into a new smoothed classifier g that is characterized by a non-linear Lipschitz property. When queried at a point x, the smoothed classifier g outputs the class that is most likely to be returned by f under isotropic Gaussian perturbations of its inputs. Unfortunately, randomized smoothing requires that the underlying classifier f is robust to relatively large random Gaussian perturbations of the input, which is not the case for off-the-shelf pretrained models. By applying our custom-trained denoiser to the classifier f, we can effectively make f robust to such Gaussian perturbations, thereby making it “suitable” for randomized smoothing.

PaperSource

Papers archive 2025-07-28

8 shown of 8, newest first. Repository counts are the archive's code-links table. A Syntology line states what Syntology ran from that paper's harvested code; it is per sample and not a correctness claim.

Tasks archive 2025-07-28

9 tasks the archive attaches to papers tagged with this method, by distinct papers. A task without a page in the catalog is plain text.

TaskPapers
Adversarial Robustness4
Denoising3
Image Classification2
Image Reconstruction2
image-classification2
Adversarial Attack1
General Classification1
Hallucination1
Robust classification1

Usage over time archive 2025-07-28

Papers per year tagged with Denoised Smoothing: 2020 to 2025, peak 2 2 0 2020: 2 papers 2020 2021: 0 papers 2021 2022: 2 papers 2022 2023: 1 paper 2023 2024: 2 papers 2024 2025: 1 paper 2025
Papers per year the archive tags with this method, by the paper's archive date (8 dated). Bars are counts, not a trend claim.

Components: the archive holds no method-to-method composition, so PwC's Components table cannot be rebuilt; the Papers list carries no Results column for the same reason (the archive does not join its leaderboard rows to method tags).

Categories archive 2025-07-28

Robustness Methods

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections