{"url":"/method/denoised-smoothing","slug":"denoised-smoothing","name":"Denoised Smoothing","full_name":"Denoised Smoothing","full_name_withheld":false,"description_markdown":"**Denoised Smoothing** is a method for obtaining a provably robust classifier from a fixed pretrained one, without any additional training or fine-tuning of the latter. The basic idea is to prepend a custom-trained denoiser before the pretrained classifier, and then apply randomized smoothing. Randomized smoothing is a certified defense that converts any given classifier $f$ into a new smoothed classifier $g$ that is characterized by a non-linear Lipschitz property. When queried at a point $x$, the smoothed classifier $g$ outputs the class that is most likely to be returned by $f$ under isotropic Gaussian perturbations of its inputs. Unfortunately, randomized smoothing requires that the underlying classifier $f$ is robust to relatively large random Gaussian perturbations of the input, which is not the case for off-the-shelf pretrained models. By applying our custom-trained denoiser to the classifier $f$, we can effectively make $f$ robust to such Gaussian perturbations, thereby making it “suitable” for randomized smoothing.","description_state":"present","introduced_year":null,"introduced_by":{"title":"Denoised Smoothing: A Provable Defense for Pretrained Classifiers","paper":"/paper/black-box-smoothing-a-provable-defense-for","first_author":"Hadi Salman","n_authors":5,"url_abs":null,"archive_paper_url":"https://paperswithcode.com/paper/black-box-smoothing-a-provable-defense-for"},"source":{"url":"https://arxiv.org/abs/2003.01908v2","title":"Denoised Smoothing: A Provable Defense for Pretrained Classifiers","url_on_a_paper_host":true},"code_snippet_url":null,"code_snippet_url_on_a_code_host":false,"categories":[{"area":"General","area_id":"general","collection":"Robustness Methods","url":"/methods/category/robustness-methods","pwc_aliases":[]}],"n_papers_tagged":8,"archive_num_papers":8,"papers_newest_first":[{"paper":null,"title":"Beyond Classification: Evaluating Diffusion Denoised Smoothing for Security-Utility Trade off","date":"2025-05-21","arxiv_id":"2505.15594","n_code_links":0,"syntology":null},{"paper":"/paper/confidence-aware-denoised-fine-tuning-of-off","title":"Confidence-aware Denoised Fine-tuning of Off-the-shelf Models for Certified Robustness","date":"2024-11-13","arxiv_id":"2411.08933","n_code_links":1,"syntology":null},{"paper":"/paper/advancing-the-robustness-of-large-language","title":"Advancing the Robustness of Large Language Models through Self-Denoised Smoothing","date":"2024-04-18","arxiv_id":"2404.12274","n_code_links":1,"syntology":{"ran":4,"of":4,"unverified":0,"pointer_only":4}},{"paper":null,"title":"Certified Zeroth-order Black-Box Defense with Robust UNet Denoiser","date":"2023-04-13","arxiv_id":"2304.06430","n_code_links":0,"syntology":null},{"paper":"/paper/certified-adversarial-robustness-for-free","title":"(Certified!!) Adversarial Robustness for Free!","date":"2022-06-21","arxiv_id":"2206.10550","n_code_links":3,"syntology":{"ran":14,"of":34,"unverified":20,"pointer_only":0}},{"paper":"/paper/how-to-robustify-black-box-ml-models-a-zeroth-1","title":"How to Robustify Black-Box ML Models? A Zeroth-Order Optimization Perspective","date":"2022-03-27","arxiv_id":"2203.14195","n_code_links":1,"syntology":{"ran":0,"of":1,"unverified":1,"pointer_only":0}},{"paper":"/paper/poisoned-classifiers-are-not-only-backdoored-1","title":"Poisoned classifiers are not only backdoored, they are fundamentally broken","date":"2020-10-18","arxiv_id":"2010.09080","n_code_links":1,"syntology":{"ran":2,"of":6,"unverified":4,"pointer_only":0}},{"paper":"/paper/black-box-smoothing-a-provable-defense-for","title":"Denoised Smoothing: A Provable Defense for Pretrained Classifiers","date":"2020-03-04","arxiv_id":"2003.01908","n_code_links":4,"syntology":{"ran":1,"of":4,"unverified":3,"pointer_only":0}}],"papers_shown":8,"tasks":[{"task":"/task/adversarial-robustness","name":"Adversarial Robustness","papers":4},{"task":"/task/denoising","name":"Denoising","papers":3},{"task":"/task/image-classification","name":"Image Classification","papers":2},{"task":"/task/image-reconstruction","name":"Image Reconstruction","papers":2},{"task":"/task/image-classification","name":"image-classification","papers":2},{"task":"/task/adversarial-attack","name":"Adversarial Attack","papers":1},{"task":"/task/classification","name":"General Classification","papers":1},{"task":"/task/hallucination","name":"Hallucination","papers":1},{"task":"/task/robust-classification","name":"Robust classification","papers":1}],"tasks_shown":9,"n_tasks":9,"usage_by_year":[{"year":"2020","papers":2},{"year":"2022","papers":2},{"year":"2023","papers":1},{"year":"2024","papers":2},{"year":"2025","papers":1}],"row_source":"methods_table","archive":{"source":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","archive_url":"https://paperswithcode.com/method/denoised-smoothing"},"syntology_read_at":"2026-09-24T18:15:14+00:00"}