{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/method/randomized-smoothing/papers/2","list_of":"/method/randomized-smoothing","method":"Randomized Smoothing","archive":{"snapshot":"2025-07-28"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"date (newest first), then slug","page":2,"pages_in_order":2,"rows_per_page":100,"rows":[101,147],"of":147,"counts":{"archive_papers_tagged":147,"with_a_code_link":67,"where_syntology_ran_a_sample":33,"not_listed_spam_title":0,"listed":147,"listed_where_code_ran":33,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":27,"every_run_a_failure_of_syntologys_instrument":6,"listed_with_a_run_with_no_instrument_failure":27,"listed_every_run_a_failure_of_syntologys_instrument":6,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/method/randomized-smoothing","prev":"/method/randomized-smoothing","next":null,"papers":[{"paper":"/paper/generating-adversarial-computer-programs-1","slug":"generating-adversarial-computer-programs-1","title":"Generating Adversarial Computer Programs using Optimized Obfuscations","date":"2021-03-18","arxiv_id":"2103.11882","n_code_links":1,"syntology":null},{"paper":"/paper/improved-deterministic-smoothing-for-l1","slug":"improved-deterministic-smoothing-for-l1","title":"Improved, Deterministic Smoothing for L_1 Certified Robustness","date":"2021-03-17","arxiv_id":"2103.10834","n_code_links":1,"syntology":{"ran":1,"of":2,"n_ran_checked":1,"n_instrument":0,"unverified":1,"pointer_only":2,"phrase":"1 ran (of which 1 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified; the one sample that ran constructed an object rather than computing a result","official":{"repos":["alevine0/smoothingSplittingNoise"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":1,"n_ran_no_instrument_failure":1,"n_unverified":1,"ran_from_kinds":["official"]}}},{"paper":null,"slug":"insta-rs-instance-wise-randomized-smoothing","title":"Insta-RS: Instance-wise Randomized Smoothing for Improved Robustness and Accuracy","date":"2021-03-07","arxiv_id":"2103.04436","n_code_links":0,"syntology":null},{"paper":null,"slug":"pointguard-provably-robust-3d-point-cloud","title":"PointGuard: Provably Robust 3D Point Cloud Classification","date":"2021-03-04","arxiv_id":"2103.03046","n_code_links":0,"syntology":null},{"paper":"/paper/adversarially-robust-classifier-with","slug":"adversarially-robust-classifier-with","title":"Towards Bridging the gap between Empirical and Certified Robustness against Adversarial Examples","date":"2021-02-09","arxiv_id":"2102.05096","n_code_links":0,"syntology":{"ran":1,"of":4,"n_ran_checked":0,"n_instrument":1,"unverified":3,"pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 3 unverified","official":null}},{"paper":null,"slug":"concentration-of-non-isotropic-random-tensors","title":"Concentration of Non-Isotropic Random Tensors with Applications to Learning and Empirical Risk Minimization","date":"2021-02-04","arxiv_id":"2102.04259","n_code_links":0,"syntology":null},{"paper":null,"slug":"study-of-pre-processing-defenses-against","title":"Study of Pre-processing Defenses against Adversarial Attacks on State-of-the-art Speaker Recognition Systems","date":"2021-01-22","arxiv_id":"2101.08909","n_code_links":0,"syntology":null},{"paper":null,"slug":"on-provable-backdoor-defense-in-collaborative","title":"On Provable Backdoor Defense in Collaborative Learning","date":"2021-01-19","arxiv_id":"2101.08177","n_code_links":0,"syntology":null},{"paper":null,"slug":"certified-watermarks-for-neural-networks","title":"Certified Watermarks for Neural Networks","date":"2021-01-01","arxiv_id":null,"n_code_links":0,"syntology":null},{"paper":null,"slug":"efficient-randomized-smoothing-by-denoising","title":"Efficient randomized smoothing by denoising with learned score function","date":"2021-01-01","arxiv_id":null,"n_code_links":0,"syntology":null},{"paper":null,"slug":"data-dependent-randomized-smoothing","title":"Data-Dependent Randomized Smoothing","date":"2020-12-08","arxiv_id":"2012.04351","n_code_links":0,"syntology":null},{"paper":null,"slug":"a-simple-and-efficient-smoothing-method-for","title":"A Simple and Efficient Smoothing Method for Faster Optimization and Local Exploration","date":"2020-12-01","arxiv_id":null,"n_code_links":0,"syntology":null},{"paper":"/paper/tight-second-order-certificates-for-1","slug":"tight-second-order-certificates-for-1","title":"Tight Second-Order Certificates for Randomized Smoothing","date":"2020-10-20","arxiv_id":"2010.10549","n_code_links":1,"syntology":null},{"paper":null,"slug":"higher-order-certification-for-randomized","title":"Higher-Order Certification for Randomized Smoothing","date":"2020-10-13","arxiv_id":"2010.06651","n_code_links":0,"syntology":null},{"paper":"/paper/efficient-robust-training-via-backward-1","slug":"efficient-robust-training-via-backward-1","title":"Efficient Robust Training via Backward Smoothing","date":"2020-10-03","arxiv_id":"2010.01278","n_code_links":1,"syntology":null},{"paper":null,"slug":"interpreting-robust-optimization-via-1","title":"Interpreting Robust Optimization via Adversarial Influence Functions","date":"2020-10-03","arxiv_id":"2010.01247","n_code_links":0,"syntology":null},{"paper":null,"slug":"a-game-theoretic-analysis-of-additive","title":"A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses","date":"2020-09-14","arxiv_id":"2009.06530","n_code_links":0,"syntology":null},{"paper":"/paper/efficient-robustness-certificates-for-1","slug":"efficient-robustness-certificates-for-1","title":"Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and More","date":"2020-08-29","arxiv_id":"2008.12952","n_code_links":1,"syntology":null},{"paper":null,"slug":"scalable-inference-of-symbolic-adversarial","title":"Provably Robust Adversarial Examples","date":"2020-07-23","arxiv_id":"2007.12133","n_code_links":0,"syntology":null},{"paper":"/paper/defense-against-adversarial-attacks-in-nlp","slug":"defense-against-adversarial-attacks-in-nlp","title":"Defense against Adversarial Attacks in NLP via Dirichlet Neighborhood Ensemble","date":"2020-06-20","arxiv_id":"2006.11627","n_code_links":1,"syntology":null},{"paper":"/paper/backdoor-attacks-to-graph-neural-networks","slug":"backdoor-attacks-to-graph-neural-networks","title":"Backdoor Attacks to Graph Neural Networks","date":"2020-06-19","arxiv_id":"2006.11165","n_code_links":2,"syntology":{"ran":3,"of":3,"n_ran_checked":2,"n_instrument":1,"unverified":0,"pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","official":{"repos":["zaixizhang/graphbackdoor"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":0,"ran_from_kinds":["official"]}}},{"paper":"/paper/consistency-regularization-for-certified","slug":"consistency-regularization-for-certified","title":"Consistency Regularization for Certified Robustness of Smoothed Classifiers","date":"2020-06-07","arxiv_id":"2006.04062","n_code_links":1,"syntology":{"ran":5,"of":6,"n_ran_checked":4,"n_instrument":1,"unverified":1,"pointer_only":2,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 0 violated, 4 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","official":{"repos":["jh-jeong/smoothing-consistency"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":1,"ran_from_kinds":["official"]}}},{"paper":null,"slug":"extensions-and-limitations-of-randomized","title":"Extensions and limitations of randomized smoothing for robustness guarantees","date":"2020-06-07","arxiv_id":"2006.04208","n_code_links":0,"syntology":null},{"paper":"/paper/safer-a-structure-free-approach-for-certified","slug":"safer-a-structure-free-approach-for-certified","title":"SAFER: A Structure-free Approach for Certified Robustness to Adversarial Word Substitutions","date":"2020-05-29","arxiv_id":"2005.14424","n_code_links":1,"syntology":{"ran":1,"of":2,"n_ran_checked":1,"n_instrument":0,"unverified":1,"pointer_only":2,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified","official":{"repos":["lushleaf/Structure-free-certified-NLP"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":1,"ran_from_kinds":["official"]}}},{"paper":null,"slug":"towards-assessment-of-randomized-mechanisms","title":"Towards Assessment of Randomized Smoothing Mechanisms for Certifying Adversarial Robustness","date":"2020-05-15","arxiv_id":"2005.07347","n_code_links":0,"syntology":null},{"paper":null,"slug":"channel-aware-adversarial-attacks-against","title":"Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers","date":"2020-05-11","arxiv_id":"2005.05321","n_code_links":0,"syntology":null},{"paper":null,"slug":"provable-robust-classification-via-learned","title":"Provable Robust Classification via Learned Smoothed Densities","date":"2020-05-09","arxiv_id":"2005.04504","n_code_links":0,"syntology":null},{"paper":null,"slug":"a-framework-for-robustness-certification-of","title":"A FRAMEWORK FOR ROBUSTNESS CERTIFICATION OF SMOOTHED CLASSIFIERS USING F-DIVERGENCES","date":"2020-05-01","arxiv_id":null,"n_code_links":0,"syntology":null},{"paper":"/paper/rab-provable-robustness-against-backdoor","slug":"rab-provable-robustness-against-backdoor","title":"RAB: Provable Robustness Against Backdoor Attacks","date":"2020-03-19","arxiv_id":"2003.08904","n_code_links":1,"syntology":null},{"paper":null,"slug":"analyzing-accuracy-loss-in-randomized","title":"Analyzing Accuracy Loss in Randomized Smoothing Defenses","date":"2020-03-03","arxiv_id":"2003.01595","n_code_links":0,"syntology":null},{"paper":null,"slug":"rethinking-randomized-smoothing-for","title":"Hidden Cost of Randomized Smoothing","date":"2020-03-02","arxiv_id":"2003.01249","n_code_links":0,"syntology":null},{"paper":"/paper/certification-of-semantic-perturbations-via","slug":"certification-of-semantic-perturbations-via","title":"Certified Defense to Image Transformations via Randomized Smoothing","date":"2020-02-27","arxiv_id":"2002.12463","n_code_links":1,"syntology":{"ran":1,"of":1,"n_ran_checked":1,"n_instrument":0,"unverified":0,"pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","official":{"repos":["eth-sri/transformation-smoothing"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"paper":"/paper/provable-robust-learning-based-on","slug":"provable-robust-learning-based-on","title":"TSS: Transformation-Specific Smoothing for Robustness Certification","date":"2020-02-27","arxiv_id":"2002.12398","n_code_links":1,"syntology":null},{"paper":null,"slug":"on-certifying-robustness-against-backdoor","title":"On Certifying Robustness against Backdoor Attacks via Randomized Smoothing","date":"2020-02-26","arxiv_id":"2002.11750","n_code_links":0,"syntology":null},{"paper":"/paper/derandomized-smoothing-for-certifiable","slug":"derandomized-smoothing-for-certifiable","title":"(De)Randomized Smoothing for Certifiable Defense against Patch Attacks","date":"2020-02-25","arxiv_id":"2002.10733","n_code_links":1,"syntology":null},{"paper":null,"slug":"black-box-certification-with-randomized","title":"Black-Box Certification with Randomized Smoothing: A Functional Optimization Based Framework","date":"2020-02-21","arxiv_id":"2002.09169","n_code_links":0,"syntology":null},{"paper":"/paper/randomized-smoothing-of-all-shapes-and-sizes","slug":"randomized-smoothing-of-all-shapes-and-sizes","title":"Randomized Smoothing of All Shapes and Sizes","date":"2020-02-19","arxiv_id":"2002.08118","n_code_links":1,"syntology":null},{"paper":null,"slug":"individual-fairness-revisited-transferring","title":"Individual Fairness Revisited: Transferring Techniques from Adversarial Robustness","date":"2020-02-18","arxiv_id":"2002.07738","n_code_links":0,"syntology":null},{"paper":null,"slug":"certified-robustness-to-label-flipping","title":"Certified Robustness to Label-Flipping Attacks via Randomized Smoothing","date":"2020-02-07","arxiv_id":"2002.03018","n_code_links":0,"syntology":null},{"paper":"/paper/macer-attack-free-and-scalable-robust-1","slug":"macer-attack-free-and-scalable-robust-1","title":"MACER: Attack-free and Scalable Robust Training via Maximizing Certified Radius","date":"2020-01-08","arxiv_id":"2001.02378","n_code_links":2,"syntology":{"ran":0,"of":1,"n_ran_checked":0,"n_instrument":0,"unverified":1,"pointer_only":1,"phrase":"0 ran · 1 unverified","official":{"repos":["RuntianZ/macer"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"paper":"/paper/certified-robustness-for-top-k-predictions-1","slug":"certified-robustness-for-top-k-predictions-1","title":"Certified Robustness for Top-k Predictions against Adversarial Perturbations via Randomized Smoothing","date":"2019-12-20","arxiv_id":"1912.09899","n_code_links":1,"syntology":null},{"paper":"/paper/smoothed-inference-for-adversarially-trained","slug":"smoothed-inference-for-adversarially-trained","title":"Smoothed Inference for Adversarially-Trained Models","date":"2019-11-17","arxiv_id":"1911.07198","n_code_links":2,"syntology":null},{"paper":null,"slug":"wasserstein-smoothing-certified-robustness","title":"Wasserstein Smoothing: Certified Robustness against Wasserstein Adversarial Attacks","date":"2019-10-23","arxiv_id":"1910.10783","n_code_links":0,"syntology":null},{"paper":null,"slug":"a-unified-framework-for-randomized-smoothing","title":"A Unified framework for randomized smoothing based certified defenses","date":"2019-09-25","arxiv_id":null,"n_code_links":0,"syntology":null},{"paper":null,"slug":"filling-the-soap-bubbles-efficient-black-box","title":"Filling the Soap Bubbles: Efficient Black-Box Adversarial Certification with Non-Gaussian Smoothing","date":"2019-09-25","arxiv_id":null,"n_code_links":0,"syntology":null},{"paper":"/paper/provably-robust-deep-learning-via","slug":"provably-robust-deep-learning-via","title":"Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers","date":"2019-06-09","arxiv_id":"1906.04584","n_code_links":3,"syntology":{"ran":2,"of":3,"n_ran_checked":1,"n_instrument":1,"unverified":1,"pointer_only":2,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","official":{"repos":["Hadisalman/smoothing-adversarial"],"state":"community repositories only","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["listed"]}}},{"paper":"/paper/certified-adversarial-robustness-via","slug":"certified-adversarial-robustness-via","title":"Certified Adversarial Robustness via Randomized Smoothing","date":"2019-02-08","arxiv_id":"1902.02918","n_code_links":12,"syntology":null}],"record_sha256":"410fe8461b8696e62c2fc44016dcda4393c4a3ec6987fab95adde1d3bdecc0db","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}