Papers › Certified Adversarial Robustness via Randomized Smoothing

Certified Adversarial Robustness via Randomized Smoothing

8 Feb 2019arXiv:1902.02918archive 2025-07-28

Jeremy M Cohen, Elan Rosenfeld, J. Zico Kolter

We show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the ℓ₂ norm. This "randomized smoothing" technique has been proposed recently in the literature, but existing guarantees are loose. We prove a tight robustness guarantee in ℓ₂ norm for smoothing with Gaussian noise. We use randomized smoothing to obtain an ImageNet classifier with e.g. a certified top-1 accuracy of 49% under adversarial perturbations with ℓ₂ norm less than 0.5 (=127/255). No certified defense has been shown feasible on ImageNet except for smoothing. On smaller-scale datasets where competing approaches to certified ℓ₂ robustness are viable, smoothing delivers higher certified accuracies. Our strong empirical results suggest that randomized smoothing is a promising direction for future research into adversarially robust classification. Code and models are available at http://github.com/locuslab/smoothing.

PaperPDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

locuslab/smoothing officialmentioned in papermentioned on GitHubpytorch report
RaphaelOlivier/gard_eval2_public mentioned on GitHubpytorch report
alevine0/smoothingGenGaussian mentioned on GitHubpytorchNOASSERTION report
aounon/distributional-robustness mentioned on GitHubpytorch report
blaisedelattre/bridging_the_gap_rs mentioned on GitHubpytorchMIT report
jayjaynandy/RBF-CNN mentioned on GitHubtf report
llylly/dsrs mentioned on GitHubpytorchBSD-3-Clause report
mwojnars/nifty mentioned on GitHubtfGPL-3.0 report
sayakpaul/Denoised-Smoothing-TF mentioned on GitHubtfMIT report
xzh0u/randomized-smoothing mentioned on GitHubpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial DefenseAdversarial RobustnessRobust classification

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Methods

Introduced by this paper: Randomized Smoothing

Randomized Smoothing

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections