Papers › Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness

Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness

8 Feb 2020ICML 2020 1arXiv:2002.03239archive 2025-07-28

Aounon Kumar, Alexander Levine, Tom Goldstein, Soheil Feizi

Randomized smoothing, using just a simple isotropic Gaussian distribution, has been shown to produce good robustness guarantees against ℓ₂-norm bounded adversaries. In this work, we show that extending the smoothing technique to defend against other attack models can be challenging, especially in the high-dimensional regime. In particular, for a vast class of i.i.d.~smoothing distributions, we prove that the largest ℓₚ-radius that can be certified decreases as O(1/d^(1/2 - 1/p)) with dimension d for p > 2. Notably, for p ≥2, this dependence on d is no better than that of the ℓₚ-radius that can be certified using isotropic Gaussian smoothing, essentially putting a matching lower bound on the robustness radius. When restricted to {\it generalized} Gaussian smoothing, these two bounds can be shown to be within a constant factor of each other in an asymptotic sense, establishing that Gaussian smoothing provides the best possible results, up to a constant factor, when p ≥2. We present experimental results on CIFAR to validate our theory. For other smoothing distributions, such as, a uniform distribution within an ℓ₁ or an ℓ_∞-norm ball, we show upper bounds of the form O(1 / d) and O(1 / d^(1 - 1/p)) respectively, which have an even worse dependence on d.

PaperPDFConference PDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

alevine0/smoothingGenGaussian officialmentioned in papermentioned on GitHubpytorchNOASSERTION report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections