{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/curse-of-dimensionality-on-randomized","title":"Curse of Dimensionality on Randomized Smoothing for Certifiable Robustness","arxiv_id":"2002.03239","date":"2020-02-08","proceeding":"ICML 2020 1","authors":["Aounon Kumar","Alexander Levine","Tom Goldstein","Soheil Feizi"],"abstract":"Randomized smoothing, using just a simple isotropic Gaussian distribution, has been shown to produce good robustness guarantees against $\\ell_2$-norm bounded adversaries. In this work, we show that extending the smoothing technique to defend against other attack models can be challenging, especially in the high-dimensional regime. In particular, for a vast class of i.i.d.~smoothing distributions, we prove that the largest $\\ell_p$-radius that can be certified decreases as $O(1/d^{\\frac{1}{2} - \\frac{1}{p}})$ with dimension $d$ for $p > 2$. Notably, for $p \\geq 2$, this dependence on $d$ is no better than that of the $\\ell_p$-radius that can be certified using isotropic Gaussian smoothing, essentially putting a matching lower bound on the robustness radius. When restricted to {\\it generalized} Gaussian smoothing, these two bounds can be shown to be within a constant factor of each other in an asymptotic sense, establishing that Gaussian smoothing provides the best possible results, up to a constant factor, when $p \\geq 2$. We present experimental results on CIFAR to validate our theory. For other smoothing distributions, such as, a uniform distribution within an $\\ell_1$ or an $\\ell_\\infty$-norm ball, we show upper bounds of the form $O(1 / d)$ and $O(1 / d^{1 - \\frac{1}{p}})$ respectively, which have an even worse dependence on $d$.","url_abs":"https://arxiv.org/abs/2002.03239v2","url_pdf":"https://arxiv.org/pdf/2002.03239v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"curse-of-dimensionality-on-randomized","repo_url":"https://github.com/alevine0/smoothingGenGaussian","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"NOASSERTION"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2002.03239","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}