Papers › Provable Robustness Against a Union of ℓ₀ Adversarial Attacks

Provable Robustness Against a Union of ℓ₀ Adversarial Attacks

22 Feb 2023arXiv:2302.11628archive 2025-07-28

Zayd Hammoudeh, Daniel Lowd

Sparse or ℓ₀ adversarial attacks arbitrarily perturb an unknown subset of the features. ℓ₀ robustness analysis is particularly well-suited for heterogeneous (tabular) data where features have different types or scales. State-of-the-art ℓ₀ certified defenses are based on randomized smoothing and apply to evasion attacks only. This paper proposes feature partition aggregation (FPA) -- a certified defense against the union of ℓ₀ evasion, backdoor, and poisoning attacks. FPA generates its stronger robustness guarantees via an ensemble whose submodels are trained on disjoint feature sets. Compared to state-of-the-art ℓ₀ defenses, FPA is up to 3,000${\times}$ faster and provides larger median robustness guarantees (e.g., median certificates of 13 pixels over 10 for CIFAR10, 12 pixels over 10 for MNIST, 4 features over 1 for Weather, and 3 features over 1 for Ames), meaning FPA provides the additional dimensions of robustness essentially for free.

PaperPDFCode

Code

zaydh/feature-partition officialmentioned in papermentioned on GitHubpytorchMIT report
zaydh/target_identification mentioned on GitHubpytorchMIT report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Methods

Randomized SmoothingTest

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections