{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/randomized-smoothing-of-all-shapes-and-sizes","title":"Randomized Smoothing of All Shapes and Sizes","arxiv_id":"2002.08118","date":"2020-02-19","proceeding":"ICML 2020 1","authors":["Greg Yang","Tony Duan","J. Edward Hu","Hadi Salman","Ilya Razenshteyn","Jerry Li"],"abstract":"Randomized smoothing is the current state-of-the-art defense with provable robustness against $\\ell_2$ adversarial attacks. Many works have devised new randomized smoothing schemes for other metrics, such as $\\ell_1$ or $\\ell_\\infty$; however, substantial effort was needed to derive such new guarantees. This begs the question: can we find a general theory for randomized smoothing? We propose a novel framework for devising and analyzing randomized smoothing schemes, and validate its effectiveness in practice. Our theoretical contributions are: (1) we show that for an appropriate notion of \"optimal\", the optimal smoothing distributions for any \"nice\" norms have level sets given by the norm's *Wulff Crystal*; (2) we propose two novel and complementary methods for deriving provably robust radii for any smoothing distribution; and, (3) we show fundamental limits to current randomized smoothing techniques via the theory of *Banach space cotypes*. By combining (1) and (2), we significantly improve the state-of-the-art certified accuracy in $\\ell_1$ on standard datasets. Meanwhile, we show using (3) that with only label statistics under random input perturbations, randomized smoothing cannot achieve nontrivial certified accuracy against perturbations of $\\ell_p$-norm $\\Omega(\\min(1, d^{\\frac{1}{p} - \\frac{1}{2}}))$, when the input dimension $d$ is large. We provide code in github.com/tonyduan/rs4a.","url_abs":"https://arxiv.org/abs/2002.08118v5","url_pdf":"https://arxiv.org/pdf/2002.08118v5.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"randomized-smoothing-of-all-shapes-and-sizes","repo_url":"https://github.com/tonyduan/rs4a","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"all","task_name":"All"}],"methods":[{"method_slug":"randomized-smoothing","method_name":"Randomized Smoothing"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2002.08118","atlas_url":"https://app.syntology.ai/?focus=2002.08118","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}