arXiv

RRISE: Robust Radius Inference via a Surrogate Estimator

Title: RRISE: Achieving Robust Radius Inference Through a Surrogate Estimator

Abstract: While randomized smoothing (RS) offers architecture-independent guarantees for $\ell_2$ classification robustness via smoothed classifiers, its reliance on per-input Monte Carlo (MC) sampling hinders applicability in real-time environments. We posit that this computational burden is structural, not fundamental, and can be substantially mitigated by leveraging shared information throughout the deployment pipeline. To address this, we present RRISE, an RS framework that streamlines the certification process into a single forward pass using a learned surrogate model. This surrogate is trained against precomputed MC class-count targets using a soft-label cross-entropy loss, and its outputs are transformed into provably conservative certified radii via a one-time conformal calibration procedure. The resulting certification is verifiable at deployment: if the calibrated radius is positive, the surrogate’s prediction is guaranteed to align with that of the smoothed classifier, which remains constant within a ball of that radius surrounding the input. Empirical results on image classification benchmarks demonstrate that RRISE achieves certified accuracy within 0.84 percentage points of fixed-budget MC methods. It replaces up to $10^4$ noisy base-model evaluations per query with a single surrogate pass, recovering the initial training cost after approximately $10^5$ deployment queries. Furthermore, on CIFAR-100 and Tiny ImageNet—datasets where existing offline-surrogate approaches fail—RRISE delivers 1.23 to $1.91\times$ higher certified accuracy, positioning efficient randomized smoothing as a viable route to certified robustness in repeated-deployment scenarios.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...