Skip to main content

Showing 1–2 of 2 results for author: Shpilevskiy, F

  1. arXiv:2406.10427  [pdf, other

    cs.LG cs.CR

    Adaptive Randomized Smoothing: Certifying Multi-Step Defences against Adversarial Examples

    Authors: Saiyue Lyu, Shadab Shaikh, Frederick Shpilevskiy, Evan Shelhamer, Mathias Lécuyer

    Abstract: We propose Adaptive Randomized Smoothing (ARS) to certify the predictions of our test-time adaptive models against adversarial examples. ARS extends the analysis of randomized smoothing using f-Differential Privacy to certify the adaptive composition of multiple steps. For the first time, our theory covers the sound adaptive composition of general and high-dimensional functions of noisy input. We… ▽ More

    Submitted 14 June, 2024; originally announced June 2024.

  2. arXiv:2312.14334  [pdf, other

    cs.LG cs.CR

    DP-AdamBC: Your DP-Adam Is Actually DP-SGD (Unless You Apply Bias Correction)

    Authors: Qiaoyue Tang, Frederick Shpilevskiy, Mathias Lécuyer

    Abstract: The Adam optimizer is a popular choice in contemporary deep learning, due to its strong empirical performance. However we observe that in privacy sensitive scenarios, the traditional use of Differential Privacy (DP) with the Adam optimizer leads to sub-optimal performance on several tasks. We find that this performance degradation is due to a DP bias in Adam's second moment estimator, introduced b… ▽ More

    Submitted 21 December, 2023; originally announced December 2023.

    Comments: Published as a conference paper at the 38th Annual AAAI Conference on Artificial Intelligence, Vancouver, 2024