ContRS: Generalizing Randomized Smoothing to Continuous Outputs
Abstract
Randomized smoothing certifies adversarial robustness by aggregating a base model’s predictions under injected noise. In classification, its classical formulation compares class probabilities under Gaussian perturbations to certify exact label invariance. For continuous outputs, however, model predictions can remain close without being identical, making a quantitative bound on prediction change more appropriate. Existing extensions typically rely on task-specific constructions and do not directly map a prescribed output tolerance to a certified input radius across different output types. To this end, we introduce ContRS, a new unified framework that defines the smoothed prediction as the center of an output neighborhood with maximum probability mass and recovers classical randomized smoothing as a special case. At the population level, we show that a probability margin over competing neighborhoods yields a certified radius within which the smoothed prediction changes by at most the prescribed tolerance. For metric and symmetric relaxed-triangle discrepancies, we derive finite-sample certificates using a center selected independently of the certification samples. For general discrepancies, we provide empirical robustness estimates based on sampled competitors. Across diverse continuous-output tasks, ContRS yields larger certified input radii through output-region selection at matched output-region scales and tighter output bounds at matched input budgets, with lower or comparable smoothing error compared with representative baselines.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.