acceptodds
Under review as a conference paper at ICLR 2027

Improving Randomized Smoothing Certificates Through Guiding Diffusion-based Denoisers

Abstract

This paper tackles the problem of improving certified robustness to adversarial examples in image classification. We focus on randomized smoothing, a scalable certification framework that provides provable robustness guarantees by evaluating a classifier under Gaussian perturbations of its input. While increasing the noise level can yield stronger certificates, it also substantially degrades classification accuracy. Recent diffusion-denoised smoothing methods mitigate this trade-off by denoising perturbed inputs before classification, but the denoising process is typically agnostic to the downstream classifier. In this work, we investigate how classifier-informed guidance can be used to steer diffusion denoising toward regions that are more favorable to certification. We introduce an entropy-guided diffusion smoothing method that encourages confident predictions without prescribing a target class. We further present principled theoretical framework for analyzing our method. This analysis yields sufficient conditions under which increasing the guidance strength improves class separation and, in the binary setting, provably increases the certification radius of diffusion-denoised randomized smoothing.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.