The Geometry of Randomized Smoothing on Feasible Sets
Organizations: Technische Universität Wien · NeverBlink · Technische Universität Wien Universitat Pompeu Fabra
Abstract
Randomized smoothing certifies the probability of a fixed output event as the center of Gaussian noise moves. Feasibility or confidence filtering reports label probabilities only among retained proposals, producing a ratio. Its numerator is a fixed Gaussian event mass, while its denominator is the probability of retention and can change with the center. Substituting this ratio into the ordinary smoothing formula can therefore certify a ball that contains a decision boundary. We separate the problem into a geometric question and a certification question. Geometry determines when conditioning preserves Gaussian comparisons. Convex retained sets preserve the full comparison, while general sets require geometric control of the retained law as the center moves. Without such control, conditional probabilities imply no positive universal radius. Joint retention-and-label probabilities always yield a valid certificate for the same filtered predictor. A uniform covariance bound transfers divergence certificates to the retained law and can yield larger radii even when the Gaussian event comparison fails. Both methods admit finite-sample bounds. For a learned image classifier with a training-selected nonconvex filter, conditional Rényi bounds certify more images than joint-mass bounds without additional model evaluations. A released confidence filter exhibits verified label changes inside radii obtained by conditional substitution. An application of adaptive Gaussian composition covers causal finite-horizon executions with history-dependent center shifts under a pathwise energy bound.
Figures & tables
Appendix figures & tables14 assets
Supplementary material from the paper’s appendix.
Appendix
| Ctrl | Proposals | Safe | Goal | Timeout | Cost | Shift safe | |||
|---|---|---|---|---|---|---|---|---|---|
| C1 | one | 211 | 78 | 133 | 45 | 213 | |||
| C1 | four | 210 | 85 | 125 | 46 | 214 | |||
| C2 | one | 187 | 60 | 127 | 69 | 180 | |||
| C2 | four | 189 | 59 | 130 | 67 | 187 | |||
| C3 | one | 205 | 107 | 98 | 51 | 204 | |||
| C3 | four | 207 | 106 | 101 | 49 | 202 |
| Current result | Used here | Established here |
|---|---|---|
| Occupancy divergences | Fixed-support Rényi log-partition identities and truncated-family KL and skew-Jensen identities ( Nielsen and Nock, 2011 ; Nielsen, 2022 ) | Gaussian occupancy specialization followed by the equivalence between concave log occupancy and the stated ordered-pair KL and positive-order Rényi rates |
| Covariance control | Log-normalizer differentiation supplies standard moment and Fisher identities | Their specialization gives the finite-path KL integral, local Rényi rate, and top-covariance diagnostic used here |
| Corollary 2 | Strongly log-concave tradeoff comparison of Gopi et al. (2022, Theorem 13) | Intrinsic affine-hull specialization with displacement scale |
| Proposition 3 | Neyman–Pearson ordering for the monotone likelihood ratio between two conditioned Gaussian centers | Necessary and sufficient projected-mass inequalities for every measurable retained event under an arbitrary fixed set |
| Theorem 7 and Algorithm 1 | Joint selected-label and selected-or-rejection masses ( Sheikholeslami et al., 2022 , Theorem 3.1) | Explicit competitor bounds and their simultaneous combination with the rejection-complement bound for arbitrary fixed filters |
| Limits of conditional votes | The cited joint-event certificate does not provide a radius from conditional votes alone | Sharpness of the joint-mass radius and the support-free conditional-only impossibility result |
| Calculation | Positive | Median | |||
|---|---|---|---|---|---|
| Conditional substitution | |||||
| Joint complement | |||||
| Joint explicit | |||||
| Joint simultaneous | |||||
| Unfiltered Gaussian |
| Calculation | Positive | Median | |||
|---|---|---|---|---|---|
| Conditional substitution | |||||
| Joint simultaneous | |||||
| Joint complement | |||||
| Joint explicit | |||||
| Unfiltered Gaussian |
| Cohort | ID | labels | nominal | shifted | |||
|---|---|---|---|---|---|---|---|
| 3 | 174 | ||||||
| 11 | 1586 | ||||||
| 15 | 879 | ||||||
| 16 | 1060 | ||||||
| 19 | 759 | ||||||
| 37 | 215 |
| ID | labels | nominal counts | shifted counts | verified | ||
|---|---|---|---|---|---|---|
| 4924 | yes | |||||
| 5089 | yes | |||||
| 8654 | yes | |||||
| 6665 | yes | |||||
| 634 | no | |||||
| 5211 | no |
| Threshold | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| Dev | |||||||||
| Confirm | |||||||||
| Retained |
| Class | Retained | F-acc | U-acc | KL | Joint | Strong |
|---|---|---|---|---|---|---|
| airplane | ||||||
| automobile | ||||||
| bird | ||||||
| cat | ||||||
| deer | ||||||
| dog |
| Certificate | |||
|---|---|---|---|
| Conditional forward KL | |||
| Conditional reverse KL | |||
| Conditional Rényi | |||
| Joint mass | |||
| Unfiltered, original | |||
| Unfiltered, matched calls |