Theoretical analysis demonstrates optimal sample complexity for certified defense in neural network classifiers, highlighting reduced computational costs during statistical estimation.
Key Points
Optimal sample complexity for certified adversarial robustness is achieved through confidence sequences, and the procedure matches standard statistical guarantees.
Standard requirements of 10^5 forward passes per certified point are reduced significantly, while randomized confidence intervals produce strictly stronger certificates.
Statistical estimation framework employing confidence sequences evaluates robustness radii, which may enable scalable certification against adversarial attacks.