Does a Hybrid Space-Aware Randomized Defense Improve Empirical and Certified Adversarial Robustness?

Joy Dhar, Manish Kumar Pandey, Behzad Bozorgtabar, Nayyar Zaidi, Wenyu Zhang, Wei-Hong Li, Tingting Mu, Dwarikanath Mahapatra, Mahsa Baktashmotlagh, Trung Le, Chen Chen, Sajib Mistry, Camila Gonzalez, Samira Ebrahimi Kahou, Lina Yao, Piotr Koniusz, Robert Burns Fisher, Dinh Phung, Bohyung Han, Nuno Vasconcelos, Pietro Lio
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:24537-24575, 2026.

Abstract

We introduce Hybrid Space-aware Stochastic Convolution Attention Noise (HySCAN), a hybrid randomized defense that helps close the long-standing gap between provable robustness under $\ell$2 certificates and empirical robustness against strong $\ell$$\infty$ attacks, while maintaining strong generalization across diverse imaging benchmarks. HySCAN jointly explores complementary sources of stochasticity at both training and inference: (i) implicit weight-space randomness via stochastic-aware Random Weights, and (ii) explicit feature-space randomness via Stochastic Attention Noise Injection modules. By incorporating randomness at both the parameter and representation levels, HySCAN enables meaningful certified guarantees while improving empirical robustness in practice. Comprehensive experiments on diverse imaging datasets, e.g., CelebA, CIFAR-10, and CIFAR-100, ImageNet-1k, HAM10000, and NIH Chest X-ray, demonstrate that HySCAN outperforms existing certified and empirical defenses, improving certified robustness by up to $\approx$ 9.6% and empirical robustness by up to $\approx$ 5% without reducing clean accuracy.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-dhar26a, title = {Does a Hybrid Space-Aware Randomized Defense Improve Empirical and Certified Adversarial Robustness?}, author = {Dhar, Joy and Pandey, Manish Kumar and Bozorgtabar, Behzad and Zaidi, Nayyar and Zhang, Wenyu and Li, Wei-Hong and Mu, Tingting and Mahapatra, Dwarikanath and Baktashmotlagh, Mahsa and Le, Trung and Chen, Chen and Mistry, Sajib and Gonzalez, Camila and Kahou, Samira Ebrahimi and Yao, Lina and Koniusz, Piotr and Fisher, Robert Burns and Phung, Dinh and Han, Bohyung and Vasconcelos, Nuno and Lio, Pietro}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {24537--24575}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/dhar26a/dhar26a.pdf}, url = {https://proceedings.mlr.press/v306/dhar26a.html}, abstract = {We introduce Hybrid Space-aware Stochastic Convolution Attention Noise (HySCAN), a hybrid randomized defense that helps close the long-standing gap between provable robustness under $\ell$2 certificates and empirical robustness against strong $\ell$$\infty$ attacks, while maintaining strong generalization across diverse imaging benchmarks. HySCAN jointly explores complementary sources of stochasticity at both training and inference: (i) implicit weight-space randomness via stochastic-aware Random Weights, and (ii) explicit feature-space randomness via Stochastic Attention Noise Injection modules. By incorporating randomness at both the parameter and representation levels, HySCAN enables meaningful certified guarantees while improving empirical robustness in practice. Comprehensive experiments on diverse imaging datasets, e.g., CelebA, CIFAR-10, and CIFAR-100, ImageNet-1k, HAM10000, and NIH Chest X-ray, demonstrate that HySCAN outperforms existing certified and empirical defenses, improving certified robustness by up to $\approx$ 9.6% and empirical robustness by up to $\approx$ 5% without reducing clean accuracy.} }
Endnote
%0 Conference Paper %T Does a Hybrid Space-Aware Randomized Defense Improve Empirical and Certified Adversarial Robustness? %A Joy Dhar %A Manish Kumar Pandey %A Behzad Bozorgtabar %A Nayyar Zaidi %A Wenyu Zhang %A Wei-Hong Li %A Tingting Mu %A Dwarikanath Mahapatra %A Mahsa Baktashmotlagh %A Trung Le %A Chen Chen %A Sajib Mistry %A Camila Gonzalez %A Samira Ebrahimi Kahou %A Lina Yao %A Piotr Koniusz %A Robert Burns Fisher %A Dinh Phung %A Bohyung Han %A Nuno Vasconcelos %A Pietro Lio %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-dhar26a %I PMLR %P 24537--24575 %U https://proceedings.mlr.press/v306/dhar26a.html %V 306 %X We introduce Hybrid Space-aware Stochastic Convolution Attention Noise (HySCAN), a hybrid randomized defense that helps close the long-standing gap between provable robustness under $\ell$2 certificates and empirical robustness against strong $\ell$$\infty$ attacks, while maintaining strong generalization across diverse imaging benchmarks. HySCAN jointly explores complementary sources of stochasticity at both training and inference: (i) implicit weight-space randomness via stochastic-aware Random Weights, and (ii) explicit feature-space randomness via Stochastic Attention Noise Injection modules. By incorporating randomness at both the parameter and representation levels, HySCAN enables meaningful certified guarantees while improving empirical robustness in practice. Comprehensive experiments on diverse imaging datasets, e.g., CelebA, CIFAR-10, and CIFAR-100, ImageNet-1k, HAM10000, and NIH Chest X-ray, demonstrate that HySCAN outperforms existing certified and empirical defenses, improving certified robustness by up to $\approx$ 9.6% and empirical robustness by up to $\approx$ 5% without reducing clean accuracy.
APA
Dhar, J., Pandey, M.K., Bozorgtabar, B., Zaidi, N., Zhang, W., Li, W., Mu, T., Mahapatra, D., Baktashmotlagh, M., Le, T., Chen, C., Mistry, S., Gonzalez, C., Kahou, S.E., Yao, L., Koniusz, P., Fisher, R.B., Phung, D., Han, B., Vasconcelos, N. & Lio, P.. (2026). Does a Hybrid Space-Aware Randomized Defense Improve Empirical and Certified Adversarial Robustness?. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:24537-24575 Available from https://proceedings.mlr.press/v306/dhar26a.html.

Related Material