Augment then Smooth: Reconciling Differential Privacy with Certified Robustness

Published in Transactions on Machine Learning Research, 2024

Recommended citation: Jiapeng Wu, Atiyeh Ashari Ghomi, David Glukhov, Jesse C. Cresswell, Franziska Boenisch, and Nicholas Papernot. Augment then Smooth: Reconciling Differential Privacy with Certified Robustness. TMLR 2024

Differential privacy and randomized smoothing respectively provide certifiable guarantees against privacy and adversarial attacks on machine learning models, however, it is not well understood how implementing either defense impacts the other. We argue that it is possible to achieve both privacy guarantees and certified robustness simultaneously, and provide a framework for integrating certified robustness through randomized smoothing into differentially private model training.

[Paper] [PDF] [Code]