%PDF-1.5
%
1 0 obj
<< /Metadata 3 0 R /Pages 4 0 R /Type /Catalog >>
endobj
2 0 obj
<< /Author (Hadi Salman; Saachi Jain; Eric Wong; Aleksander Madry) /Producer (pikepdf 5.1.3) /Subject (IEEE Conference on Computer Vision and Pattern Recognition) /Title (Certified Patch Robustness via Smoothed Vision Transformers) >>
endobj
3 0 obj
<< /Subtype /XML /Type /Metadata /Length 1170 >>
stream
Certified Patch Robustness via Smoothed Vision TransformersHadi Salman Saachi Jain Eric Wong Aleksander MadryIEEE Conference on Computer Vision and Pattern Recognition
endstream
endobj
4 0 obj
<< /Count 11 /Kids [ 5 0 R 6 0 R 7 0 R 8 0 R 9 0 R 10 0 R 11 0 R 12 0 R 13 0 R 14 0 R 15 0 R ] /Type /Pages >>
endobj
5 0 obj
<< /Annots [ 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R 29 0 R 30 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R 36 0 R 37 0 R 38 0 R 39 0 R ] /Contents 40 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 41 0 R /Type /Page >>
endobj
6 0 obj
<< /Annots [ 42 0 R 43 0 R 44 0 R 45 0 R 46 0 R 47 0 R 48 0 R 49 0 R 50 0 R 51 0 R 52 0 R ] /Contents 53 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 54 0 R /Type /Page >>
endobj
7 0 obj
<< /Annots [ 55 0 R 56 0 R 57 0 R 58 0 R 59 0 R 60 0 R 61 0 R 62 0 R 63 0 R 64 0 R 65 0 R 66 0 R 67 0 R 68 0 R 69 0 R 70 0 R 71 0 R 72 0 R 73 0 R 74 0 R 75 0 R 76 0 R ] /Contents 77 0 R /Group 78 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 79 0 R /Type /Page >>
endobj
8 0 obj
<< /Annots [ 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R 85 0 R 86 0 R 87 0 R 88 0 R 89 0 R 90 0 R 91 0 R 92 0 R 93 0 R 94 0 R 95 0 R 96 0 R 97 0 R 98 0 R 99 0 R 100 0 R 101 0 R 102 0 R 103 0 R 104 0 R 105 0 R 106 0 R 107 0 R 108 0 R 109 0 R 110 0 R 111 0 R 112 0 R 113 0 R 114 0 R 115 0 R 116 0 R 117 0 R ] /Contents 118 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 119 0 R /Type /Page >>
endobj
9 0 obj
<< /Annots [ 120 0 R 121 0 R 122 0 R 123 0 R 124 0 R 125 0 R 126 0 R 127 0 R 128 0 R 129 0 R 130 0 R ] /Contents 131 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 132 0 R /Type /Page >>
endobj
10 0 obj
<< /Annots [ 133 0 R 134 0 R 135 0 R 136 0 R 137 0 R 138 0 R ] /Contents 139 0 R /Group 140 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 141 0 R /Type /Page >>
endobj
11 0 obj
<< /Annots [ 142 0 R 143 0 R 144 0 R 145 0 R 146 0 R 147 0 R 148 0 R 149 0 R 150 0 R 151 0 R 152 0 R 153 0 R 154 0 R 155 0 R 156 0 R 157 0 R 158 0 R 159 0 R 160 0 R 161 0 R 162 0 R 163 0 R 164 0 R 165 0 R 166 0 R 167 0 R 168 0 R 169 0 R 170 0 R 171 0 R 172 0 R 173 0 R 174 0 R 175 0 R 176 0 R 177 0 R 178 0 R 179 0 R 180 0 R 181 0 R ] /Contents 182 0 R /Group 183 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 184 0 R /Type /Page >>
endobj
12 0 obj
<< /Annots [ 185 0 R 186 0 R 187 0 R 188 0 R 189 0 R 190 0 R 191 0 R 192 0 R 193 0 R 194 0 R 195 0 R 196 0 R 197 0 R 198 0 R 199 0 R 200 0 R 201 0 R 202 0 R 203 0 R 204 0 R 205 0 R 206 0 R 207 0 R 208 0 R 209 0 R 210 0 R 211 0 R ] /Contents 212 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 213 0 R /Type /Page >>
endobj
13 0 obj
<< /Annots [ 214 0 R 215 0 R 216 0 R 217 0 R 218 0 R 219 0 R 220 0 R 221 0 R 222 0 R 223 0 R 224 0 R 225 0 R 226 0 R 227 0 R 228 0 R 229 0 R 230 0 R 231 0 R 232 0 R 233 0 R 234 0 R 235 0 R 236 0 R 237 0 R 238 0 R 239 0 R 240 0 R 241 0 R 242 0 R 243 0 R 244 0 R 245 0 R 246 0 R 247 0 R 248 0 R 249 0 R 250 0 R 251 0 R 252 0 R 253 0 R 254 0 R 255 0 R 256 0 R 257 0 R 258 0 R 259 0 R 260 0 R ] /Contents 261 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 262 0 R /Type /Page >>
endobj
14 0 obj
<< /Annots [ 263 0 R 264 0 R 265 0 R 266 0 R 267 0 R 268 0 R 269 0 R 270 0 R 271 0 R 272 0 R 273 0 R 274 0 R 275 0 R 276 0 R 277 0 R 278 0 R 279 0 R 280 0 R 281 0 R 282 0 R 283 0 R 284 0 R 285 0 R 286 0 R 287 0 R 288 0 R 289 0 R 290 0 R 291 0 R 292 0 R 293 0 R 294 0 R 295 0 R 296 0 R 297 0 R ] /Contents 298 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 299 0 R /Type /Page >>
endobj
15 0 obj
<< /Annots [ 300 0 R 301 0 R 302 0 R 303 0 R 304 0 R 305 0 R 306 0 R 307 0 R 308 0 R 309 0 R 310 0 R 311 0 R 312 0 R 313 0 R 314 0 R 315 0 R 316 0 R 317 0 R 318 0 R 319 0 R ] /Contents 320 0 R /MediaBox [ 0 0 612 792 ] /Parent 4 0 R /Resources 321 0 R /Type /Page >>
endobj
16 0 obj
<< /A << /D [ 5 0 R /XYZ 64.458 99.929 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 214.494 419.78 220.471 432.153 ] /Subtype /Link /Type /Annot >>
endobj
17 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 652.254 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 154.304 307.506 166.259 316.472 ] /Subtype /Link /Type /Annot >>
endobj
18 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 135.193 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 195.106 295.671 207.062 304.517 ] /Subtype /Link /Type /Annot >>
endobj
19 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 687.123 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 206.859 235.994 218.814 244.741 ] /Subtype /Link /Type /Annot >>
endobj
20 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 417.136 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 52.433 224.039 64.388 232.786 ] /Subtype /Link /Type /Annot >>
endobj
21 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 699.078 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 130.054 223.94 142.009 232.786 ] /Subtype /Link /Type /Annot >>
endobj
22 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 187.6 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 199.251 212.084 206.225 220.831 ] /Subtype /Link /Type /Annot >>
endobj
23 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 699.078 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 90.888 200.029 102.844 208.876 ] /Subtype /Link /Type /Annot >>
endobj
24 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 418.132 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 105.832 200.129 117.788 208.876 ] /Subtype /Link /Type /Annot >>
endobj
25 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 268.022 200.029 279.978 208.876 ] /Subtype /Link /Type /Annot >>
endobj
26 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 316.118 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 243.989 176.219 250.963 184.966 ] /Subtype /Link /Type /Annot >>
endobj
27 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 158.107 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 255.547 176.119 267.502 184.966 ] /Subtype /Link /Type /Annot >>
endobj
28 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 547.646 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 272.086 176.119 284.041 184.966 ] /Subtype /Link /Type /Annot >>
endobj
29 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 721.993 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 184.093 164.164 191.067 173.01 ] /Subtype /Link /Type /Annot >>
endobj
30 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 440.05 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 196.634 164.164 208.59 173.01 ] /Subtype /Link /Type /Annot >>
endobj
31 0 obj
<< /A << /S /URI /Type /Action /URI (https://github.com/MadryLab/smoothed-vit) >> /Border [ 0 0 0 ] /C [ 0 1 1 ] /H /I /Rect [ 146.857 88.241 287.358 98.326 ] /Subtype /Link /Type /Annot >>
endobj
32 0 obj
<< /A << /S /URI /Type /Action /URI (https://github.com/MadryLab/smoothed-vit) >> /Border [ 0 0 0 ] /C [ 0 1 1 ] /H /I /Rect [ 49.116 77.164 108.991 87.093 ] /Subtype /Link /Type /Annot >>
endobj
33 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 335.834 553.224 347.789 562.071 ] /Subtype /Link /Type /Annot >>
endobj
34 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 336.438 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 351.349 553.224 363.305 562.071 ] /Subtype /Link /Type /Annot >>
endobj
35 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 640.299 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 366.865 553.224 378.82 562.071 ] /Subtype /Link /Type /Annot >>
endobj
36 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 276.663 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 382.381 553.224 394.336 562.071 ] /Subtype /Link /Type /Annot >>
endobj
37 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 498.889 505.404 510.844 514.25 ] /Subtype /Link /Type /Annot >>
endobj
38 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 534.695 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 394.148 405.977 406.103 414.824 ] /Subtype /Link /Type /Annot >>
endobj
39 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 407.042 257.436 418.997 266.282 ] /Subtype /Link /Type /Annot >>
endobj
40 0 obj
<< /Length 11118 >>
stream
q
q
q
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
BT
/F86 14.3462 Tf 106.731 675.067 Td [(Certi\002ed)-250(P)10(atch)-250(Rob)20(ustness)-250(via)-250(Smoothed)-250(V)37(ision)-250(T)74(ransf)25(ormers)]TJ/F87 11.9552 Tf -36.008 -37.858 Td [(Hadi)-250(Salman)]TJ/F87 7.9701 Tf 62.094 2.577 Td [(*)]TJ/F87 11.9552 Tf -42.004 -16.525 Td [(MIT)]TJ/F89 11.9552 Tf -32.081 -13.947 Td [(hady@mit.edu)]TJ/F87 11.9552 Tf 137.174 27.895 Td [(Saachi)-250(Jain)]TJ/F87 7.9701 Tf 54.121 2.577 Td [(*)]TJ/F87 11.9552 Tf -38.017 -16.525 Td [(MIT)]TJ/F89 11.9552 Tf -42.842 -13.947 Td [(saachij@mit.edu)]TJ/F87 11.9552 Tf 163.757 27.895 Td [(Eric)-250(W)80(ong)]TJ/F87 7.9701 Tf 51.168 2.577 Td [(*)]TJ/F87 11.9552 Tf -36.541 -16.525 Td [(MIT)]TJ/F89 11.9552 Tf -46.428 -13.947 Td [(wongeric@mit.edu)]TJ/F87 11.9552 Tf 142.597 27.895 Td [(Aleksander)-250(M)-211(\b)544(adry)]TJ 33.695 -13.948 Td [(MIT)]TJ/F89 11.9552 Tf -37.163 -13.947 Td [(madry@mit.edu)]TJ
0 g 0 G
0 g 0 G
/F86 11.9552 Tf -294.258 -54.994 Td [(Abstract)]TJ/F91 9.9626 Tf -83.928 -23.91 Td [(Certi\002ed)-278(patc)15(h)-277(defenses)-278(can)-278(guar)15(antee)-277(r)45(ob)20(ustness)-278(of)-278(an)]TJ -11.955 -11.956 Td [(ima)10(g)10(e)-222(classi\002er)-222(to)-221(arbitr)15(ary)-222(c)15(hang)10(es)-222(within)-222(a)-222(bounded)-222(con-)]TJ 0 -11.955 Td [(tiguous)-348(r)37(e)40(gion.)-603(But,)-372(curr)37(ently)55(,)-373(this)-347(r)45(ob)20(ustness)-348(comes)-348(at)-348(a)]TJ 0 -11.955 Td [(cost)-274(of)-273(de)40(gr)15(aded)-274(standar)37(d)-274(accur)15(acies)-273(and)-274(slower)-274(infer)37(ence)]TJ 0 -11.955 Td [(times.)-572(W)92(e)-338(demonstr)15(ate)-337(how)-337(using)-338(vision)-337(tr)15(ansformer)10(s)-338(en-)]TJ 0 -11.955 Td [(ables)-352(signi\002cant)1(ly)-352(better)-352(certi\002ed)-351(patc)15(h)-352(r)45(ob)20(ustness)-351(that)-352(is)]TJ 0 -11.955 Td [(also)-395(mor)37(e)-395(computationally)-394(ef)18(\002cient)-395(and)-395(does)-395(not)-395(incur)-395(a)]TJ 0 -11.956 Td [(substantial)-229(dr)45(op)-230(in)-229(standar)37(d)-229(accur)15(acy)55(.)-303(These)-230(impr)45(o)10(vements)]TJ 0 -11.955 Td [(stem)-337(fr)45(om)-337(the)-337(inher)37(ent)-337(ability)-337(of)-337(the)-337(vision)-337(tr)15(ansformer)-337(to)]TJ 0 -11.955 Td [(gr)15(acefully)-250(handle)-250(lar)37(g)10(ely)-250(mask)10(ed)-250(ima)10(g)10(es.)]TJ
1 0 0 rg 1 0 0 RG
/F91 6.9738 Tf 165.378 3.615 Td [(1)]TJ
0 g 0 G
/F86 11.9552 Tf -165.378 -39.002 Td [(1.)-250(Intr)18(oduction)]TJ/F87 9.9626 Tf 11.955 -18.929 Td [(High-stak)10(es)-378(scenarios)-378(w)10(arrant)-377(the)-378(de)25(v)15(elopment)-378(of)-378(cer)20(-)]TJ -11.955 -11.955 Td [(ti\002ably)-360(rob)20(ust)-361(models)-360(that)-360(are)]TJ/F91 9.9626 Tf 126.779 0 Td [(guar)15(anteed)]TJ/F87 9.9626 Tf 49.088 0 Td [(to)-360(be)-361(rob)20(ust)-360(to)]TJ -175.867 -11.955 Td [(a)-374(set)-374(of)-375(transformations.)-682(These)-374(techniques)-374(are)-375(be)15(ginning)]TJ 0 -11.955 Td [(to)-363<026e64>-364(applications)-363(in)-364(real-w)10(orld)-363(settings,)-392(such)-363(as)-364(v)15(erify-)]TJ 0 -11.955 Td [(ing)-386(that)-386(aircraft)-386(controllers)-386(beha)20(v)15(e)-386(safely)-387(in)-386(the)-386(presence)]TJ 0 -11.956 Td [(of)-280(approaching)-280(airplanes)-279([)]TJ
0 1 0 rg 0 1 0 RG
[(19)]TJ
0 g 0 G
[(],)-288(and)-279(ensuring)-280(the)-280(stability)-280(of)]TJ 0 -11.955 Td [(automoti)25(v)15(e)-250(systems)-250(to)-250(sensor)-250(noise)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(54)]TJ
0 g 0 G
[(].)]TJ 11.955 -11.955 Td [(W)80(e)-672(study)-672(rob)20(ustness)-671(in)-672(the)-672(conte)15(xt)-672(of)-672(adv)15(ersarial)]TJ -11.955 -11.955 Td [(patches\227a)-611(broad)-611(class)-610(of)-611(arbitrary)-611(changes)-611(contained)]TJ 0 -11.955 Td [(within)-240(a)-240(small,)-242(contiguous)-239(re)15(gion.)-307(Adv)15(ersarial)-240(patches)-240(cap-)]TJ 0 -11.955 Td [(ture)-315(the)-315(essence)-315(of)-315(a)-315(range)-315(of)-315(maliciously)-315(designed)-315(ph)5(ysi-)]TJ 0 -11.956 Td [(cal)-272(objects)-272(such)-271(as)-272(adv)15(ersarial)-272(glasses)-272([)]TJ
0 1 0 rg 0 1 0 RG
[(44)]TJ
0 g 0 G
[(],)-277(stick)10(ers/graf)25<027469>]TJ 0 -11.955 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(12)]TJ
0 g 0 G
[(],)-405(and)-374(clothing)-374([)]TJ
0 1 0 rg 0 1 0 RG
[(55)]TJ
0 g 0 G
[(].)-682(Researchers)-375(ha)20(v)15(e)-374(used)-374(adv)15(ersar)20(-)]TJ 0 -11.955 Td [(ial)-327(patches)-327(to)-326(fool)-327(image)-327(classi\002ers)-327([)]TJ
0 1 0 rg 0 1 0 RG
[(4)]TJ
0 g 0 G
[(],)-346(manipulate)-327(object)]TJ 0 -11.955 Td [(detectors)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(18)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-250(24)]TJ
0 g 0 G
[(],)-250(and)-250(disrupt)-250(optical)-250<036f>25(w)-250(estimation)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(38)]TJ
0 g 0 G
[(].)]TJ 11.955 -11.955 Td [(Adv)15(ersarial)-364(patch)-363(defenses)-364(can)-363(be)-364(trick)15(y)-363(to)-364(e)25(v)25(aluate\227)]TJ -11.955 -11.955 Td [(recent)-410(w)10(ork)-410(brok)10(e)-410(se)25(v)15(eral)-410(empirical)-410(defenses)-410([)]TJ
0 1 0 rg 0 1 0 RG
[(1)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-411(16)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-410(35)]TJ
0 g 0 G
[(])]TJ 0 -11.956 Td [(with)-509(stronger)-509(adapti)25(v)15(e)-509(attacks)-508([)]TJ
0 1 0 rg 0 1 0 RG
[(6)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-509(48)]TJ
0 g 0 G
[(].)-1087(This)-509(moti)25(v)25(ated)]TJ/F91 9.9626 Tf 0 -11.955 Td [(certi\002ed)]TJ/F87 9.9626 Tf 37.243 0 Td [(defenses,)-480(which)-435(deli)25(v)15(er)-434(pro)15(v)25(ably)-434(rob)20(ust)-434(models)]TJ -37.243 -11.955 Td [(without)-372(ha)20(ving)-373(to)-372(rely)-372(on)-373(an)-372(empirical)-373(e)25(v)25(aluation.)-677(Ho)25(w-)]TJ 0 -11.955 Td [(e)25(v)15(er)40(,)-603(certi\002ed)-532(guarantees)-532(tend)-532(to)-532(be)-532(modest)-532(and)-532(come)]TJ 0 -11.955 Td [(at)-476(a)-476(cost:)-762(poor)-476(standard)-476(accurac)15(y)-477(and)-476(slo)25(wer)-476(inference)]TJ
0 g 0 G
ET
q
1 0 0 1 50.112 109.584 cm
[]0 d 0 J 0.398 w 0 0 m 94.499 0 l S
Q
BT
/F87 5.9776 Tf 60.971 101.661 Td [(*)]TJ/F87 7.9701 Tf 3.487 -1.492 Td [(Equal)-250(contrib)20(ution.)]TJ/F87 5.9776 Tf -3.487 -6.892 Td [(1)]TJ/F87 7.9701 Tf 3.487 -2.813 Td [(Our)-413(code)-414(is)-413(a)20(v)25(ailable)-413(at)]TJ
0 1 0 0 k 0 1 0 0 K
/F89 7.9701 Tf 83.396 0 Td [(https)-64(:)-64(/)-65(/)-64(github)-64(.)-65(com)-64(/)-64(MadryLab)-64(/)]TJ -97.742 -9.464 Td [(smoothed-)-62(vit)]TJ
0 g 0 G
/F87 7.9701 Tf 57.883 0 Td [(.)]TJ
0 g 0 G
0 g 0 G
0 g 0 G
/F87 9.9626 Tf 200.867 473.32 Td [(times)-307([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-308(26)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-307(56)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-307(63)]TJ
0 g 0 G
[(].)-483(F)15(or)-307(e)15(xample,)-322(a)-307(top-performing,)-322(re-)]TJ 0 -11.955 Td [(cently)-256(proposed)-256(method)-255(reduces)-256(standard)-256(accurac)15(y)-256(by)-256(30%)]TJ 0 -11.955 Td [(and)-352(increases)-351(inference)-352(time)-351(by)-352(tw)10(o)-352(orders)-351(of)-352(magnitude,)]TJ 0 -11.956 Td [(while)-326(certifying)-326(only)-326(13.9%)-326(rob)20(ust)-326(accurac)15(y)-326(on)-326(ImageNet)]TJ 0 -11.955 Td [(ag)5(ainst)-336(patches)-336(that)-337(tak)10(e)-336(up)-336(2%)-336(of)-337(the)-336(image)-336([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(].)-569(These)]TJ 0 -11.955 Td [(dra)15(wbacks)-411(are)-412(commonly)-411(accepted)-411(as)-412(the)-411(cost)-411(of)-412(certi\002-)]TJ 0 -11.955 Td [(cation,)-397(b)20(ut)-368(se)25(v)15(erely)-367(limit)-368(the)-368(applicability)-367(of)-368(certi\002ed)-368(de-)]TJ 0 -11.955 Td [(fenses.)-772(Does)-404(certi\002ed)-404(rob)20(ustness)-404(really)-404(need)-404(to)-404(come)-404(at)]TJ 0 -11.955 Td [(such)-250(a)-250(high)-250(price?)]TJ/F86 10.9589 Tf 0 -21.27 Td [(Our)-250(contrib)20(utions)]TJ/F87 9.9626 Tf 11.955 -18.381 Td [(In)-430(this)-430(paper)40(,)-475(we)-429(demonstrate)-430(ho)25(w)-430(to)-430(le)25(v)15(erage)-430(vision)]TJ -11.955 -11.955 Td [(transformers)-334(\(V)60(iTs\))-334([)]TJ
0 1 0 rg 0 1 0 RG
[(10)]TJ
0 g 0 G
[(])-333(to)-334(create)-334(certi\002ed)-334(patch)-334(defenses)]TJ 0 -11.955 Td [(that)-250(achie)25(v)15(e)-250(signi\002cantly)-250(higher)-250(rob)20(ustness)-250(guarantees)-250(than)]TJ 0 -11.955 Td [(prior)-201(w)10(ork.)-294(Moreo)15(v)15(er)40(,)-211(we)-202(sho)25(w)-201(that)-202(certi\002ed)-201(patch)-202(defenses)]TJ 0 -11.955 Td [(with)-308(V)60(iTs)-307(can)-308(actually)-307(maintain)-308(standard)-308(a)1(ccurac)15(y)-308(and)-308(in-)]TJ 0 -11.956 Td [(ference)-276(times)-276(comparable)-276(to)-276(standard)-276(\(non-rob)20(ust\))-276(models.)]TJ 0 -11.955 Td [(At)-337(i)1(ts)-337(core,)-358(our)-337(methodology)-336(e)15(xploits)-337(the)-336(tok)10(en-based)-337(na-)]TJ 0 -11.955 Td [(ture)-265(of)-266(attention)-265(modules)-265(used)-265(in)-266(V)60(iTs)-265(to)-265(gracefully)-266(handle)]TJ 0 -11.955 Td [(the)-258(ablated)-257(images)-258(used)-257(in)-258(certi\002ed)-257(patch)-258(defenses.)-333(Specif-)]TJ 0 -11.955 Td [(ically)65(,)-250(we)-250(demonstrate)-250(the)-250(follo)25(wing:)]TJ/F86 9.9626 Tf 0 -28.99 Td [(Impr)18(o)10(v)10(ed)-228(guarantees)-228(via)-228(smoothed)-228(vision)-228(transf)25(ormers.)]TJ/F87 9.9626 Tf 0 -11.955 Td [(W)80(e)-297<026e64>-297(that)-297(using)-296(V)60(iTs)-297(as)-297(the)-297(backbone)-297(of)-297(the)-297(derandom-)]TJ 0 -11.956 Td [(ized)-226(smoothing)-227(defense)-226([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])-226(enables)-226(signi\002cantly)-227(impro)15(v)15(ed)]TJ 0 -11.955 Td [(certi\002ed)-254(patch)-254(rob)20(ustness.)-323(Indeed,)-255(this)-254(change)-255(alone)-254(boosts)]TJ 0 -11.955 Td [(certi\002ed)-330(accurac)15(y)-330(by)-329(up)-330(to)-330(13%)-330(on)-329(ImageNet,)-350(and)-330(5%)-330(on)]TJ 0 -11.955 Td [(CIF)74(AR-10)-250(o)15(v)15(er)-250(similarly)-250(sized)-250(ResNets.)]TJ/F86 9.9626 Tf 0 -28.99 Td [(Standard)-338(accuracy)-337(comparable)-338(to)-338(that)-337(of)-338(standard)-338(ar)37(-)]TJ 0 -11.955 Td [(chitecur)18(es.)]TJ/F87 9.9626 Tf 55.431 0 Td [(W)80(e)-225(demonstrate)-225(that)-225(V)60(iTs)-225(enable)-225(certi\002ed)-225(de-)]TJ -55.431 -11.955 Td [(fenses)-271(with)-270(standard)-271(accuracies)-270(comparable)-271(to)-271(that)-270(of)-271(stan-)]TJ 0 -11.956 Td [(dard,)-515(non-rob)20(ust)-463(models.)-947(In)-462(particular)40(,)-516(our)-462(lar)18(gest)-463(V)60(iT)]TJ 0 -11.955 Td [(impro)15(v)15(es)-332(state-of-the-art)-331(certi\002ed)-332(rob)20(ustness)-331(on)-332(ImageNet)]TJ 0 -11.955 Td [(while)-321(maintaining)-320(standard)-321(accurac)15(y)-320(that)-321(is)-321(similar)-320(to)-321(that)]TJ 0 -11.955 Td [(of)-250(a)-250(non-rob)20(ust)-250(ResNet)-250(\(>70%\).)]TJ/F86 9.9626 Tf 0 -28.99 Td [(F)25(aster)-220(infer)18(ence.)]TJ/F87 9.9626 Tf 80.61 0 Td [(W)80(e)-220(modify)-220(the)-221(V)60(iT)-220(architecture)-220(to)-220(drop)]TJ -80.61 -11.955 Td [(unnecessary)-373(tok)10(ens,)-405(and)-373(reduce)-373(the)-374(smoothing)-373(process)-374(to)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/IloZeKiTS-1jt4HTKPzoIQ Do
Q
Q
q
1 0 0 1 0 0 cm
/RdVA2F6LNqNB-cCAd6svJQ Do
Q
endstream
endobj
41 0 obj
<< /Font << /F86 322 0 R /F87 323 0 R /F89 324 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /IloZeKiTS-1jt4HTKPzoIQ 326 0 R /RdVA2F6LNqNB-cCAd6svJQ 327 0 R >> >>
endobj
42 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 675.168 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 105.321 554.234 112.295 562.812 ] /Subtype /Link /Type /Annot >>
endobj
43 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 336.438 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 115.536 554.234 127.492 563.081 ] /Subtype /Link /Type /Annot >>
endobj
44 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 269.595 542.279 281.55 551.125 ] /Subtype /Link /Type /Annot >>
endobj
45 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 52.433 358.11 64.388 366.956 ] /Subtype /Link /Type /Annot >>
endobj
46 0 obj
<< /A << /D [ 6 0 R /XYZ 50.112 314.066 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 265.701 344.097 272.675 355.001 ] /Subtype /Link /Type /Annot >>
endobj
47 0 obj
<< /A << /D [ 328 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 262.016 320.187 271.201 331.091 ] /Subtype /Link /Type /Annot >>
endobj
48 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 52.433 127.725 64.388 136.572 ] /Subtype /Link /Type /Annot >>
endobj
49 0 obj
<< /A << /D [ 6 0 R /XYZ 370.949 404.032 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 473.579 316.891 480.553 327.795 ] /Subtype /Link /Type /Annot >>
endobj
50 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 534.695 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 483.283 268.936 495.238 277.783 ] /Subtype /Link /Type /Annot >>
endobj
51 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 393.225 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 427.465 220.996 439.421 229.962 ] /Subtype /Link /Type /Annot >>
endobj
52 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 393.225 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 331.108 122.677 343.064 131.644 ] /Subtype /Link /Type /Annot >>
endobj
53 0 obj
<< /Length 15477 >>
stream
q
q
0 g 0 G
0 g 0 G
BT
/F87 9.9626 Tf 50.112 710.037 Td [(pass)-388(o)15(v)15(er)-388(mostly)-388(redundant)-388(computation.)-724(These)-388(changes)]TJ 0 -11.955 Td [(turn)-252(out)-252(to)-252(v)25(astly)-252(speed)-252(up)-252(inference)-252(time)-252(for)-252(our)-252(smoothed)]TJ 0 -11.955 Td [(V)60(iTs.)-551(In)-331(our)-330(frame)25(w)10(ork,)-351(a)-330(forw)10(ard)-330(pass)-331(on)-330(ImageNet)-331(be-)]TJ 0 -11.955 Td [(comes)-407(up)-407(to)-407(tw)10(o)-407(orders)-407(of)-407(magnitude)-407(f)10(aster)-408(than)-407(that)-407(of)]TJ 0 -11.955 Td [(prior)-296(certi\002ed)-295(defenses,)-308(and)-295(is)-296(close)-296(in)-296(spee)1(d)-296(to)-296(a)-296(standard)]TJ 0 -11.956 Td [(\(non-rob)20(ust\))-250(ResNet.)]TJ/F86 11.9552 Tf 0 -25.619 Td [(2.)-419(Certi\002ed)-418(patch)-419(defense)-419(with)-419(smoothing)-418(&)]TJ 17.933 -13.948 Td [(transf)25(ormers)]TJ/F87 9.9626 Tf -5.978 -19.499 Td [(Smoothing)-349(methods)-350(are)-349(a)-350(general)-349(class)-350(of)-349(certi\002ed)-350(de-)]TJ -11.955 -11.955 Td [(fenses)-202(that)-202(combine)-202(the)-202(predictions)-202(of)-202(a)-203(class)1<69026572>-203(o)15(v)15(er)-202(man)15(y)]TJ 0 -11.955 Td [(v)25(ariations)-391(of)-392(an)-391(input)-391(to)-392(create)-391(predictions)-391(that)-391(are)-392(certi-)]TJ 0 -11.955 Td [(\002ably)-275(rob)20(ust)-276([)]TJ
0 1 0 rg 0 1 0 RG
[(7)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-275(26)]TJ
0 g 0 G
[(].)-386(One)-275(such)-276(method)-275(that)-275(obtains)-276(rob)20(ust-)]TJ 0 -11.956 Td [(ness)-196(to)-196(adv)15(ersarial)-196(patches)-196(is)-196(derandomized)-196(smoothing)-196([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(],)]TJ 0 -11.955 Td [(which)-223(aggre)15(g)5(ates)-223(a)-223(classi\002er')55(s)-223(predictions)-223(on)-223(v)25(arious)]TJ/F91 9.9626 Tf 212.101 0 Td [(ima)10(g)10(e)]TJ -212.101 -11.955 Td [(ablations)]TJ/F87 9.9626 Tf 39.581 0 Td [(that)-250(mask)-250(most)-250(of)-250(the)-250(image)-250(out.)]TJ -27.626 -12.525 Td [(These)-398(approaches)-398(typically)-398(use)-398(CNNs,)-435(a)-399(common)-398(de-)]TJ -11.955 -11.955 Td [(f)10(ault)-340(model)-340(for)-340(computer)-340(vision)-340(tasks,)-362(to)-340(e)25(v)25(aluate)-340(the)-340(im-)]TJ 0 -11.955 Td [(age)-284(ablations.)-412(The)-283(starting)-284(point)-284(of)-284(our)-284(approach)-284(is)-284(to)-284(ask:)]TJ 0 -11.955 Td [(are)-326(con)40(v)20(olutional)-327(architectures)-326(the)-326(right)-327(tool)-326(for)-326(this)-327(task?)]TJ 0 -11.956 Td [(The)-380(crux)-381(of)-380(our)-381(methodology)-380(is)-380(to)-381(le)25(v)15(erage)-380(vision)-381(trans-)]TJ 0 -11.955 Td [(formers,)-279(which)-274(we)-274(demonstrate)-273(are)-274(more)-273(capable)-274(of)-274(grace-)]TJ 0 -11.955 Td [(fully)-319(handling)-318(the)-319(image)-319(ablations)-319(that)-318(arise)-319(in)-319(derandom-)]TJ 0 -11.955 Td [(ized)-250(smoothing.)]TJ/F86 10.9589 Tf 0 -21.635 Td [(2.1.)-250(Pr)18(eliminaries)]TJ/F86 9.9626 Tf 0 -18.502 Td [(Image)-213(ablations.)]TJ/F87 9.9626 Tf 79.891 0 Td [(Image)-213(ablations)-213(are)-213(v)25(ariations)-213(of)-213(an)-214(im-)]TJ -79.891 -11.956 Td [(age)-220(where)-219(all)-220(b)20(ut)-220(a)-219(small)-220(portion)-219(of)-220(the)-220(image)-219(is)-220(mask)10(ed)-220(out)]TJ 0 -11.955 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(].)-426(F)15(or)-289(e)15(xample,)-299(a)-289(column)-288(ablation)-289(masks)-289(the)-289(entire)-289(im-)]TJ 0 -11.955 Td [(age)-308(e)15(xcept)-308(for)-307(a)-308(column)-308(of)-308(a)-308<0278>15(ed)-307(width)-308(\(see)-308(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-308(1)]TJ
0 g 0 G
[-308(for)]TJ 0 -11.955 Td [(an)-300(e)15(xample\).)-461(W)80(e)-300(focus)-301(primarily)-300(on)-300(column)-300(ablations)-301(and)]TJ 0 -11.955 Td [(e)15(xplore)-250(the)-250(more)-250(general)-250(block)-250(ablation)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(G)]TJ
0 g 0 G
[(.)]TJ
0 g 0 G
ET
1 0 0 1 50.112 261.074 cm
q
.29384 0 0 .29384 0 0 cm
q
1 0 0 1 0 0 cm
/Im1 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -261.074 cm
BT
/F87 8.9664 Tf 50.112 243.44 Td [(Figure)-327(1.)-541(Examples)-327(of)-327(column)-327(ablations)-327(for)-327(the)-327(left-most)-326(image)]TJ 0 -10.958 Td [(with)-250(column)-250(width)-250(19px.)]TJ
0 g 0 G
0 g 0 G
/F87 9.9626 Tf 11.955 -26.181 Td [(F)15(or)-337(a)-337(input)]TJ/F11 9.9626 Tf 48.662 0 Td [(h)]TJ/F14 9.9626 Tf 8.595 0 Td [<02>]TJ/F11 9.9626 Tf 10.603 0 Td [(w)]TJ/F87 9.9626 Tf 10.756 0 Td [(sized)-337(image)]TJ/F77 9.9626 Tf 51.533 0 Td [(x)]TJ/F87 9.9626 Tf 6.047 0 Td [(,)-359(we)-336(denote)-337(by)]TJ/F14 9.9626 Tf 64.269 0 Td [(S)]TJ/F10 6.9738 Tf 6.033 -1.495 Td [(b)]TJ/F8 9.9626 Tf 4.001 1.495 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F87 9.9626 Tf -232.376 -11.955 Td [(the)-310(set)-310(of)-310(all)-310(possible)-311(column)-310(ablations)-310(of)-310(width)]TJ/F11 9.9626 Tf 198.824 0 Td [(b)]TJ/F87 9.9626 Tf 4.276 0 Td [(.)-490(A)-310(col-)]TJ -203.1 -11.956 Td [(umn)-279(ablation)-279(can)-278(start)-279(at)-279(an)15(y)-279(position)-278(and)-279(wrap)-279(around)-279(the)]TJ 0 -11.955 Td [(image,)-250(so)-250(there)-250(are)]TJ/F11 9.9626 Tf 77.738 0 Td [(w)]TJ/F87 9.9626 Tf 9.891 0 Td [(total)-250(ablations)-250(in)]TJ/F14 9.9626 Tf 68.91 0 Td [(S)]TJ/F10 6.9738 Tf 6.033 -1.494 Td [(b)]TJ/F8 9.9626 Tf 4.002 1.494 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F87 9.9626 Tf 3.874 0 Td [(.)]TJ/F86 9.9626 Tf -180.369 -29.659 Td [(Derandomized)-823(smoothing)15(.)]TJ/F87 9.9626 Tf 127.325 0 Td [(Derandomized)-823(smoothing)]TJ -127.325 -11.955 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])-296(is)-296(a)-296(popular)-296(approach)-296(for)-297(cer)1(ti\002ed)-297(patch)-296(defenses)-296(that)]TJ 0 -11.955 Td [(constructs)-418(a)]TJ/F91 9.9626 Tf 53.147 0 Td [(smoothed)-418(classi\002er)]TJ/F87 9.9626 Tf 82.715 0 Td [(comprising)-418(of)-418(tw)10(o)-418(m)1(ain)]TJ -135.862 -11.956 Td [(components:)-299(\(1\))-227(a)]TJ/F91 9.9626 Tf 74.471 0 Td [(base)-228(classi\002er)]TJ/F87 9.9626 Tf 56.504 0 Td [(,)-232(and)-228(\(2\))-227(a)-228(set)-228(of)-227(image)-228(ab-)]TJ -130.975 -11.955 Td [(lations)-281(used)-281(to)-281(smooth)-281(the)-281(base)-282(c)1(lassi\002er)55(.)-404(Then,)-289(the)-281(result-)]TJ 0 -11.955 Td [(ing)-237(smoothed)-238(cl)1(assi\002er)-238(returns)-237(the)-237(most)-237(frequent)-238(prediction)]TJ
0 g 0 G
0 g 0 G
258.75 629.037 Td [(of)-337(the)-338(base)-337(classi\002er)-338(o)15(v)15(er)-337(the)-338(ablation)-337(set)]TJ/F14 9.9626 Tf 173.234 0 Td [(S)]TJ/F10 6.9738 Tf 6.033 -1.494 Td [(b)]TJ/F8 9.9626 Tf 4.002 1.494 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F87 9.9626 Tf 3.874 0 Td [(.)-572(Speci\002-)]TJ -197.064 -11.955 Td [(cally)65(,)-327(for)-312(an)-312(input)-312(image)]TJ/F77 9.9626 Tf 102.756 0 Td [(x)]TJ/F87 9.9626 Tf 6.047 0 Td [(,)-327(ablation)-312(set)]TJ/F14 9.9626 Tf 55.136 0 Td [(S)]TJ/F10 6.9738 Tf 6.033 -1.494 Td [(b)]TJ/F8 9.9626 Tf 4.001 1.494 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F8 9.9626 Tf 6.046 0 Td [(\))]TJ/F87 9.9626 Tf 3.875 0 Td [(,)-327(and)-312(a)-312(base)]TJ -187.769 -11.955 Td [(classi\002er)]TJ/F11 9.9626 Tf 37.907 0 Td [(f)]TJ/F87 9.9626 Tf 5.95 0 Td [(,)-250(a)-250(smoothed)-250(classi\002er)]TJ/F11 9.9626 Tf 91.038 0 Td [(g)]TJ/F87 9.9626 Tf 7.599 0 Td [(is)-250(de\002ned)-250(as:)]TJ/F11 9.9626 Tf -70.313 -19.561 Td [(g)]TJ/F8 9.9626 Tf 5.109 0 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))-278(=)-277(arg)-181(max)]TJ/F10 6.9738 Tf 32.48 -7.914 Td [(c)]TJ/F11 9.9626 Tf 20.543 7.914 Td [(n)]TJ/F10 6.9738 Tf 5.98 -1.494 Td [(c)]TJ/F8 9.9626 Tf 4.058 1.494 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F8 9.9626 Tf 6.046 0 Td [(\))]TJ/F87 9.9626 Tf 64.44 0 Td [(\(1\))]TJ -224.634 -24.267 Td [(where)]TJ/F11 9.9626 Tf 55.571 -11.955 Td [(n)]TJ/F10 6.9738 Tf 5.98 -1.495 Td [(c)]TJ/F8 9.9626 Tf 4.058 1.495 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))-278(=)]TJ/F1 9.9626 Tf 26.141 9.464 Td [(X)]TJ/F78 6.9738 Tf -8.984 -21.834 Td [(x)]TJ/F12 4.9813 Tf 4.762 1.992 Td [(0)]TJ/F13 6.9738 Tf 2.694 -1.992 Td [(2)]TJ/F10 6.9738 Tf 5.369 0 Td [(S)]TJ/F9 4.9813 Tf 4.892 -1.058 Td [(b)]TJ/F7 6.9738 Tf 3.653 1.058 Td [(\()]TJ/F78 6.9738 Tf 3.114 0 Td [(x)]TJ/F7 6.9738 Tf 4.761 0 Td [(\))]TJ/F75 9.9626 Tf 4.774 12.37 Td [(I)]TJ/F14 9.9626 Tf 3.874 0 Td [(f)]TJ/F11 9.9626 Tf 4.981 0 Td [(f)]TJ/F8 9.9626 Tf 5.95 0 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F13 6.9738 Tf 6.046 4.113 Td [(0)]TJ/F8 9.9626 Tf 2.795 -4.113 Td [(\))-278(=)]TJ/F11 9.9626 Tf 17.158 0 Td [(c)]TJ/F14 9.9626 Tf 4.312 0 Td [(g)]TJ/F87 9.9626 Tf -175.698 -27.424 Td [(denotes)-437(the)-437(number)-437(of)-437(image)-437(ablations)-437(that)-437(were)-437(classi-)]TJ 0 -11.955 Td [<026564>-440(as)-440(class)]TJ/F11 9.9626 Tf 55.767 0 Td [(c)]TJ/F87 9.9626 Tf 4.312 0 Td [(.)-881(W)80(e)-440(refer)-440(to)-440(the)-441(fraction)-440(of)-440(images)-440(that)]TJ -60.079 -11.956 Td [(the)-322(smoothed)-322(classi\002er)-322(correctly)-322(classi\002es)-322(as)]TJ/F91 9.9626 Tf 185.262 0 Td [(standar)37(d)-322(ac-)]TJ -185.262 -11.955 Td [(cur)15(acy)]TJ/F87 9.9626 Tf 26.959 0 Td [(.)]TJ -15.004 -11.955 Td [(A)-369(smoothed)-369(classi\002er)-368(is)]TJ/F91 9.9626 Tf 102.697 0 Td [(certi\002ably)-369(r)45(ob)20(ust)]TJ/F87 9.9626 Tf 72.744 0 Td [(for)-369(an)-369(input)]TJ -187.396 -11.955 Td [(image)-233(if)-233(the)-233(number)-232(of)-233(ablations)-233(for)-233(the)-233(most)-233(frequent)-233(class)]TJ 0 -11.955 Td [(e)15(xceeds)-331(the)-330(second)-331(most)-330(frequent)-331(class)-330(by)-331(a)-330(lar)18(ge)-331(enough)]TJ 0 -11.956 Td [(mar)18(gin.)-438(Intuiti)25(v)15(ely)65(,)-303(a)-292(lar)18(ge)-293(mar)18(gin)-292(mak)10(es)-293(it)-292(impossible)-293(for)]TJ 0 -11.955 Td [(an)-242(adv)15(ersarial)-242(patch)-242(to)-242(change)-242(the)-242(prediction)-243(of)-242(a)-242(smoothed)]TJ 0 -11.955 Td [(classi\002er)-291(since)-291(a)-291(patch)-291(can)-291(only)-291(af)25(fect)-291(a)-292(limited)-291(number)-291(of)]TJ 0 -11.955 Td [(ablations.)]TJ 11.955 -11.955 Td [(Speci\002cally)65(,)-258(let)]TJ/F8 9.9626 Tf 63.973 0 Td [<01>]TJ/F87 9.9626 Tf 10.856 0 Td [(be)-256(the)-257(maximum)-256(number)-256(of)-257(ablations)]TJ -86.784 -11.955 Td [(in)-361(the)-361(ablation)-361(set)]TJ/F11 9.9626 Tf 77.483 0 Td [(S)]TJ/F10 6.9738 Tf 6.11 -1.495 Td [(b)]TJ/F8 9.9626 Tf 4.001 1.495 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(x)]TJ/F8 9.9626 Tf 6.046 0 Td [(\))]TJ/F87 9.9626 Tf 7.472 0 Td [(that)-361(an)-361(adv)15(ersarial)-361(patch)-361(can)-362(si-)]TJ -104.987 -11.956 Td [(multaneously)-258(intersect)-258(\(e.g.,)-260(for)-258(column)-258(ablations)-258(of)-258(size)]TJ/F11 9.9626 Tf 229.484 0 Td [(b)]TJ/F87 9.9626 Tf 4.275 0 Td [(,)]TJ -233.759 -11.955 Td [(an)]TJ/F11 9.9626 Tf 11.891 0 Td [(m)]TJ/F14 9.9626 Tf 10.944 0 Td [<02>]TJ/F11 9.9626 Tf 9.946 0 Td [(m)]TJ/F87 9.9626 Tf 11.234 0 Td [(patch)-249(can)-250(intersect)-250(with)-249(at)-250(most)]TJ/F8 9.9626 Tf 128.359 0 Td [<01>-278(=)]TJ/F11 9.9626 Tf 21.586 0 Td [(m)]TJ/F8 9.9626 Tf 10.944 0 Td [(+)]TJ/F11 9.9626 Tf 9.946 0 Td [(b)]TJ/F14 9.9626 Tf 6.473 0 Td [<00>]TJ/F8 9.9626 Tf 9.946 0 Td [(1)]TJ/F87 9.9626 Tf -231.269 -11.955 Td [(ablations\).)-412(Then,)-293(a)-284(smoothed)-284(classi\002er)-284(is)-284(certi\002ably)-284(rob)20(ust)]TJ 0 -11.955 Td [(on)-250(an)-250(input)]TJ/F77 9.9626 Tf 47.322 0 Td [(x)]TJ/F87 9.9626 Tf 8.538 0 Td [(if)-250(it)-250(is)-250(the)-250(case)-250(that)-250(for)-250(the)-250(predicted)-250(class)]TJ/F11 9.9626 Tf 167.668 0 Td [(c)]TJ/F87 9.9626 Tf 4.312 0 Td [(:)]TJ/F11 9.9626 Tf -165.753 -19.561 Td [(n)]TJ/F10 6.9738 Tf 5.98 -1.494 Td [(c)]TJ/F8 9.9626 Tf 4.059 1.494 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F11 9.9626 Tf 6.641 0 Td [(>)]TJ/F8 9.9626 Tf 10.517 0 Td [(max)]TJ/F10 6.9738 Tf 1.305 -6.503 Td [(c)]TJ/F12 4.9813 Tf 3.56 1.992 Td [(0)]TJ/F13 6.9738 Tf 2.695 -1.992 Td [(6)]TJ/F7 6.9738 Tf 0 0 Td [(=)]TJ/F10 6.9738 Tf 6.116 0 Td [(c)]TJ/F11 9.9626 Tf 6.526 6.503 Td [(n)]TJ/F10 6.9738 Tf 5.98 -1.494 Td [(c)]TJ/F12 4.9813 Tf 3.56 1.992 Td [(0)]TJ/F8 9.9626 Tf 3.193 -0.498 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))-222(+)-222<3201>]TJ/F11 9.9626 Tf 29.334 0 Td [(:)]TJ/F87 9.9626 Tf 53.239 0 Td [(\(2\))]TJ -224.634 -24.212 Td [(If)-328(this)-328(threshold)-328(is)-328(met,)-348(the)-328(most)-328(frequent)-328(class)-328(is)-328(guaran-)]TJ 0 -11.955 Td [(teed)-210(to)-209(not)-210(change)-209(e)25(v)15(en)-210(if)-209(an)-210(adv)15(ersarial)-209(patch)-210(compromises)]TJ 0 -11.955 Td [(e)25(v)15(ery)-311(ablation)-311(it)-310(intersects.)-493(W)80(e)-311(denote)-310(the)-311(fraction)-311(of)-311(pre-)]TJ 0 -11.955 Td [(dictions)-345(by)-345(the)-345(smooth)-345(classi\002er)-345(that)-345(are)-346(both)-345(correct)-345(and)]TJ 0 -11.955 Td [(certi\002ably)-287(rob)20(ust)-286(\(according)-287(to)-287(Equation)]TJ
1 0 0 rg 1 0 0 RG
[-287(2)]TJ
0 g 0 G
[(\))-286(as)]TJ/F91 9.9626 Tf 188.024 0 Td [(certi\002ed)-287(ac-)]TJ -188.024 -11.956 Td [(cur)15(acy)]TJ/F87 9.9626 Tf 26.959 0 Td [(.)]TJ/F86 9.9626 Tf -26.959 -26.101 Td [(V)37(ision)-296(transf)25(ormers.)]TJ/F87 9.9626 Tf 97.795 0 Td [(A)-296(k)10(e)15(y)-297(component)-296(of)-296(our)-296(approach)]TJ -97.795 -11.955 Td [(is)-223(the)-223(vision)-223(transformer)-223(\(V)60(iT\))-223(architecture)-224([)]TJ
0 1 0 rg 0 1 0 RG
[(10)]TJ
0 g 0 G
[(].)-301(In)-223(contrast)]TJ 0 -11.955 Td [(to)-380(con)40(v)20(olutional)-379(architecures,)-412(V)60(iTs)-380(use)-379(self-attention)-380(lay-)]TJ 0 -11.955 Td [(ers)-238(instead)-239(of)-238(con)40(v)20(olutional)-239(layers)-238(as)-239(their)-238(primary)-239(b)20(uilding)]TJ 0 -11.955 Td [(block)-388(and)-389(are)-388(inspired)-389(by)-388(the)-389(succes)1(s)-389(of)-388(self-attention)-389(in)]TJ 0 -11.956 Td [(natural)-336(language)-336(processing)-336([)]TJ
0 1 0 rg 0 1 0 RG
[(49)]TJ
0 g 0 G
[(].)-568(V)60(iTs)-336(process)-336(images)-336(in)]TJ 0 -11.955 Td [(three)-250(main)-250(stages:)]TJ
0 g 0 G
7.472 -19.56 Td [(1.)]TJ
0 g 0 G
/F91 9.9626 Tf 12.453 0 Td [(T)92(ok)10(enization:)]TJ/F87 9.9626 Tf 60.728 0 Td [(The)-444(V)60(iTs)-444(spl)1(it)-444(the)-444(image)-444(into)]TJ/F11 9.9626 Tf 130.536 0 Td [(p)]TJ/F14 9.9626 Tf 8.656 0 Td [<02>]TJ/F11 9.9626 Tf 11.393 0 Td [(p)]TJ/F87 9.9626 Tf -211.313 -11.956 Td [(patches.)-365(Each)-269(patch)-268(is)-269(then)-268(embedded)-269(into)-268(a)-269(position-)]TJ 0 -11.955 Td [(ally)-250(encoded)]TJ/F91 9.9626 Tf 53.121 0 Td [(tok)10(en)]TJ/F87 9.9626 Tf 21.479 0 Td [(.)]TJ
0 g 0 G
-87.053 -18.982 Td [(2.)]TJ
0 g 0 G
/F91 9.9626 Tf 12.453 0 Td [(Self-Attention:)]TJ/F87 9.9626 Tf 67.082 0 Td [(The)-545(set)-545(of)-546(tok)10(ens)-545(are)-545(then)-545(passed)]TJ -67.082 -11.955 Td [(through)-351(a)-351(series)-351(of)-352(multi-headed)-351(self-attention)-351(layers)]TJ 0 -11.956 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(49)]TJ
0 g 0 G
[(].)]TJ
0 g 0 G
-12.453 -18.982 Td [(3.)]TJ
0 g 0 G
/F91 9.9626 Tf 12.453 0 Td [(Classi\002cation)-198(head:)]TJ/F87 9.9626 Tf 82.285 0 Td [(The)-198(resulting)-197(representation)-198(is)-197(fed)]TJ -82.285 -11.955 Td [(into)-403(a)-404(fully)-403(connected)-404(layer)-403(to)-404(mak)10(e)-403(predictions)-404(for)]TJ 0 -11.955 Td [(classi\002cation.)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/QMI3kESfCOgABhAuTHmOdw Do
Q
endstream
endobj
54 0 obj
<< /Font << /F1 329 0 R /F10 330 0 R /F11 331 0 R /F12 332 0 R /F13 333 0 R /F14 334 0 R /F7 335 0 R /F75 336 0 R /F77 337 0 R /F78 338 0 R /F8 339 0 R /F86 322 0 R /F87 323 0 R /F9 340 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /Im1 341 0 R /QMI3kESfCOgABhAuTHmOdw 342 0 R >> >>
endobj
55 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 488.867 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 107.968 485.35 119.923 494.197 ] /Subtype /Link /Type /Annot >>
endobj
56 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 281.249 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 142.671 473.495 149.645 482.242 ] /Subtype /Link /Type /Annot >>
endobj
57 0 obj
<< /A << /D [ 343 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 212.197 471.338 220.834 482.242 ] /Subtype /Link /Type /Annot >>
endobj
58 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 393.225 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 130.531 289.208 142.486 298.175 ] /Subtype /Link /Type /Annot >>
endobj
59 0 obj
<< /A << /D [ 7 0 R /XYZ 308.862 425.853 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 203.091 167.17 210.065 178.074 ] /Subtype /Link /Type /Annot >>
endobj
60 0 obj
<< /A << /D [ 9 0 R /XYZ 308.862 184.778 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 49.116 131.304 56.09 142.208 ] /Subtype /Link /Type /Annot >>
endobj
61 0 obj
<< /A << /D [ 7 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 264.995 131.304 271.969 142.208 ] /Subtype /Link /Type /Annot >>
endobj
62 0 obj
<< /A << /D [ 328 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 259.771 89.802 268.956 100.706 ] /Subtype /Link /Type /Annot >>
endobj
63 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 487.87 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 147.028 80.004 158.984 88.751 ] /Subtype /Link /Type /Annot >>
endobj
64 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 581.519 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 224.08 79.785 231.054 88.751 ] /Subtype /Link /Type /Annot >>
endobj
65 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 534.695 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 359.386 497.305 371.341 506.152 ] /Subtype /Link /Type /Annot >>
endobj
66 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 263.711 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 376.569 497.305 388.524 506.152 ] /Subtype /Link /Type /Annot >>
endobj
67 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 111.283 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 481.735 485.35 493.69 494.197 ] /Subtype /Link /Type /Annot >>
endobj
68 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 405.181 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 370.014 473.395 381.969 482.242 ] /Subtype /Link /Type /Annot >>
endobj
69 0 obj
<< /A << /D [ 344 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 449.172 459.383 458.357 470.286 ] /Subtype /Link /Type /Annot >>
endobj
70 0 obj
<< /A << /D [ 343 0 R /XYZ 50.112 515.902 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 491.715 447.427 500.352 458.331 ] /Subtype /Link /Type /Annot >>
endobj
71 0 obj
<< /A << /D [ 8 0 R /XYZ 50.112 147.718 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 525.854 227.613 540.3 238.517 ] /Subtype /Link /Type /Annot >>
endobj
72 0 obj
<< /A << /D [ 9 0 R /XYZ 308.862 562.47 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 372.054 144.3 386.5 154.831 ] /Subtype /Link /Type /Annot >>
endobj
73 0 obj
<< /A << /D [ 8 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 332.007 113.712 338.981 124.616 ] /Subtype /Link /Type /Annot >>
endobj
74 0 obj
<< /A << /D [ 8 0 R /XYZ 50.112 411.91 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 380.023 113.712 386.997 124.616 ] /Subtype /Link /Type /Annot >>
endobj
75 0 obj
<< /A << /D [ 9 0 R /XYZ 308.862 184.778 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 433.215 89.802 440.188 100.706 ] /Subtype /Link /Type /Annot >>
endobj
76 0 obj
<< /A << /D [ 345 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 506.233 89.802 515.419 100.706 ] /Subtype /Link /Type /Annot >>
endobj
77 0 obj
<< /Length 10586 >>
stream
q
q
0 g 0 G
0 g 0 G
0 g 0 G
1 0 0 1 50.112 605.998 cm
q
.36105 0 0 .36105 0 0 cm
q
1371 0 0 315.75 0 0 cm
/Im2 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -605.998 cm
BT
/F87 8.9664 Tf 50.112 588.364 Td [(Figure)-260(2.)-340(Illustration)-260(of)-260(the)-260(smoothed)-260(vision)-260(transformer)55(.)-339(F)15(or)-260(a)-260(gi)25(v)15(en)-260(image,)-263(we)-260<02727374>-260(generate)-260(a)-260(set)-260(of)-260(ablations)1(.)-340(W)80(e)-260(encode)-260(each)-260(ablation)]TJ 0 -10.959 Td [(into)-256(tok)10(ens,)-258(and)-256(drop)-256(fully)-257(mask)10(ed)-256(tok)10(ens.)-329(The)-256(remaining)-256(tok)10(ens)-256(for)-256(each)-257(ablation)-256(are)-256(then)-256(fed)-256(into)-257(a)-256(vision)-256(transformer)40(,)-258(which)-256(predicts)-256(a)]TJ 0 -10.959 Td [(class)-271(label)-271(for)-271(each)-272(ablation.)-373(W)80(e)-271(predict)-271(the)-272(class)-271(with)-271(the)-271(most)-271(predictions)-271(o)15(v)15(er)-272(all)-271(the)-271(ablations,)-276(and)-271(use)-272(the)-271(mar)18(gin)-271(to)-271(the)-271(second-place)]TJ 0 -10.959 Td [(class)-250(for)-250(rob)20(ustness)-250(certi\002cation.)]TJ
0 g 0 G
0 g 0 G
/F87 9.9626 Tf 11.955 -33.176 Td [(Recent)-391(w)10(orks)-391(ha)20(v)14(e)-391(in)40(v)15(estig)5(ated)-391(whether)-391(V)60(iTs)-391(can)-392(im-)]TJ -11.955 -11.955 Td [(pro)15(v)15(e)-217(rob)20(ustness)-217(in)-217(v)25(arious)-217(settings.)-299(V)60(iTs)-217(initially)-217(appeared)]TJ 0 -11.955 Td [(to)-429(be)-430(more)-429(rob)20(ust)-429(than)-430(CNNs)-429(to)-429(natural)-429(and)-430(adv)15(ersarial)]TJ 0 -11.955 Td [(perturbations)-297([)]TJ
0 1 0 rg 0 1 0 RG
[(36)]TJ
0 g 0 G
[(].)-452(Ho)25(we)25(v)15(er)40(,)-309(recent)-298(w)10(ork)-297(sho)25(wed)-297(that)-298(this)]TJ 0 -11.955 Td [(might)-312(not)-311(be)-312(the)-312(case)-312([)]TJ
0 1 0 rg 0 1 0 RG
[(2)]TJ
0 g 0 G
[(].)-495(In)-312(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-311(B)]TJ
0 g 0 G
[-312(we)-312(demonstrate)]TJ 0 -11.955 Td [(that)-251(standard)-251(V)60(iTs)-251(and)-251(CNNs)-251(can)-251(both)-251(be)-251(easily)-251(brok)10(en)-251(us-)]TJ 0 -11.956 Td [(ing)-250(simple)-250(patch)-250(attacks.)]TJ/F86 10.9589 Tf 0 -21.573 Td [(2.2.)-250(Smoothed)-250(vision)-250(transf)25(ormers)]TJ/F87 9.9626 Tf 11.955 -18.482 Td [(T)80(w)10(o)-232(central)-232(properties)-231(of)-232(vision)-232(transformers)-232(mak)10(e)-232(V)60(iTs)]TJ -11.955 -11.955 Td [(particularly)-416(appealing)-416(for)-416(processing)-416(the)-416(image)-416(ablations)]TJ 0 -11.955 Td [(that)-561(arise)-560(in)-561(derandomized)-561(sm)1(oothing.)-1242(Firstly)65(,)-639(unlik)10(e)]TJ 0 -11.956 Td [(CNNs,)-390(V)60(iTs)-362(process)-361(images)-362(as)-362(sets)-362(of)-361(tok)10(ens.)-646(V)60(iTs)-362(thus)]TJ 0 -11.955 Td [(ha)20(v)15(e)-323(the)-323(natural)-324(capability)-323(to)-323(simply)-323(drop)-323(u)-1(nnec)1(essary)-324(to-)]TJ 0 -11.955 Td [(k)10(ens)-343(from)-343(the)-342(input)-343(and)-343(\223ignore\224)-343(lar)18(ge)-342(re)15(gions)-343(of)-343(the)-343(im-)]TJ 0 -11.955 Td [(age,)-407(which)-376(can)-376(greatly)-376(speed)-375(up)-376(the)-376(processing)-376(of)-376(image)]TJ 0 -11.955 Td [(ablations.)]TJ 11.955 -12.505 Td [(Moreo)15(v)15(er)40(,)-218(unlik)10(e)-211(con)40(v)20(olutions)-210(which)-210(operate)-210(locally)65(,)-219(the)]TJ -11.955 -11.955 Td [(self-attention)-305(mechanism)-306(in)-305(V)60(iTs)-305(shares)-305(information)]TJ/F91 9.9626 Tf 215.219 0 Td [(glob-)]TJ -215.219 -11.955 Td [(ally)]TJ/F87 9.9626 Tf 18.523 0 Td [(at)-359(e)25(v)15(ery)-360(layer)-359([)]TJ
0 1 0 rg 0 1 0 RG
[(49)]TJ
0 g 0 G
[(].)-638(Thus,)-386(one)-360(w)10(ould)-359(e)15(xpect)-359(V)60(iTs)-359(to)]TJ -18.523 -11.955 Td [(be)-263(better)-263(suited)-263(for)-264(classifying)-263(image)-263(ablations,)-266(as)-264(the)15(y)-263(can)]TJ 0 -11.956 Td [(dynamically)-289(attend)-290(to)-289(the)-290(sm)1(all,)-300(unmask)10(ed)-289(re)15(gion.)-428(In)-290(con-)]TJ 0 -11.955 Td [(trast,)-236(a)-233(CNN)-233(must)-233(gradually)-234(b)20(uild)-233(up)-233(its)-233(recepti)25(v)15(e)-233<02656c64>-233(o)15(v)15(er)]TJ 0 -11.955 Td [(multiple)-250(layers)-250(and)-250(process)-250(mask)10(ed-out)-250(pix)15(els.)]TJ 11.955 -12.504 Td [(Guided)-352(by)-352(these)-353(intuitions,)-377(our)-353(methodology)-352(le)25(v)15(erages)]TJ -11.955 -11.956 Td [(the)-241(V)60(iT)-241(architecture)-241(as)-241(the)-241(base)-241(classi\002er)-241(for)-241(processing)-241(the)]TJ 0 -11.955 Td [(image)-276(ablations)-276(used)-277(in)-276(derandomized)-276(smoothing.)-389(W)80(e)-276<02727374>]TJ 0 -11.955 Td [(demonstrate)-216(that)-216(these)]TJ/F91 9.9626 Tf 90.573 0 Td [(smoothed)-216(vision)-216(tr)15(ansformer)10(s)]TJ/F87 9.9626 Tf 119.675 0 Td [(enable)]TJ -210.248 -11.955 Td [(substantially)-311(impro)15(v)15(ed)-311(rob)20(ustness)-311(guarantees,)-327(without)-311(los-)]TJ 0 -11.955 Td [(ing)-339(much)-340(standard)-339(accurac)15(y)-339(\(Section)]TJ
1 0 0 rg 1 0 0 RG
[-339(3)]TJ
0 g 0 G
[(\).)-578(W)80(e)-339(then)-340(modify)]TJ 0 -11.955 Td [(the)-230(V)60(iT)-230(architecture)-231(and)-230(smoothing)-230(procedure)-230(to)-231(drastically)]TJ 0 -11.956 Td [(speed)-300(up)-300(the)-300(cost)-300(of)-300(inference)-300(of)-301(a)-300(smoothed)-300(V)60(iT)-300(\(Section)]TJ
1 0 0 rg 1 0 0 RG
0 -11.955 Td [(4)]TJ
0 g 0 G
[(\).)-310(W)80(e)-250(present)-250(an)-250(o)15(v)15(ervie)25(w)-250(of)-250(our)-250(approach)-250(in)-250(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-250(2)]TJ
0 g 0 G
[(.)]TJ/F86 9.9626 Tf 0 -29.547 Td [(Setup.)]TJ/F87 9.9626 Tf 36.812 0 Td [(W)80(e)-276(focus)-276(primarily)-277(on)-276(the)-276(column)-276(smoothing)-277(set-)]TJ -36.812 -11.955 Td [(ting)-289(and)-289(defer)-289(block)-289(smoothing)-289(results)-289(to)-290(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-289(G)]TJ
0 g 0 G
[(.)-289(W)80(e)]TJ 0 -11.955 Td [(consider)-227(the)-227(CIF)74(AR-10)-227([)]TJ
0 1 0 rg 0 1 0 RG
[(22)]TJ
0 g 0 G
[(])-227(and)-227(ImageNet)-227([)]TJ
0 1 0 rg 0 1 0 RG
[(9)]TJ
0 g 0 G
[(])-227(datasets,)-232(and)]TJ
0 g 0 G
0 g 0 G
258.75 441.311 Td [(perform)-208(our)-208(analysis)-208(on)-207(three)-208(sizes)-208(of)-208(vision)-208(transformers\227)]TJ 0 -11.955 Td [(V)60(iT)92(-T)35(in)15(y)-345(\(V)60(iT)92(-T\),)-345(V)60(iT)92(-Small)-344(\(V)60(iT)92(-S\),)-345(and)-345(V)60(iT)92(-Base)-345(\(V)60(iT)92(-)]TJ 0 -11.955 Td [(B\))-475(models)-474([)]TJ
0 1 0 rg 0 1 0 RG
[(10)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-475(51)]TJ
0 g 0 G
[(].)-985(W)80(e)-474(compare)-475(to)-475(residual)-475(netw)10(orks)]TJ 0 -11.955 Td [(of)-520(similar)-521(size\227ResNet-18,)-588(ResNet-50)-520([)]TJ
0 1 0 rg 0 1 0 RG
[(17)]TJ
0 g 0 G
[(],)-588(and)-521(W)40(ide)]TJ 0 -11.955 Td [(ResNet-101-2)-295([)]TJ
0 1 0 rg 0 1 0 RG
[(60)]TJ
0 g 0 G
[(],)-307(respecti)25(v)15(ely)65(.)-445(Further)-295(details)-295(of)-296(our)-295(e)15(x-)]TJ 0 -11.956 Td [(perimental)-370(setup)-371(are)-371(in)-370(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-371(A)]TJ
0 g 0 G
[(.)-370(Further)-371(e)15(xperiments)]TJ 0 -11.955 Td [(e)15(xploring)-250(data-augmentation)-250(are)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(C)]TJ
0 g 0 G
[(.)]TJ/F86 11.9552 Tf 0 -42.822 Td [(3.)-219(Impr)18(o)10(ving)-219(certi\002ed)-219(and)-219(standard)-219(accuracies)]TJ 17.933 -13.948 Td [(with)-250(V)37(iTs)]TJ/F87 9.9626 Tf -5.978 -25.233 Td [(Recall)-508(that)-509(e)25(v)15(en)-508(though)-509(certi\002ed)-508(patch)-508(defenses)-509(can)]TJ -11.955 -11.955 Td [(guarantee)-339(rob)20(ustness)-339(to)-339(patch)-339(attacks,)-362(this)-339(rob)20(ustness)-339(typ-)]TJ 0 -11.956 Td [(ically)-361(does)-360(not)-361(come)-360(for)-361(free.)-641(Indeed,)-389(certi\002ed)-360(patch)-361(de-)]TJ 0 -11.955 Td [(fenses)-375(tend)-376(to)-375(ha)20(v)15(e)-376(substantially)-375(lo)25(wer)-375(standard)-376(accurac)15(y)]TJ 0 -11.955 Td [(when)-352(compared)-352(to)-351(typical)-352(\(non-rob)20(ust\))-352(models,)-377(while)-352(de-)]TJ 0 -11.955 Td [(li)25(v)15(ering)-250(a)-250(f)10(airly)-250(limited)-250(de)15(gree)-250(of)-250(\(certi\002ed\))-250(rob)20(ustness.)]TJ 11.955 -18.259 Td [(In)-232(this)-231(section,)-235(we)-232(sho)25(w)-231(ho)25(w)-232(to)-231(use)-232(V)60(iTs)-231(to)-232(substantially)]TJ -11.955 -11.955 Td [(impro)15(v)15(e)-274(both)-274(standard)-273(and)-274(certi\002ed)-274(accuracies)-274(for)-274(certi\002ed)]TJ 0 -11.956 Td [(patch)-376(defenses.)-688(T)80(o)-377(this)-376(end,)-407(we)-377<027273>1(t)-377(empirically)-376(demon-)]TJ 0 -11.955 Td [(strate)-383(that)-383(V)60(iTs)-383(are)-383(a)-383(more)-383(suitable)-383(architecture)-383(than)-383(tra-)]TJ 0 -11.955 Td [(ditional)-399(con)40(v)20(olutional)-400(netw)10(orks)-399(for)-400(classifying)-399(the)-400(image)]TJ 0 -11.955 Td [(ablations)-406(used)-407(in)-406(derandomized)-406(smoothing)-406(\(Section)]TJ
1 0 0 rg 1 0 0 RG
[-407(3.1)]TJ
0 g 0 G
[(\).)]TJ 0 -11.955 Td [(Speci\002cally)65(,)-231(this)-226(change)-226(in)-226(architecture)-226(alone)-227(yields)-226(models)]TJ 0 -11.956 Td [(with)-356(signi\002cantly)-356(impro)15(v)15(ed)-356(standard)-356(and)-357(certi\002ed)-356(accura-)]TJ 0 -11.955 Td [(cies.)-570(W)80(e)-337(then)-337(sho)25(w)-337(ho)25(w)-337(a)-336(careful)-337(selection)-337(of)-337(smoothing)]TJ 0 -11.955 Td [(parameters)-308(can)-308(enable)-309(smoothed)-308(V)60(iTs)-308(to)-308(ha)20(v)15(e)-308(e)25(v)15(en)-309(higher)]TJ 0 -11.955 Td [(standard)-444(accuracies)-444(that)-445(are)-444(comparable)-444(to)-444(typical)-445(\(non-)]TJ 0 -11.955 Td [(rob)20(ust\))-376(models,)-406(without)-376(sacri\002cing)-376(much)-375(certi\002ed)-376(perfor)20(-)]TJ 0 -11.955 Td [(mance)-250(\(Section)]TJ
1 0 0 rg 1 0 0 RG
[-250(3.2)]TJ
0 g 0 G
[(\).)]TJ 11.955 -18.26 Td [(Our)-267(ImageNet)-267(and)-267(CIF)74(AR-10)-267(results)-268(are)-267(summarized)-267(in)]TJ -11.955 -11.955 Td [(T)80(able)]TJ
1 0 0 rg 1 0 0 RG
[-226(1)]TJ
0 g 0 G
[-226(and)-227(T)80(able)]TJ
1 0 0 rg 1 0 0 RG
[-226(2)]TJ
0 g 0 G
[(,)-231(respecti)25(v)15(ely)65(.)-302(W)80(e)-226(further)-226(include)-227(t)1(he)-227(in-)]TJ 0 -11.955 Td [(ference)-290(time)-290(to)-289(e)25(v)25(aluate)-290(a)-290(batch)-290(of)-289(images,)-300(using)-290(the)-290(mod-)]TJ 0 -11.955 Td [(i\002cations)-326(described)-326(in)-327(Section)]TJ
1 0 0 rg 1 0 0 RG
[-326(4)]TJ
0 g 0 G
[(.)-539(See)-326(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-326(H)]TJ
0 g 0 G
[-326(for)-327(e)15(x-)]TJ 0 -11.955 Td [(tended)-250(tables)-250(co)15(v)15(ering)-250(a)-250(wider)-250(range)-250(of)-250(e)15(xperiments.)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/U5Vi1hUHNVJtHTpV-S0ilg Do
Q
endstream
endobj
78 0 obj
<< /CS /DeviceRGB /I true /S /Transparency /Type /Group >>
endobj
79 0 obj
<< /Font << /F86 322 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text /ImageC ] /XObject << /Im2 346 0 R /U5Vi1hUHNVJtHTpV-S0ilg 347 0 R >> >>
endobj
80 0 obj
<< /A << /D [ 345 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 329.113 686.127 337.579 697.486 ] /Subtype /Link /Type /Annot >>
endobj
81 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 276.663 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 149.374 565.419 161.329 574.266 ] /Subtype /Link /Type /Annot >>
endobj
82 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 664.209 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 171.092 553.464 183.047 562.31 ] /Subtype /Link /Type /Annot >>
endobj
83 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 184.372 549.977 190.35 563.924 ] /Subtype /Link /Type /Annot >>
endobj
84 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 184.372 556.07 189.852 563.844 ] /Subtype /Link /Type /Annot >>
endobj
85 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 141.623 541.509 153.578 550.355 ] /Subtype /Link /Type /Annot >>
endobj
86 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 154.903 538.021 160.881 551.969 ] /Subtype /Link /Type /Annot >>
endobj
87 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 154.903 545.223 160.383 550.41 ] /Subtype /Link /Type /Annot >>
endobj
88 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 640.299 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 141.623 529.553 153.578 538.4 ] /Subtype /Link /Type /Annot >>
endobj
89 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 154.903 526.066 160.881 540.014 ] /Subtype /Link /Type /Annot >>
endobj
90 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 154.903 532.268 160.383 539.933 ] /Subtype /Link /Type /Annot >>
endobj
91 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 248.197 526.066 254.174 540.014 ] /Subtype /Link /Type /Annot >>
endobj
92 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 248.197 532.268 253.676 539.933 ] /Subtype /Link /Type /Annot >>
endobj
93 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 297.571 526.066 303.549 540.014 ] /Subtype /Link /Type /Annot >>
endobj
94 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 297.571 532.268 303.051 539.933 ] /Subtype /Link /Type /Annot >>
endobj
95 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 348.948 526.066 354.926 540.014 ] /Subtype /Link /Type /Annot >>
endobj
96 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 348.948 532.268 354.428 539.933 ] /Subtype /Link /Type /Annot >>
endobj
97 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 400.325 526.066 406.303 540.014 ] /Subtype /Link /Type /Annot >>
endobj
98 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 400.325 532.268 405.805 539.933 ] /Subtype /Link /Type /Annot >>
endobj
99 0 obj
<< /A << /D [ 345 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 132.664 350.141 141.13 361.501 ] /Subtype /Link /Type /Annot >>
endobj
100 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 276.663 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 90.081 277.254 102.036 286.101 ] /Subtype /Link /Type /Annot >>
endobj
101 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 82.33 265.299 94.285 274.145 ] /Subtype /Link /Type /Annot >>
endobj
102 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 95.61 261.812 101.587 275.759 ] /Subtype /Link /Type /Annot >>
endobj
103 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 95.61 269.014 101.089 274.2 ] /Subtype /Link /Type /Annot >>
endobj
104 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 640.299 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 82.33 253.344 94.285 262.19 ] /Subtype /Link /Type /Annot >>
endobj
105 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 95.61 249.857 101.587 263.804 ] /Subtype /Link /Type /Annot >>
endobj
106 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 95.61 256.058 101.089 263.724 ] /Subtype /Link /Type /Annot >>
endobj
107 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 179.669 249.857 185.647 263.804 ] /Subtype /Link /Type /Annot >>
endobj
108 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 179.669 256.058 185.149 263.724 ] /Subtype /Link /Type /Annot >>
endobj
109 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 220.402 249.857 226.38 263.804 ] /Subtype /Link /Type /Annot >>
endobj
110 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 220.402 256.058 225.882 263.724 ] /Subtype /Link /Type /Annot >>
endobj
111 0 obj
<< /A << /D [ 5 0 R /Fit ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 259.177 249.857 265.154 263.804 ] /Subtype /Link /Type /Annot >>
endobj
112 0 obj
<< /A << /D [ 8 0 R /XYZ 308.862 181.012 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 259.177 256.058 264.656 263.724 ] /Subtype /Link /Type /Annot >>
endobj
113 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 218.618 79.904 230.574 88.751 ] /Subtype /Link /Type /Annot >>
endobj
114 0 obj
<< /A << /D [ 9 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 374.556 293.57 381.53 304.474 ] /Subtype /Link /Type /Annot >>
endobj
115 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 410.785 158.865 420.748 166.341 ] /Subtype /Link /Type /Annot >>
endobj
116 0 obj
<< /A << /D [ 344 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 449.581 146.64 457.328 156.876 ] /Subtype /Link /Type /Annot >>
endobj
117 0 obj
<< /A << /D [ 345 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 341.292 89.661 349.039 99.896 ] /Subtype /Link /Type /Annot >>
endobj
118 0 obj
<< /Length 16914 >>
stream
q
q
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
BT
/F87 8.9664 Tf 50.112 712.329 Td [(T)80(able)-385(1.)-716(Summary)-386(of)-385(our)-385(ImageNet)-385(results)-386(and)-385(comparisons)-385(to)-386(certi\002ed)-385(patch)-385(defenses)-386(f)1(rom)-386(the)-385(literature:)-581(Clipped)-385(Bagnet)-385(\(CBN\),)]TJ 0.224 -10.959 Td [(B)]TJ/F87 7.1731 Tf 6.151 0 Td [(A)-22(G)]TJ/F87 8.9664 Tf 10.957 0 Td [(C)]TJ/F87 7.1731 Tf 6.429 0 Td [(E)-61(R)-2(T)]TJ/F87 8.9664 Tf 14.22 0 Td [(,)-296(Derandomized)-286(Smoothing)-286(\(DS\),)-287(and)-286(P)15(atchGuard)-287(\(PG\).)-286(T)35(ime)-287(refers)-286(to)-287(the)-286(inference)-287(time)-286(for)-287(a)-286(batch)-286(of)-287(1024)-286(images,)]TJ/F102 8.9664 Tf 430.995 0 Td [(b)]TJ/F87 8.9664 Tf 6.518 0 Td [(is)-286(the)]TJ -475.494 -10.959 Td [(ablation)-250(size,)-250(and)]TJ/F102 8.9664 Tf 64.745 0 Td [(s)]TJ/F87 8.9664 Tf 6.535 0 Td [(is)-250(the)-250(ablation)-250(stride.)-310(An)-250(e)15(xtended)-250(v)15(ersion)-250(is)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(H)]TJ
0 g 0 G
[(.)]TJ
0 g 0 G
ET
q
1 0 0 1 118.101 676.762 cm
[]0 d 0 J 0.797 w 0 0 m 356.531 0 l S
Q
BT
/F87 9.9626 Tf 195.461 665.207 Td [(Standard)-250(and)-250(Certi\002ed)-250(Accurac)15(y)-250(on)-250(ImageNet)-250(\(%\))]TJ
ET
q
1 0 0 1 118.101 659.656 cm
[]0 d 0 J 0.498 w 0 0 m 356.531 0 l S
Q
q
1 0 0 1 218.644 644.663 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 224.621 648.25 Td [(Standard)-1200(1%)-250(pix)15(els)-1200(2%)-250(pix)15(els)-1200(3%)-250(pix)15(els)]TJ
ET
q
1 0 0 1 420.147 644.663 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 426.124 648.25 Td [(T)35(ime)-250(\(sec\))]TJ
ET
q
1 0 0 1 118.101 642.698 cm
[]0 d 0 J 0.498 w 0 0 m 356.531 0 l S
Q
BT
/F91 9.9626 Tf 124.079 631.293 Td [(Baselines)]TJ
ET
q
1 0 0 1 118.101 625.741 cm
[]0 d 0 J 0.498 w 0 0 m 356.531 0 l S
Q
BT
/F87 9.9626 Tf 124.079 614.335 Td [(Standard)-250(ResNet-50)]TJ
ET
q
1 0 0 1 218.644 610.749 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 614.335 Td [(76.1)-3581<97>-4157<97>-4157<97>]TJ
ET
q
1 0 0 1 420.147 610.749 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 438.672 614.335 Td [(0.67)]TJ -314.593 -11.955 Td [(WRN-101-2)]TJ
ET
q
1 0 0 1 218.644 598.794 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 602.38 Td [(78.9)-3581<97>-4157<97>-4157<97>]TJ
ET
q
1 0 0 1 420.147 598.794 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 441.163 602.38 Td [(3.1)]TJ -317.084 -11.955 Td [(V)60(iT)92(-S)]TJ
ET
q
1 0 0 1 218.644 586.838 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 590.425 Td [(79.9)-3581<97>-4157<97>-4157<97>]TJ
ET
q
1 0 0 1 420.147 586.838 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 441.163 590.425 Td [(0.4)]TJ -317.084 -11.955 Td [(V)60(iT)92(-B)]TJ
ET
q
1 0 0 1 218.644 574.883 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 578.47 Td [(81.8)-3581<97>-4157<97>-4157<97>]TJ
ET
q
1 0 0 1 420.147 574.883 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 438.672 578.47 Td [(0.95)]TJ -314.593 -11.955 Td [(CBN)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(63)]TJ
0 g 0 G
[(])]TJ
ET
q
1 0 0 1 218.644 562.928 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 566.515 Td [(49.5)-3206(13.4)-3657(7.1)-3907(3.1)]TJ
ET
q
1 0 0 1 420.147 562.928 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 438.672 566.515 Td [(3.05)]TJ -314.344 -11.955 Td [(B)]TJ/F87 7.9701 Tf 6.834 0 Td [(A)-22(G)]TJ/F87 9.9626 Tf 12.174 0 Td [(C)]TJ/F87 7.9701 Tf 7.144 0 Td [(E)-61(R)-2(T)]TJ/F87 9.9626 Tf 18.291 0 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(32)]TJ
0 g 0 G
[(])]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 16.597 3.615 Td [<87>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 218.644 550.973 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 554.56 Td [(45.3)-3581<97>-3782(22.9)-3782<97>]TJ
ET
q
1 0 0 1 420.147 550.973 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 438.672 554.56 Td [(8.60)]TJ -314.593 -11.956 Td [(DS)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 31.82 2.075 Td [(*)]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 218.644 539.018 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 542.604 Td [(44.4)-3206(17.7)-3407(14.0)-3407(11.2)]TJ
ET
q
1 0 0 1 420.147 539.018 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 436.181 542.604 Td [(149.5)]TJ -312.102 -11.955 Td [(PG)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(56)]TJ
0 g 0 G
[(])]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 31.82 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 218.644 527.063 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F8 9.9626 Tf 231.481 530.649 Td [(55)]TJ/F11 9.9626 Tf 9.963 0 Td [(:)]TJ/F8 9.9626 Tf 2.768 0 Td [(1)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 4.981 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
/F8 9.9626 Tf 31.663 -3.616 Td [(32)]TJ/F11 9.9626 Tf 9.963 0 Td [(:)]TJ/F8 9.9626 Tf 2.767 0 Td [(3)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 4.981 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
/F8 9.9626 Tf 33.666 -3.616 Td [(26)]TJ/F11 9.9626 Tf 9.963 0 Td [(:)]TJ/F8 9.9626 Tf 2.767 0 Td [(0)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 4.981 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
/F8 9.9626 Tf 33.666 -3.616 Td [(19)]TJ/F11 9.9626 Tf 9.963 0 Td [(:)]TJ/F8 9.9626 Tf 2.767 0 Td [(7)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 4.981 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 420.147 527.063 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F8 9.9626 Tf 438.534 530.649 Td [(3)]TJ/F11 9.9626 Tf 4.981 0 Td [(:)]TJ/F8 9.9626 Tf 2.767 0 Td [(05)]TJ
ET
q
1 0 0 1 118.101 525.098 cm
[]0 d 0 J 0.498 w 0 0 m 356.531 0 l S
Q
BT
/F91 9.9626 Tf 124.079 513.692 Td [(Smoothed)-250(models)]TJ
ET
q
1 0 0 1 118.101 508.141 cm
[]0 d 0 J 0.498 w 0 0 m 356.531 0 l S
Q
BT
/F87 9.9626 Tf 124.079 496.735 Td [(ResNet-50)-250(\(b)-250(=)-250(19\))]TJ
ET
q
1 0 0 1 218.644 493.148 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 496.735 Td [(51.5)-3206(22.8)-3407(18.3)-3407(15.3)]TJ
ET
q
1 0 0 1 420.147 493.148 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 436.181 496.735 Td [(149.5)]TJ -312.102 -11.955 Td [(V)60(iT)92(-S)-250(\(b)-250(=)-250(19\))]TJ
ET
q
1 0 0 1 218.644 481.193 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 233.612 484.78 Td [(63.5)-3206(36.8)-3407(31.6)-3407(27.9)]TJ
ET
q
1 0 0 1 420.147 481.193 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 438.672 484.78 Td [(14.0)]TJ
ET
q
1 0 0 1 118.101 479.228 cm
[]0 d 0 J 0.498 w 0 0 m 356.531 0 l S
Q
BT
/F87 9.9626 Tf 124.079 467.822 Td [(WRN-101-2)-250(\(b)-250(=)-250(19\))]TJ
ET
q
1 0 0 1 218.644 464.236 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 467.822 Td [(61.4)-3206(33.3)-3407(28.1)-3407(24.1)]TJ
ET
q
1 0 0 1 420.147 464.236 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 436.181 467.822 Td [(694.5)]TJ -312.102 -11.955 Td [(V)60(iT)92(-B)-250(\(b)-250(=)-250(19\))]TJ
ET
q
1 0 0 1 218.644 452.281 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 455.867 Td [(69.3)]TJ/F86 9.9626 Tf 49.375 0 Td [(43.8)-3407(38.3)-3407(34.3)]TJ
ET
q
1 0 0 1 420.147 452.281 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 438.672 455.867 Td [(31.5)]TJ -314.593 -11.955 Td [(V)60(iT)92(-B)-250(\(b)-250(=)-250(37\))]TJ
ET
q
1 0 0 1 218.644 440.325 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 233.612 443.912 Td [(73.2)]TJ/F87 9.9626 Tf 49.375 0 Td [(43.0)-3407(38.2)-3407(34.1)]TJ
ET
q
1 0 0 1 420.147 440.325 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 438.672 443.912 Td [(58.7)]TJ -314.593 -11.955 Td [(V)60(iT)92(-B)-250(\(b)-250(=)-250(19,)-250(s)-250(=)-250(10\))]TJ
ET
q
1 0 0 1 218.644 428.37 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 233.612 431.957 Td [(68.3)-3206(36.9)-3407(36.9)-3407(31.4)]TJ
ET
q
1 0 0 1 420.147 428.37 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 441.163 431.957 Td [(3.2)]TJ
ET
q
1 0 0 1 118.101 426.256 cm
[]0 d 0 J 0.797 w 0 0 m 356.531 0 l S
Q
0 g 0 G
0 g 0 G
0 g 0 G
BT
/F87 8.9664 Tf 50.112 398.261 Td [(T)80(able)-447(2.)-902(Summary)-447(of)-448(our)-447(CIF)74(AR-10)-447(results)-447(and)-447(comparisons)]TJ 0 -10.959 Td [(to)-425(ce)1(rti\002ed)-425(patch)-424(defenses)-425(from)-424(the)-425(literature:)-659(Clipped)-424(Bagnet)]TJ 0 -10.959 Td [(\(CBN\),)-427(Derandomized)-427(Smoothing)-427(\(DS\),)-427(and)-427(P)15(atchGuard)-426(\(PG\).)]TJ 0 -10.959 Td [(Here,)]TJ/F102 8.9664 Tf 22.249 0 Td [(b)]TJ/F87 8.9664 Tf 6.465 0 Td [(is)-281(the)-280(column)-281(ablation)-281(size)-280(out)-281(of)-281(32)-280(pix)15(els.)-402(An)-281(e)15(xtended)]TJ -28.714 -10.959 Td [(v)15(ersion)-250(is)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(H)]TJ
0 g 0 G
[(.)]TJ
0 g 0 G
ET
q
1 0 0 1 58.808 340.777 cm
[]0 d 0 J 0.797 w 0 0 m 216.367 0 l S
Q
BT
/F87 9.9626 Tf 64.786 329.221 Td [(Standard)-250(and)-250(Certi\002ed)-250(Accurac)15(y)-250(on)-250(CIF)74(AR-10)-250(\(%\))]TJ
ET
q
1 0 0 1 58.808 323.67 cm
[]0 d 0 J 0.498 w 0 0 m 216.367 0 l S
Q
q
1 0 0 1 150.255 308.678 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 156.232 312.264 Td [(Standard)]TJ/F8 9.9626 Tf 47.372 0 Td [(2)]TJ/F14 9.9626 Tf 7.196 0 Td [<02>]TJ/F8 9.9626 Tf 9.962 0 Td [(2)-1670(4)]TJ/F14 9.9626 Tf 28.812 0 Td [<02>]TJ/F8 9.9626 Tf 9.962 0 Td [(4)]TJ
ET
q
1 0 0 1 58.808 306.713 cm
[]0 d 0 J 0.498 w 0 0 m 216.367 0 l S
Q
BT
/F91 9.9626 Tf 64.786 295.307 Td [(Baselines)]TJ
ET
q
1 0 0 1 58.808 289.756 cm
[]0 d 0 J 0.498 w 0 0 m 216.367 0 l S
Q
BT
/F87 9.9626 Tf 64.786 278.35 Td [(CBN)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(63)]TJ
0 g 0 G
[(])]TJ
ET
q
1 0 0 1 150.255 274.763 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 165.223 278.35 Td [(84.2)-2339(44.2)-2392(9.3)]TJ -100.437 -11.955 Td [(DS)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 31.82 2.074 Td [(*)]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 150.255 262.808 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 165.223 266.395 Td [(83.9)-2339(68.9)-2142(56.2)]TJ -100.437 -11.956 Td [(PG)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(56)]TJ
0 g 0 G
[(])]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 31.82 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 150.255 250.853 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 163.231 254.439 Td [(84.7)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 17.435 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
/F87 9.9626 Tf 23.298 -3.616 Td [(69.2)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 17.435 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
/F87 9.9626 Tf 21.339 -3.616 Td [(57.7)]TJ
1 0 0 rg 1 0 0 RG
1 0 0 rg 1 0 0 RG
/F87 6.9738 Tf 17.435 3.616 Td [<86>]TJ
1 0 0 rg 1 0 0 RG
0 g 0 G
ET
q
1 0 0 1 58.808 248.888 cm
[]0 d 0 J 0.498 w 0 0 m 216.367 0 l S
Q
BT
/F91 9.9626 Tf 64.786 237.482 Td [(Smoothed)-250(models)]TJ
ET
q
1 0 0 1 58.808 231.931 cm
[]0 d 0 J 0.498 w 0 0 m 216.367 0 l S
Q
BT
/F87 9.9626 Tf 64.786 220.525 Td [(ResNet-50)-250(\(b)-250(=)-250(4\))]TJ
ET
q
1 0 0 1 150.255 216.938 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 165.223 220.525 Td [(86.4)-2339(71.6)-2142(59.0)]TJ -100.437 -11.955 Td [(V)60(iT)92(-S)-250(\(b)-250(=)-250(4\))]TJ
ET
q
1 0 0 1 150.255 204.983 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 165.223 208.57 Td [(88.4)-2339(75.0)-2142(63.8)]TJ
ET
q
1 0 0 1 58.808 203.019 cm
[]0 d 0 J 0.498 w 0 0 m 216.367 0 l S
Q
BT
/F87 9.9626 Tf 64.786 191.613 Td [(WRN-101-2)-250(\(b)-250(=)-250(4\))]TJ
ET
q
1 0 0 1 150.255 188.026 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 165.223 191.613 Td [(88.2)-2339(73.9)-2142(62.0)]TJ -100.437 -11.955 Td [(V)60(iT)92(-B)-250(\(b)-250(=)-250(4\))]TJ
ET
q
1 0 0 1 150.255 176.071 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 165.223 179.658 Td [(90.8)-2339(78.1)-2142(67.6)]TJ
ET
q
1 0 0 1 58.808 173.957 cm
[]0 d 0 J 0.797 w 0 0 m 216.367 0 l S
Q
0 g 0 G
BT
/F86 10.9589 Tf 50.112 137.756 Td [(3.1.)-250(V)37(iTs)-250(outperf)25(orm)-250(ResNets)-250(on)-250(image)-250(ablations.)]TJ/F87 9.9626 Tf 11.955 -20.89 Td [(W)80(e)-406<02727374>-405(isolate)-406(the)-405(ef)25(fect)-406(of)-405(using)-406(a)-405(V)60(iT)-406(instead)-405(of)-406(a)]TJ -11.955 -11.956 Td [(ResNet)-297(as)-297(the)-297(base)-297(classi\002er)-297(for)-297(derandomized)-297(smoothing.)]TJ 0 -11.955 Td [(Speci\002cally)65(,)-418(we)-384(k)10(eep)-384(all)-385(smoothing)-384(parameters)-384<0278>15(ed)-385(and)]TJ 0 -11.955 Td [(only)-346(v)25(ary)-346(the)-347(base)-346(classi\002er)55(.)-599(F)15(ollo)25(wing)-346([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(],)-370(we)-346(use)-347(col-)]TJ
0 g 0 G
0 g 0 G
258.75 314.97 Td [(umn)-245(ablations)-246(of)-245(width)]TJ/F11 9.9626 Tf 94.462 0 Td [(b)]TJ/F8 9.9626 Tf 7.042 0 Td [(=)-278(4)]TJ/F87 9.9626 Tf 17.943 0 Td [(for)-245(CIF)74(AR-10)-246(and)]TJ/F11 9.9626 Tf 75.22 0 Td [(b)]TJ/F8 9.9626 Tf 7.043 0 Td [(=)-278(19)]TJ/F87 9.9626 Tf 22.924 0 Td [(for)]TJ -224.634 -11.956 Td [(ImageNet)-250(for)-250(both)-250(training)-250(and)-250(certi\002cation.)]TJ/F86 9.9626 Tf 0 -27.515 Td [(Ablation)-468(accuracy)70(.)]TJ/F87 9.9626 Tf 91.687 0 Td [(The)-468(performance)-468(of)-469(derandomized)]TJ -91.687 -11.955 Td [(smoothing)-341(entir)1(ely)-341(depends)-341(on)-340(whether)-341(the)-340(base)-341(classi\002er)]TJ 0 -11.956 Td [(can)-369(accurately)-370(classify)-369(ablated)-369(images.)-668(W)80(e)-369(thus)-370(measure)]TJ 0 -11.955 Td [(the)-230(accurac)15(y)-230(of)-231(V)60(iTs)-230(and)-230(ResNets)-230(at)-230(classifying)-231(col)1(u)-1(m)1(n)-231(ab-)]TJ 0 -11.955 Td [(lated)-314(images)-314(across)-314(a)-313(range)-314(of)-314(e)25(v)25(aluation)-314(ablation)-314(sizes)-314(as)]TJ 0 -11.955 Td [(sho)25(wn)-240(in)-239(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-240(3)]TJ
0 g 0 G
[(.)-307(W)80(e)-239<026e64>-240(that)-240(V)60(iTs)-239(are)-240(signi\002cantly)-240(more)]TJ 0 -11.955 Td [(accurate)-234(on)-233(these)-234(ablations)-234(than)-233(comparably)-234(sized)-234(ResNets.)]TJ 0 -11.955 Td [(F)15(or)-245(e)15(xample,)-247(on)-245(ImageNet,)-246(V)60(iT)92(-S)-246(has)-245(up)-246(to)-245(12%)-245(higher)-246(ac-)]TJ 0 -11.956 Td [(curac)15(y)-250(on)-250(ablations)-250(than)-250(ResNet-50.)]TJ/F86 9.9626 Tf 0 -27.515 Td [(Certi\002ed)-327(patch)-326(r)18(ob)20(ustness.)]TJ/F87 9.9626 Tf 125.401 0 Td [(W)80(e)-327(ne)15(xt)-326(measure)-327(the)-327(ef)25(fect)]TJ -125.401 -11.955 Td [(of)-383(impro)15(v)15(ed)-384(ablation)-383(accurac)15(y)-383(on)-383(certi\002ed)-384(accurac)15(y)65(.)-710(W)80(e)]TJ 0 -11.956 Td [<026e64>-267(that)-266(using)-267(a)-266(V)60(iT)-267(as)-266(the)-267(base)-267(classi\002er)-266(in)-267(derandomized)]TJ 0 -11.955 Td [(smoothing)-224(substantially)-224(boosts)-224(certi\002ed)-225(accurac)15(y)-224(compared)]TJ
0 g 0 G
0 g 0 G
ET
q
1 0 0 1 308.862 178.82 cm
[]0 d 0 J 0.398 w 0 0 m 94.499 0 l S
Q
BT
/F87 5.9776 Tf 319.721 170.897 Td [(*)]TJ/F87 7.9701 Tf 3.487 -1.492 Td [(W)80(e)-323(found)-324(that)-323(ResNets)-324(could)-323(achie)25(v)15(e)-324(a)-323(signi\002cantly)-324(higher)-323(certi\002ed)]TJ -14.346 -9.464 Td [(accurac)15(y)-289(than)-288(w)10(as)-289(reported)-289(by)-288([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])-289(if)-289(we)-288(use)-289(early)-288(stopping-based)-289(model)]TJ 0 -9.465 Td [(selection.)-310(W)80(e)-250(elaborate)-250(further)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(A)]TJ
0 g 0 G
[(.)]TJ/F87 5.9776 Tf 10.859 -6.844 Td [<86>]TJ/F87 7.9701 Tf 3.487 -2.813 Td [(The)-270(P)15(atchGuard)-270(defense)-269(uses)-270(a)-270(speci\002c)-270(mask)-270(size)-269(that)-270(guarantees)-270(ro-)]TJ -14.346 -9.464 Td [(b)20(ustness)-266(to)-266(patches)-267(sm)1(aller)-267(than)-266(the)-266(mask,)-270(and)-266(pro)15(vides)-267(no)-266(guarantees)-266(for)]TJ 0 -9.465 Td [(lar)18(ger)-319(patches.)-516(In)-318(this)-319(table,)-336(we)-318(report)-319(their)-319(best)-318(results:)-448(each)-318(patch)-319(size)]TJ 0 -9.464 Td [(corresponds)-193(to)-194(a)-193(separate)-193(model)-194(that)-193(achie)25(v)15(es)-193(0%)-193(certi\002ed)-194(accurac)15(y)-193(ag)5(ainst)]TJ 0 -9.465 Td [(lar)18(ger)-263(patches.)-349(Comparisons)-263(across)-263(the)-264(indi)25(vidual)-263(models)-263(can)-263(be)-263(found)-263(in)]TJ 0 -9.465 Td [(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(H)]TJ
0 g 0 G
[(.)]TJ/F87 5.9776 Tf 10.859 -6.844 Td [<87>]TJ/F87 7.9701 Tf 3.487 -2.813 Td [(No)-250(code)-250(w)10(as)-250(a)20(v)25(ailable,)-250(so)-250(we)-250(e)15(xtracted)-250(the)-250(numbers)-250(from)-250(the)-250(paper)55(.)]TJ
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/2gFdkbPEncJnkjfDYxYARg Do
Q
endstream
endobj
119 0 obj
<< /Font << /F102 348 0 R /F11 331 0 R /F14 334 0 R /F8 339 0 R /F86 322 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /2gFdkbPEncJnkjfDYxYARg 349 0 R >> >>
endobj
120 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 207.125 161.06 218.084 169.221 ] /Subtype /Link /Type /Annot >>
endobj
121 0 obj
<< /A << /D [ 9 0 R /XYZ 50.112 435.095 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 184.313 113.712 191.287 124.616 ] /Subtype /Link /Type /Annot >>
endobj
122 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 640.299 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 377.863 696.986 389.818 705.833 ] /Subtype /Link /Type /Annot >>
endobj
123 0 obj
<< /A << /D [ 8 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 417.746 594.239 424.72 605.143 ] /Subtype /Link /Type /Annot >>
endobj
124 0 obj
<< /A << /D [ 345 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 465.573 570.329 474.759 581.233 ] /Subtype /Link /Type /Annot >>
endobj
125 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 382.649 508.848 394.604 517.695 ] /Subtype /Link /Type /Annot >>
endobj
126 0 obj
<< /A << /D [ 10 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 536.644 422.662 543.618 433.566 ] /Subtype /Link /Type /Annot >>
endobj
127 0 obj
<< /A << /D [ 343 0 R /XYZ 50.112 159.388 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 439.859 398.752 456.517 409.656 ] /Subtype /Link /Type /Annot >>
endobj
128 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 363.845 388.412 375.8 397.258 ] /Subtype /Link /Type /Annot >>
endobj
129 0 obj
<< /A << /D [ 350 0 R /XYZ 50.112 491.412 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 337.096 362.444 353.754 373.348 ] /Subtype /Link /Type /Annot >>
endobj
130 0 obj
<< /A << /D [ 10 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 536.644 326.579 543.618 337.483 ] /Subtype /Link /Type /Annot >>
endobj
131 0 obj
<< /Length 10524 >>
stream
q
q
0 g 0 G
0 g 0 G
0 g 0 G
1 0 0 1 50.112 624.447 cm
q
.42874 0 0 .42874 0 0 cm
q
1 0 0 1 0 0 cm
/Im3 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -624.447 cm
BT
/F87 6.9738 Tf 149.51 615.879 Td [(\(a\))-250(CIF)74(AR-10)]TJ
0 g 0 G
ET
1 0 0 1 50.112 516.938 cm
q
.42874 0 0 .42874 0 0 cm
q
1 0 0 1 0 0 cm
/Im4 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -516.938 cm
BT
/F87 6.9738 Tf 150.225 508.371 Td [(\(b\))-250(ImageNet)]TJ
0 g 0 G
0 g 0 G
/F87 8.9664 Tf -100.113 -20.025 Td [(Figure)-388(3.)-723(Accuracies)-387(on)-388(column-ablated)-388(im)1(ages)-388(for)-388(models)-387(on)]TJ 0 -10.959 Td [(CIF)74(AR-10)-378(and)-379(ImageNet.)-695(The)-378(models)-378(were)-379(trained)-378(on)-378(column)]TJ 0 -10.959 Td [(ablations)-328(of)-327(width)]TJ/F102 8.9664 Tf 69.085 0 Td [(b)]TJ/F101 8.9664 Tf 7.835 0 Td [(=)-433(19)]TJ/F87 8.9664 Tf 23.206 0 Td [(for)-328(ImageNet)-327(and)]TJ/F102 8.9664 Tf 67.57 0 Td [(b)]TJ/F101 8.9664 Tf 7.835 0 Td [(=)-433(4)]TJ/F87 8.9664 Tf 18.598 0 Td [(for)-328(CIF)74(AR-)]TJ -194.129 -10.959 Td [(10,)-348(and)-328(e)25(v)25(aluated)-329(on)-328(a)-328(range)-329(of)-328(ablation)-328(sizes.)-545(V)60(iTs)-328(outperform)]TJ 0 -10.959 Td [(ResNets)-250(on)-250(image)-250(ablations)-250(by)-250(a)-250(sizeable)-250(mar)18(gin.)]TJ
0 g 0 G
0 g 0 G
0 g 0 G
ET
1 0 0 1 50.112 333.082 cm
q
.42874 0 0 .42874 0 0 cm
q
1 0 0 1 0 0 cm
/Fm1 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -333.082 cm
BT
/F87 6.9738 Tf 149.51 324.514 Td [(\(a\))-250(CIF)74(AR-10)]TJ
0 g 0 G
ET
1 0 0 1 50.112 223.615 cm
q
.42874 0 0 .42874 0 0 cm
q
1 0 0 1 0 0 cm
/Im6 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -223.615 cm
BT
/F87 6.9738 Tf 150.225 215.047 Td [(\(b\))-250(ImageNet)]TJ
0 g 0 G
0 g 0 G
/F87 8.9664 Tf -100.113 -20.025 Td [(Figure)-434(4.)-860(Certi\002ed)-434(accuracies)-434(for)-433(V)60(iT)-434(and)-433(ResNet)-434(models)-433(on)]TJ 0 -10.959 Td [(CIF)74(AR-10)-262(and)-263(ImageNet)-262(for)-262(v)25(arious)-263(adv)15(ersarial)-262(patch)-262(sizes.)-347(Cer)20(-)]TJ 0 -10.959 Td [(ti\002cation)-314(w)10(as)-314(performed)-314(using)-315(a)-314<0278>15(ed)-314(ablation)-314(of)-314(size)]TJ/F102 8.9664 Tf 199.944 0 Td [(b)]TJ/F101 8.9664 Tf 7.604 0 Td [(=)-408(4)]TJ/F87 8.9664 Tf 18.247 0 Td [(for)]TJ -225.795 -10.958 Td [(CIF)74(AR-10)-250(and)]TJ/F102 8.9664 Tf 55.125 0 Td [(b)]TJ/F101 8.9664 Tf 6.509 0 Td [(=)-285(19)]TJ/F87 8.9664 Tf 21.184 0 Td [(for)-250(ImageNet)-250(\(as)-250(in)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(]\).)]TJ
0 g 0 G
0 g 0 G
/F87 9.9626 Tf -82.818 -33.325 Td [(to)-372(ResNets)-371(across)-372(a)-372(range)-372(of)-371(model)-372(sizes)-372(and)-372(adv)15(ersarial)]TJ 0 -11.956 Td [(patch)-394(sizes,)-431(as)-394(sho)25(wn)-395(in)-394(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-395(4)]TJ
0 g 0 G
[(.)-743(F)15(or)-394(e)15(xample,)-431(ag)5(ainst)]TJ/F8 9.9626 Tf 0 -11.955 Td [(32)]TJ/F14 9.9626 Tf 10.81 0 Td [<02>]TJ/F8 9.9626 Tf 8.597 0 Td [(32)]TJ/F87 9.9626 Tf 12.084 0 Td [(adv)15(ersarial)-213(patches)-213(on)-213(ImageNet)-213(\(2%)-213(of)-213(the)-213(image\),)]TJ -31.491 -11.955 Td [(a)-243(smoothed)-243(V)60(iT)92(-S)-244(impro)15(v)15(es)-243(certi\002ed)-243(accurac)15(y)-243(by)-243(14%)-244(o)15(v)15(er)]TJ 0 -11.955 Td [(a)-395(smoothed)-395(ResNet-50,)-431(while)-395(the)-394(lar)18(ger)-395(V)60(iT)92(-B)-395(reaches)-395(a)]TJ
0 g 0 G
0 g 0 G
258.75 629.037 Td [(certi\002ed)-244(accurac)15(y)-244(of)-245(39%\227well)-244(abo)15(v)15(e)-244(the)-244(highest)-245(reported)]TJ 0 -11.955 Td [(baseline)-250(of)-250(26%)-250([)]TJ
0 1 0 rg 0 1 0 RG
[(56)]TJ
0 g 0 G
[(].)]TJ/F86 9.9626 Tf 0 -28.959 Td [(Standard)-298(accuracy)70(.)]TJ/F87 9.9626 Tf 92.759 0 Td [(W)80(e)-298(further)-298<026e64>-297(that)-298(smoothed)-298(V)60(iTs)]TJ -92.759 -11.955 Td [(can)-315(mitig)5(ate)-314(the)-315(precipitous)-314(drop)-315(in)-315(sta)1(nd)-1(a)1(rd)-315(accurac)15(y)-315(ob-)]TJ 0 -11.955 Td [(serv)15(ed)-394(in)-393(pre)25(viously)-394(proposed)-394(certi\002ed)-393(defenses,)-430(particu-)]TJ 0 -11.955 Td [(larly)-376(so)-376(for)-375(lar)18(ger)-376(architectures)-376(and)-376(datasets.)-687(Indeed,)-408(the)]TJ 0 -11.955 Td [(smoothed)-515(V)60(iT)92(-B)-516(remains)-515(69%)-516(accurate)-515(on)-516(ImageNet\227)]TJ 0 -11.956 Td [(14.2%)-352(higher)-353(standard)-352(accurac)15(y)-353(than)-352(that)-352(of)-353(the)-352(best)-353(per)20(-)]TJ 0 -11.955 Td [(forming)-322(prior)-322(w)10(ork)-322(\(T)80(able)]TJ
1 0 0 rg 1 0 0 RG
[-322(1)]TJ
0 g 0 G
[(\).)-527(A)-322(full)-322(comparison)-322(between)]TJ 0 -11.955 Td [(the)-320(performance)-319(of)-320(smoothed)-320(models)-319(and)-320(their)-320(non-rob)20(ust)]TJ 0 -11.955 Td [(counterparts)-250(can)-250(be)-250(found)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(H)]TJ
0 g 0 G
[(.)]TJ/F86 10.9589 Tf 0 -21.253 Td [(3.2.)-250(Ablation)-250(size)-250(matters)]TJ/F87 9.9626 Tf 11.955 -18.375 Td [(In)-382(the)-382(pre)25(vious)-383(section,)-415(we)-382<0278>15(ed)-382(the)-382(width)-383(of)-382(column)]TJ -11.955 -11.955 Td [(ablations)-337(a)1(t)]TJ/F11 9.9626 Tf 49.873 0 Td [(b)]TJ/F8 9.9626 Tf 8.64 0 Td [(=)-438(19)]TJ/F87 9.9626 Tf 25.428 0 Td [(for)-337(derandomi)1(zed)-337(smoothing)-337(on)-336(Ima-)]TJ -83.941 -11.955 Td [(geNet,)-345(follo)25(wing)-326([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(].)-539(W)80(e)-326(no)25(w)-326(demonstrate)-327(that)-326(properly)]TJ 0 -11.955 Td [(choosing)-330(the)-329(ablation)-330(size)-330(can)-330(impro)15(v)15(e)-329(the)-330(standard)-330(accu-)]TJ 0 -11.955 Td [(rac)15(y)-318(e)25(v)15(en)-317(further)20<976279>-318(4%)-318(on)-317(ImageNet\227without)-318(sacri\002c-)]TJ 0 -11.956 Td [(ing)-250(certi\002ed)-250(performance.)]TJ 11.955 -12.397 Td [(Speci\002cally)65(,)-400(we)-370(tak)10(e)-370(ImageNet)-370(models)-371(tr)1(ained)-371(on)-370(col-)]TJ -11.955 -11.955 Td [(umn)-290(ablations)-290(with)-290(width)]TJ/F11 9.9626 Tf 105.66 0 Td [(b)]TJ/F8 9.9626 Tf 7.784 0 Td [(=)-352(19)]TJ/F87 9.9626 Tf 21.22 0 Td [(,)-300(and)-290(change)-291(the)-290(smooth-)]TJ -134.664 -11.956 Td [(ing)-204(procedure)-204(to)-204(use)-204(a)-204(dif)25(ferent)-203(width)-204(at)]TJ/F91 9.9626 Tf 158.209 0 Td [(test)]TJ/F87 9.9626 Tf 16.049 0 Td [(time.)-295(W)80(e)-203(report)]TJ -174.258 -11.955 Td [(the)-322(resulting)-323(standard)-322(and)-323(certi\002ed)-322(accuracies)-323(in)-322(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-323(5)]TJ
0 g 0 G
[(,)]TJ 0 -11.955 Td [(and)-319(defer)-319(additional)-319(e)15(xperiments)-319(on)-319(changing)-319(the)-319(ablation)]TJ 0 -11.955 Td [(size)-250(during)-250(training)-250(to)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(D.1)]TJ
0 g 0 G
[(.)]TJ 11.955 -12.398 Td [(Although)-308([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])-308(found)-308(a)-308(steep)-308(trade-of)25(f)-308(between)-308(certi\002ed)]TJ -11.955 -11.955 Td [(and)-190(standard)-191(accurac)15(y)-190(in)-190(CIF)74(AR-10)-190(\(which)-191(we)-190(v)15(erify)-190(in)-191(Ap-)]TJ 0 -11.955 Td [(pendix)]TJ
1 0 0 rg 1 0 0 RG
[-212(D.2)]TJ
0 g 0 G
[(\),)-220(we)-212<026e64>-212(this)-212(to)-212(not)-212(be)-212(the)-212(case)-212(for)-212(ImageNet)-212(for)]TJ 0 -11.955 Td [(either)-212(CNNs)-213(or)-212(V)60(iTs.)-298(W)80(e)-212(can)-213(thus)-212(substantially)-212(increase)-213(the)]TJ 0 -11.955 Td [(ablation)-297(size)-296(to)-297(impro)15(v)15(e)-297(standard)-296(accurac)15(y)]TJ/F91 9.9626 Tf 174.984 0 Td [(without)]TJ/F87 9.9626 Tf 33.032 0 Td [(signi\002-)]TJ -208.016 -11.956 Td [(cantly)-221(dropping)-222(certi\002ed)-221(performance)-221(as)-222(sho)25(wn)-221(in)-221(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-222(5)]TJ
0 g 0 G
[(.)]TJ 0 -11.955 Td [(F)15(or)-357(e)15(xample,)-384(increasing)-358(the)-357(width)-357(of)-357(column)-357(ablations)-358(to)]TJ/F11 9.9626 Tf 0 -11.955 Td [(b)]TJ/F8 9.9626 Tf 9.486 0 Td [(=)-523(37)]TJ/F87 9.9626 Tf 26.731 0 Td [(impro)15(v)15(es)-382(the)-383(standard)-382(accurac)15(y)-383(of)-382(the)-382(smoothed)]TJ -36.217 -11.955 Td [(V)60(iT)92(-B)-203(model)-204(by)-203(nearly)]TJ/F8 9.9626 Tf 92.37 0 Td [(4%)]TJ/F87 9.9626 Tf 15.311 0 Td [(to)-203(73%)-204(while)-203(maintaining)-204(a)-203(38%)]TJ -107.681 -11.955 Td [(certi\002ed)-207(accurac)15(y)-208(ag)5(ainst)]TJ/F8 9.9626 Tf 102.271 0 Td [(32)]TJ/F14 9.9626 Tf 10.608 0 Td [<02>]TJ/F8 9.9626 Tf 8.395 0 Td [(32)]TJ/F87 9.9626 Tf 12.03 0 Td [(patches.)-296(In)-207(addition)-208(to)-207(be-)]TJ -133.304 -11.955 Td [(ing)-292(12%)-292(higher)-293(than)-292(the)-292(standard)-292(accurac)15(y)-292(of)-292(the)-293(best)-292(per)20(-)]TJ 0 -11.956 Td [(forming)-283(prior)-282(w)10(ork,)-291(this)-283(model')55(s)-283(standard)-282(accurac)15(y)-283(is)-283(only)]TJ 0 -11.955 Td [(3%)-250(lo)25(wer)-250(than)-250(that)-250(of)-250(a)]TJ/F91 9.9626 Tf 95.481 0 Td [(non-r)45(ob)20(ust)]TJ/F87 9.9626 Tf 45.748 0 Td [(ResNet-50.)]TJ -129.274 -12.397 Td [(Thus,)-227(using)-222(smoothed)-222(V)60(iTs,)-227(we)-221(can)-222(achie)25(v)15(e)-222(state-of-the-)]TJ -11.955 -11.956 Td [(art)-230(certi\002ed)-230(rob)20(ustness)-231(to)-230(patch)-230(attacks)-230(in)-230(the)-231(ImageNet)-230(set-)]TJ 0 -11.955 Td [(ting)-257(while)-256(attaining)-257(standard)-256(accuracies)-257(that)-257(are)-256(more)-257(com-)]TJ 0 -11.955 Td [(parable)-250(to)-250(those)-250(of)-250(non-rob)20(ust)-250(ResNets.)]TJ/F86 11.9552 Tf 0 -25.237 Td [(4.)-250(F)25(aster)-250(infer)18(ence)-250(with)-250(V)37(iTs)]TJ/F87 9.9626 Tf 11.955 -19.372 Td [(Derandomized)-401(smoothing)-400(with)-401(column)-400(ablations)-401(is)-401(an)]TJ -11.955 -11.955 Td [(e)15(xpensi)25(v)15(e)-369(operation,)-399(especially)-369(for)-369(lar)18(ge)-369(images.)-668(Indeed,)]TJ 0 -11.955 Td [(an)-257(image)-257(with)]TJ/F11 9.9626 Tf 59.154 0 Td [(h)]TJ/F14 9.9626 Tf 8.008 0 Td [<02>]TJ/F11 9.9626 Tf 10.016 0 Td [(w)]TJ/F87 9.9626 Tf 9.963 0 Td [(pix)15(els)-257(has)]TJ/F11 9.9626 Tf 42.056 0 Td [(w)]TJ/F87 9.9626 Tf 9.963 0 Td [(column)-257(ablations,)-259(so)-257(the)]TJ -139.16 -11.955 Td [(forw)10(ard)-323(pass)-323(of)-323(smoothed)-323(model)-323(is)]TJ/F11 9.9626 Tf 146.495 0 Td [(w)]TJ/F87 9.9626 Tf 10.62 0 Td [(times)-323(slo)25(wer)-323(than)-323(a)]TJ -157.115 -11.956 Td [(normal)-338(forw)10(ard)-337(pass\227)]TJ/F91 9.9626 Tf 93.502 0 Td [(two)-338(or)37(der)10(s)-337(of)-338(ma)10(gnitude)]TJ/F87 9.9626 Tf 103.11 0 Td [(slo)25(wer)-338(on)]TJ -196.612 -11.955 Td [(ImageNet.)]TJ 11.955 -12.397 Td [(T)80(o)-454(address)-454(this,)-506(we)-454<02727374>-454(modify)-454(the)-455(V)60(iT)-454(architecture)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/Sw48vzpI-5QzEzzeO0s0Nw Do
Q
endstream
endobj
132 0 obj
<< /Font << /F101 351 0 R /F102 348 0 R /F11 331 0 R /F14 334 0 R /F8 339 0 R /F86 322 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /Fm1 352 0 R /Im3 353 0 R /Im4 354 0 R /Im6 355 0 R /Sw48vzpI-5QzEzzeO0s0Nw 356 0 R >> >>
endobj
133 0 obj
<< /A << /D [ 10 0 R /XYZ 50.112 468.497 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 67.093 533.227 81.539 544.131 ] /Subtype /Link /Type /Annot >>
endobj
134 0 obj
<< /A << /D [ 11 0 R /XYZ 308.862 721.993 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 267.104 521.272 281.55 532.175 ] /Subtype /Link /Type /Annot >>
endobj
135 0 obj
<< /A << /D [ 10 0 R /XYZ 308.862 564.275 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 105.576 200.117 112.549 211.021 ] /Subtype /Link /Type /Annot >>
endobj
136 0 obj
<< /A << /D [ 10 0 R /XYZ 308.862 391.731 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 220.486 188.162 227.46 199.066 ] /Subtype /Link /Type /Annot >>
endobj
137 0 obj
<< /A << /D [ 357 0 R /XYZ 50.112 720 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 140.712 128.386 148.791 139.29 ] /Subtype /Link /Type /Annot >>
endobj
138 0 obj
<< /A << /D [ 357 0 R /XYZ 50.112 700.637 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 307.866 207.435 323.417 217.622 ] /Subtype /Link /Type /Annot >>
endobj
139 0 obj
<< /Length 14963 >>
stream
q
q
0 g 0 G
0 g 0 G
0 g 0 G
1 0 0 1 53.814 621.062 cm
q
.43768 0 0 .43768 0 0 cm
q
1 0 0 1 0 0 cm
/Im7 Do
Q
Q
1 0 0 1 245.043 0 cm
q
.43768 0 0 .43768 0 0 cm
q
1 0 0 1 0 0 cm
/Im8 Do
Q
Q
0 g 0 G
1 0 0 1 -298.857 -621.062 cm
BT
/F87 8.9664 Tf 50.112 603.428 Td [(Figure)-277(5.)-391(Certi\002ed)-276(\(left\))-277(and)-277(standard)-277(\(right\))-277(accuracies)-277(for)-277(a)-277(collection)-276(of)-277(smoothed)-277(models)-277(trained)-277(with)-277(a)-277<0278>15(ed)-277(ablation)-276(size)]TJ/F102 8.9664 Tf 457.181 0 Td [(b)]TJ/F101 8.9664 Tf 6.968 0 Td [(=)-337(19)]TJ/F87 8.9664 Tf 21.885 0 Td [(on)]TJ -486.034 -10.958 Td [(ImageNet,)-338(and)-320(e)25(v)25(aluated)-321(with)-320(v)25(arying)-321(ablation)-320(sizes.)-521(Certi\002ed)-321(accurac)15(y)-320(remains)-320(stable)-321(across)-320(a)-321(range)-320(of)-320(ablation)-321(sizes,)-338(while)-320(standard)]TJ 0 -10.959 Td [(accurac)15(y)-250(substantially)-250(impro)15(v)15(es)-250(with)-250(lar)18(ger)-250(ablations.)]TJ
0 g 0 G
0 g 0 G
/F87 9.9626 Tf 0 -33.176 Td [(to)-334(a)20(v)20(oid)-334(unnecessary)-334(computation)-334(on)-334(mask)10(ed)-334(pix)15(els)-334(\(Sec-)]TJ 0 -11.955 Td [(tion)]TJ
1 0 0 rg 1 0 0 RG
[-249(4.1)]TJ
0 g 0 G
[(\).)-309(W)80(e)-249(then)-248(demonstrate)-249(that)-248(reducing)-249(the)-248(number)-249(of)]TJ 0 -11.955 Td [(ablations)-294(via)-294(striding)-295(of)25(fers)-294(further)-294(speed)-294(up)-294(\(Section)]TJ
1 0 0 rg 1 0 0 RG
[-295(4.2)]TJ
0 g 0 G
[(\).)]TJ 0 -11.956 Td [(These)-367(tw)10(o)-368(\(complementary\))-367(modi\002cations)-367(v)25(astly)-368(impro)15(v)15(e)]TJ 0 -11.955 Td [(the)-334(inference)-334(time)-334(for)-334(smoothed)-334(V)60(iTs,)-356(making)-334(them)-334(com-)]TJ 0 -11.955 Td [(parable)-292(in)-291(speed)-292(to)-291(standard)-292(\(non-rob)20(ust\))-291(con)40(v)20(olutional)-292(ar)20(-)]TJ 0 -11.955 Td [(chitectures.)]TJ/F86 10.9589 Tf 0 -19.982 Td [(4.1.)-250(Dr)18(opping)-250(mask)10(ed)-250(tok)10(ens)]TJ/F87 9.9626 Tf 11.955 -17.951 Td [(Recall)-270(that)-270(the)-270<02727374>-271(operation)-270(in)-270(a)-270(V)60(iT)-270(is)-270(to)-270(split)-271(and)-270(en-)]TJ -11.955 -11.955 Td [(code)-326(the)-325(input)-326(image)-325(as)-326(a)-326(set)-325(of)]TJ/F91 9.9626 Tf 133.857 0 Td [(tok)10(ens)]TJ/F87 9.9626 Tf 25.354 0 Td [(,)-345(where)-325(each)-326(tok)10(en)]TJ -159.211 -11.956 Td [(corresponds)-200(to)-200(a)-200(patch)-200(in)-200(the)-200(image.)-293(Ho)25(we)25(v)15(er)40(,)-210(for)-200(image)-200(ab-)]TJ 0 -11.955 Td [(lations,)-313(a)-301(lar)18(ge)-300(number)-301(of)-300(these)-301(tok)10(ens)-301(correspond)-300(to)-301(fully)]TJ 0 -11.955 Td [(mask)10(ed)-250(re)15(gions)-250(of)-250(the)-250(image.)]TJ 11.955 -11.974 Td [(Our)-219(strate)15(gy)-220(i)1(s)-220(to)-219(pass)-219(only)-219(the)]TJ/F91 9.9626 Tf 123.613 0 Td [(subset)]TJ/F87 9.9626 Tf 27.27 0 Td [(of)-219(tok)10(ens)-220(that)-219(con-)]TJ -162.838 -11.955 Td [(tain)-297(an)-297(unmask)10(ed)-296(part)-297(of)-297(the)-297(original)-296(image,)-309(thus)-297(a)20(v)20(oiding)]TJ 0 -11.955 Td [(computation)-259(on)-260(fully)-259(mask)10(ed)-259(tok)10(ens.)-338(Speci\002cally)65(,)-261(gi)25(v)15(en)-260(an)]TJ 0 -11.955 Td [(image)-291(ablation,)-301(we)-290(alter)-291(the)-291(V)60(iT)-291(architecture)-290(to)-291(do)-291(the)-291(fol-)]TJ 0 -11.956 Td [(lo)25(wing)-250(steps:)]TJ
0 g 0 G
7.472 -19.981 Td [(1.)]TJ
0 g 0 G
[-500(Positionally)-270(encode)-270(the)-270(entire)-270(ablated)-270(image)-271(int)1(o)-271(a)-270(set)]TJ 12.453 -11.956 Td [(of)-250(tok)10(ens.)]TJ
0 g 0 G
-12.453 -20 Td [(2.)]TJ
0 g 0 G
[-500(Drop)-281(an)15(y)-281(tok)10(ens)-282(that)-281(correspond)-281(to)-281(a)]TJ/F91 9.9626 Tf 164.068 0 Td [(fully)]TJ/F87 9.9626 Tf 20.514 0 Td [(mask)10(ed)-281(re-)]TJ -172.129 -11.955 Td [(gion)-250(of)-250(the)-250(input.)]TJ
0 g 0 G
-12.453 -20.001 Td [(3.)]TJ
0 g 0 G
[-500(P)15(ass)-410(the)-411(remaining)-410(tok)10(ens)-411(through)-410(the)-411(self-attention)]TJ 12.453 -11.955 Td [(layers.)]TJ -19.925 -19.982 Td [(The)-478(algorithm)-478(for)-479(dropping)-478(mask)10(ed)-478(tok)10(ens)-478(is)-479(described)]TJ 0 -11.955 Td [(in)-361(Algorithm)]TJ
1 0 0 rg 1 0 0 RG
[-361(1)]TJ
0 g 0 G
[(,)-389(and)-361(the)-361(o)15(v)15(erall)-361(inference)-361(procedure)-362(for)-361(a)]TJ 0 -11.955 Td [(smoothed)-210(V)60(iT)-210(is)-211(summarized)-210(in)-210(Algorithm)]TJ
1 0 0 rg 1 0 0 RG
[-210(2)]TJ
0 g 0 G
[(.)-297(As)-210(one)-211(w)10(ould)]TJ 0 -11.955 Td [(e)15(xpect,)-338(since)-320(the)-320(positional)-320(encoding)-320(maintains)-321(the)-320(spatial)]TJ 0 -11.955 Td [(information)-430(of)-429(the)-430(remaining)-430(tok)10(ens,)-474(the)-430(V)60(iT')55(s)-430(accurac)15(y)]TJ 0 -11.956 Td [(on)-296(image)-296(ablations)-296(barely)-295(changes)-296(when)-296(we)-296(drop)-296(the)-296(fully)]TJ 0 -11.955 Td [(mask)10(ed)-364(tok)10(ens.)-654(W)80(e)-364(defer)-365(a)-364(detailed)-364(analysis)-365(of)-364(this)-365(phe-)]TJ 0 -11.955 Td [(nomenon)-250(to)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(E)]TJ
0 g 0 G
[(.)]TJ/F86 9.9626 Tf 0 -26.629 Td [(Computational)-198(complexity)70(.)]TJ/F87 9.9626 Tf 124.422 0 Td [(W)80(e)-198(no)25(w)-198(pro)15(vide)-198(an)-198(informal)]TJ -124.422 -11.955 Td [(summary)-414(of)-414(the)-414(computational)-414(comple)15(xity)-414(of)-414(this)-414(proce-)]TJ 0 -11.955 Td [(dure,)-363(and)-340(defer)-341(a)-340(formal)-341(asymptotic)-340(analysis)-340(to)-341(Appendix)]TJ
0 g 0 G
0 g 0 G
ET
q
1 0 0 1 308.862 557.899 cm
[]0 d 0 J 0.797 w 0 0 m 236.25 0 l S
Q
0 g 0 G
BT
/F86 9.9626 Tf 308.862 548.644 Td [(Algorithm)-293(1)]TJ/F87 9.9626 Tf 55.092 0 Td [(Mechanism)-293(for)-293(processing)-293(an)-293(image)-293(ablation)]TJ/F77 9.9626 Tf -55.092 -11.955 Td [(z)]TJ/F14 9.9626 Tf 8.152 0 Td [(2)]TJ/F75 9.9626 Tf 9.703 0 Td [(R)]TJ/F7 6.9738 Tf 7.195 3.615 Td [(3)]TJ/F13 6.9738 Tf 3.971 0 Td [<02>]TJ/F10 6.9738 Tf 6.227 0 Td [(h)]TJ/F13 6.9738 Tf 4.664 0 Td [<02>]TJ/F10 6.9738 Tf 6.227 0 Td [(w)]TJ/F87 9.9626 Tf 9.098 -3.615 Td [(with)-266(mask)]TJ/F77 9.9626 Tf 44.042 0 Td [(m)]TJ/F87 9.9626 Tf 12.197 0 Td [(using)-266(a)-266(V)60(iT)-266(with)-265(tok)10(ens)-266(of)-266(size)]TJ/F11 9.9626 Tf -111.476 -11.955 Td [(p)]TJ/F14 9.9626 Tf 7.82 0 Td [<02>]TJ/F11 9.9626 Tf 10.557 0 Td [(p)]TJ/F87 9.9626 Tf 8.305 0 Td [(while)-331(dropping)-330(mask)10(ed)-331(tok)10(ens.)-551(The)-331(V)60(iT)-330(is)-330(decom-)]TJ -26.682 -11.956 Td [(posed)-250(into)-250(a)-250(positional)-250(encoder)]TJ/F11 9.9626 Tf 126.454 0 Td [(E)]TJ/F87 9.9626 Tf 10.42 0 Td [(and)-250(attention)-250(layers)]TJ/F11 9.9626 Tf 80.517 0 Td [(V)]TJ/F87 9.9626 Tf 8.025 0 Td [(.)]TJ
0 g 0 G
ET
q
1 0 0 1 308.862 508.43 cm
[]0 d 0 J 0.398 w 0 0 m 236.25 0 l S
Q
0 g 0 G
0 g 0 G
BT
/F87 7.9701 Tf 314.616 497.381 Td [(1:)]TJ
0 g 0 G
/F86 9.9626 Tf 11.182 0 Td [(function)]TJ/F87 9.9626 Tf 38.167 0 Td [(P)]TJ/F87 7.9701 Tf 6.037 0 Td [(R)-22(O)-61(C)-62(E)-62(S)-61(S)]TJ/F87 9.9626 Tf 32.747 0 Td [(A)]TJ/F87 7.9701 Tf 7.691 0 Td [(B)-62(L)-61(A)49(T)-61(I)-62(O)-62(N)]TJ/F87 9.9626 Tf 37.28 0 Td [(\()]TJ/F77 9.9626 Tf 3.317 0 Td [(z)]TJ/F11 9.9626 Tf 5.092 0 Td [(;)]TJ/F77 9.9626 Tf 4.428 0 Td [(m)]TJ/F87 9.9626 Tf 9.547 0 Td [(\))]TJ
0 g 0 G
/F87 7.9701 Tf -155.488 -11.955 Td [(2:)]TJ
0 g 0 G
/F14 9.9626 Tf 26.126 0 Td [(T)]TJ/F8 9.9626 Tf 10.726 0 Td [(=)]TJ/F14 9.9626 Tf 10.516 0 Td [(fg)]TJ/F91 9.9626 Tf 12.453 0 Td [(Initialize)-250(set)-250(of)-250(tok)10(ens)-250(for)-250(an)-250(ablation)]TJ
0 g 0 G
/F87 7.9701 Tf -59.821 -11.955 Td [(3:)]TJ
0 g 0 G
/F86 9.9626 Tf 26.126 0 Td [(f)25(or)]TJ/F11 9.9626 Tf 14.964 0 Td [(i;)-167(j)]TJ/F14 9.9626 Tf 15.3 0 Td [(2)]TJ/F8 9.9626 Tf 9.41 0 Td [([)]TJ/F11 9.9626 Tf 2.767 0 Td [(h=p)]TJ/F8 9.9626 Tf 15.734 0 Td [(])]TJ/F14 9.9626 Tf 4.981 0 Td [<02>]TJ/F8 9.9626 Tf 9.963 0 Td [([)]TJ/F11 9.9626 Tf 2.767 0 Td [(w)-27(=p)]TJ/F8 9.9626 Tf 17.394 0 Td [(])]TJ/F86 9.9626 Tf 5.258 0 Td [(do)]TJ
0 g 0 G
/F87 7.9701 Tf -124.664 -11.955 Td [(4:)]TJ
0 g 0 G
/F86 9.9626 Tf 41.07 0 Td [(if)-250(not)]TJ/F77 9.9626 Tf 24.907 0 Td [(m)]TJ/F10 6.9738 Tf 9.547 -1.799 Td [(ip)]TJ/F7 6.9738 Tf 6.926 0 Td [(:\()]TJ/F10 6.9738 Tf 5.368 0 Td [(i)]TJ/F7 6.9738 Tf 2.819 0 Td [(+1\))]TJ/F10 6.9738 Tf 13.201 0 Td [(p;j)-58(p)]TJ/F7 6.9738 Tf 14.279 0 Td [(:\()]TJ/F10 6.9738 Tf 5.369 0 Td [(j)]TJ/F7 6.9738 Tf 3.7 0 Td [(+1\))]TJ/F10 6.9738 Tf 13.2 0 Td [(p)]TJ/F8 9.9626 Tf 7.373 1.799 Td [(=)]TJ/F77 9.9626 Tf 10.516 0 Td [(0)]TJ/F86 9.9626 Tf 8.219 0 Td [(then)]TJ
0 g 0 G
/F87 7.9701 Tf -166.494 -11.955 Td [(5:)]TJ
0 g 0 G
/F14 9.9626 Tf 56.014 0 Td [(T)]TJ/F8 9.9626 Tf 10.726 0 Td [(=)]TJ/F14 9.9626 Tf 10.516 0 Td [(T)-476([)]TJ/F11 9.9626 Tf 19.028 0 Td [(E)]TJ/F8 9.9626 Tf 7.928 0 Td [(\()]TJ/F77 9.9626 Tf 3.875 0 Td [(z)]TJ/F10 6.9738 Tf 5.092 -1.799 Td [(ip)]TJ/F7 6.9738 Tf 6.925 0 Td [(:\()]TJ/F10 6.9738 Tf 5.369 0 Td [(i)]TJ/F7 6.9738 Tf 2.819 0 Td [(+1\))]TJ/F10 6.9738 Tf 13.2 0 Td [(p;j)-58(p)]TJ/F7 6.9738 Tf 14.28 0 Td [(:\()]TJ/F10 6.9738 Tf 5.369 0 Td [(j)]TJ/F7 6.9738 Tf 3.699 0 Td [(+1\))]TJ/F10 6.9738 Tf 13.201 0 Td [(p)]TJ/F11 9.9626 Tf 4.605 1.799 Td [(;)-167(i;)-166(j)]TJ/F8 9.9626 Tf 16.961 0 Td [(\))]TJ
0 g 0 G
/F87 7.9701 Tf -199.607 -11.956 Td [(6:)]TJ
0 g 0 G
/F86 9.9626 Tf 41.07 0 Td [(end)-250(if)]TJ
0 g 0 G
/F87 7.9701 Tf -41.07 -11.955 Td [(7:)]TJ
0 g 0 G
/F86 9.9626 Tf 26.126 0 Td [(end)-250(f)25(or)]TJ
0 g 0 G
/F87 7.9701 Tf -26.126 -11.955 Td [(8:)]TJ
0 g 0 G
/F86 9.9626 Tf 26.126 0 Td [(r)18(etur)15(n)]TJ/F11 9.9626 Tf 29.828 0 Td [(V)]TJ/F8 9.9626 Tf 8.026 0 Td [(\()]TJ/F14 9.9626 Tf 3.874 0 Td [(T)]TJ/F8 9.9626 Tf 7.958 0 Td [(\))]TJ
0 g 0 G
/F87 7.9701 Tf -75.812 -11.955 Td [(9:)]TJ
0 g 0 G
/F86 9.9626 Tf 11.182 0 Td [(end)-250(function)]TJ
0 g 0 G
ET
q
1 0 0 1 308.862 397.38 cm
[]0 d 0 J 0.398 w 0 0 m 236.25 0 l S
Q
q
1 0 0 1 308.862 385.355 cm
[]0 d 0 J 0.797 w 0 0 m 236.25 0 l S
Q
0 g 0 G
BT
/F86 9.9626 Tf 308.862 376.099 Td [(Algorithm)-263(2)]TJ/F87 9.9626 Tf 54.505 0 Td [(F)15(orw)10(ard)-263(pass)-264(for)-263(a)-264(smoothed)-263(V)60(iT)-264(on)-263(an)-264(input)]TJ -54.505 -11.955 Td [(image)]TJ/F77 9.9626 Tf 27.065 0 Td [(x)]TJ/F87 9.9626 Tf 8.763 0 Td [(for)]TJ/F11 9.9626 Tf 14.333 0 Td [(k)]TJ/F87 9.9626 Tf 8.216 0 Td [(classes)-273(and)-272(ablation)-273(set)]TJ/F14 9.9626 Tf 96.085 0 Td [(S)]TJ/F8 9.9626 Tf 6.78 0 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F87 9.9626 Tf 3.874 0 Td [(,)-278(where)]TJ/F77 9.9626 Tf 32.319 0 Td [(z)]TJ/F11 9.9626 Tf 5.092 0 Td [(;)]TJ/F77 9.9626 Tf 4.427 0 Td [(m)]TJ/F14 9.9626 Tf 12.733 0 Td [(2)]TJ -229.608 -11.955 Td [(S)]TJ/F8 9.9626 Tf 6.78 0 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F87 9.9626 Tf 6.245 0 Td [(are)-238(the)-238(image)-238(ablations)]TJ/F77 9.9626 Tf 94.143 0 Td [(z)]TJ/F87 9.9626 Tf 7.463 0 Td [(and)-238(the)-238(corresponding)-238(mask)]TJ/F77 9.9626 Tf -124.552 -11.955 Td [(m)]TJ/F87 9.9626 Tf 9.547 0 Td [(.)]TJ
0 g 0 G
ET
q
1 0 0 1 308.862 337.942 cm
[]0 d 0 J 0.398 w 0 0 m 236.25 0 l S
Q
0 g 0 G
0 g 0 G
BT
/F87 7.9701 Tf 314.616 326.894 Td [(1:)]TJ
0 g 0 G
/F86 9.9626 Tf 11.182 0 Td [(function)]TJ/F87 9.9626 Tf 38.167 0 Td [(S)]TJ/F87 7.9701 Tf 6.037 0 Td [(M)-62(O)-62(O)-22(T)-61(H)-62(E)-61(D)]TJ/F87 9.9626 Tf 42.61 0 Td [(V)]TJ/F87 7.9701 Tf 7.691 0 Td [(I)]TJ/F87 9.9626 Tf 3.148 0 Td [(T)-25(\()]TJ/F77 9.9626 Tf 9.654 0 Td [(x)]TJ/F87 9.9626 Tf 6.046 0 Td [(\))]TJ
0 g 0 G
/F87 7.9701 Tf -124.535 -11.955 Td [(2:)]TJ
0 g 0 G
/F11 9.9626 Tf 26.126 0 Td [(c)]TJ/F10 6.9738 Tf 4.312 -1.495 Td [(i)]TJ/F8 9.9626 Tf 6.084 1.495 Td [(=)-278(0)]TJ/F87 9.9626 Tf 17.988 0 Td [(for)]TJ/F11 9.9626 Tf 14.107 0 Td [(i)]TJ/F14 9.9626 Tf 6.2 0 Td [(2)]TJ/F8 9.9626 Tf 9.409 0 Td [([)]TJ/F11 9.9626 Tf 2.767 0 Td [(k)]TJ/F8 9.9626 Tf 5.5 0 Td [(])]TJ/F91 9.9626 Tf 5.258 0 Td [(//)-250(Initialize)-250(counts)-250(to)-250(zer)45(o)]TJ
0 g 0 G
/F87 7.9701 Tf -97.751 -11.955 Td [(3:)]TJ
0 g 0 G
/F86 9.9626 Tf 26.126 0 Td [(f)25(or)]TJ/F77 9.9626 Tf 14.964 0 Td [(z)]TJ/F11 9.9626 Tf 5.092 0 Td [(;)]TJ/F77 9.9626 Tf 4.428 0 Td [(m)]TJ/F14 9.9626 Tf 12.315 0 Td [(2)-278(S)]TJ/F8 9.9626 Tf 16.189 0 Td [(\()]TJ/F77 9.9626 Tf 3.874 0 Td [(x)]TJ/F8 9.9626 Tf 6.047 0 Td [(\))]TJ/F86 9.9626 Tf 6.365 0 Td [(do)]TJ
0 g 0 G
/F87 7.9701 Tf -95.4 -11.956 Td [(4:)]TJ
0 g 0 G
/F87 9.9626 Tf 41.07 0 Td [(y)-250(=)-275(P)]TJ/F87 7.9701 Tf 21.868 0 Td [(R)-22(O)-61(C)-62(E)-62(S)-61(S)]TJ/F87 9.9626 Tf 32.747 0 Td [(A)]TJ/F87 7.9701 Tf 7.691 0 Td [(B)-62(L)-61(A)49(T)-61(I)-62(O)-62(N)]TJ/F87 9.9626 Tf 37.28 0 Td [(\()]TJ/F77 9.9626 Tf 3.317 0 Td [(z)]TJ/F11 9.9626 Tf 5.092 0 Td [(;)]TJ/F77 9.9626 Tf 4.428 0 Td [(m)]TJ/F87 9.9626 Tf 9.547 0 Td [(\))]TJ
0 g 0 G
/F87 7.9701 Tf -163.04 -11.955 Td [(5:)]TJ
0 g 0 G
/F11 9.9626 Tf 41.07 0 Td [(c)]TJ/F10 6.9738 Tf 4.312 -1.494 Td [(y)]TJ/F8 9.9626 Tf 7.556 1.494 Td [(=)]TJ/F11 9.9626 Tf 10.516 0 Td [(c)]TJ/F10 6.9738 Tf 4.311 -1.494 Td [(y)]TJ/F8 9.9626 Tf 7.003 1.494 Td [(+)-222(1)]TJ/F91 9.9626 Tf 17.435 0 Td [(//)-250(Update)-250(counts)]TJ
0 g 0 G
/F87 7.9701 Tf -92.203 -11.955 Td [(6:)]TJ
0 g 0 G
/F86 9.9626 Tf 26.126 0 Td [(end)-250(f)25(or)]TJ
0 g 0 G
/F87 7.9701 Tf -26.126 -11.955 Td [(7:)]TJ
0 g 0 G
/F86 9.9626 Tf 26.126 0 Td [(r)18(etur)15(n)]TJ/F8 9.9626 Tf 29.828 0 Td [(arg)-181(max)]TJ/F10 6.9738 Tf 34.205 -2.435 Td [(y)]TJ/F11 9.9626 Tf 6.45 2.435 Td [(c)]TJ/F10 6.9738 Tf 4.311 -1.494 Td [(y)]TJ
0 g 0 G
/F87 7.9701 Tf -100.92 -10.461 Td [(8:)]TJ
0 g 0 G
/F86 9.9626 Tf 11.182 0 Td [(end)-250(function)]TJ
0 g 0 G
ET
q
1 0 0 1 308.862 238.904 cm
[]0 d 0 J 0.398 w 0 0 m 236.25 0 l S
Q
1 0 0 rg 1 0 0 RG
BT
/F87 9.9626 Tf 308.862 209.871 Td [(E.1)]TJ
0 g 0 G
[(.)-543(After)-327(tok)10(enization,)-347(the)-328(b)20(ulk)-328(of)-327(a)-328(V)60(iT)-327(consists)-328(of)-328(tw)10(o)]TJ 0 -11.955 Td [(main)-250(operation)-250(types:)]TJ
0 g 0 G
11.457 -18.871 Td [<95>]TJ
0 g 0 G
/F91 9.9626 Tf 8.468 0 Td [(Attention)-672(oper)15(ator)10(s)]TJ/F87 9.9626 Tf 81.722 0 Td [(,)-777(which)-672(ha)20(v)15(e)-672(costs)-672(that)-672(scale)]TJ -81.722 -11.955 Td [(quadratically)-384(with)-385(the)-384(number)-385(of)-384(tok)10(ens)-384(b)20(ut)-385(linearly)]TJ 0 -11.955 Td [(in)-250(the)-250(hidden)-250(dimension.)]TJ
0 g 0 G
-8.468 -19.398 Td [<95>]TJ
0 g 0 G
/F91 9.9626 Tf 8.468 0 Td [(Fully-connected)-217(oper)15(ator)11(s)]TJ/F87 9.9626 Tf 105.389 0 Td [(,)-223(which)-217(ha)20(v)15(e)-216(costs)-217(that)-216(scale)]TJ -105.389 -11.956 Td [(linearly)-239(with)-239(the)-239(number)-239(of)-239(tok)10(ens)-240(b)20(ut)-239(quadratically)-239(in)]TJ 0 -11.955 Td [(the)-250(hidden)-250(dimension.)]TJ -19.925 -18.871 Td [(Reducing)-396(the)-397(number)-396(of)-397(tok)10(ens)-396(thus)-397(directly)-396(reduces)-397(the)]TJ 0 -11.955 Td [(cost)-197(of)-197(attention)-198(and)-197(fully)-197(connected)-197(operators)-197(at)-198(a)-197(quadratic)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/NKspLyX-cmDwqQ8BCvDcfw Do
Q
endstream
endobj
140 0 obj
<< /CS /DeviceRGB /S /Transparency /Type /Group >>
endobj
141 0 obj
<< /Font << /F10 330 0 R /F101 351 0 R /F102 348 0 R /F11 331 0 R /F13 333 0 R /F14 334 0 R /F7 335 0 R /F75 336 0 R /F77 337 0 R /F8 339 0 R /F86 322 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /Im7 358 0 R /Im8 359 0 R /NKspLyX-cmDwqQ8BCvDcfw 360 0 R >> >>
endobj
142 0 obj
<< /A << /D [ 11 0 R /XYZ 50.112 505.379 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 157.885 524.866 164.859 535.77 ] /Subtype /Link /Type /Annot >>
endobj
143 0 obj
<< /A << /D [ 344 0 R /XYZ 50.112 194.902 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 229.528 512.91 246.185 523.814 ] /Subtype /Link /Type /Annot >>
endobj
144 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 52.433 175.546 64.388 184.392 ] /Subtype /Link /Type /Annot >>
endobj
145 0 obj
<< /A << /D [ 11 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 106.218 173.488 113.192 184.392 ] /Subtype /Link /Type /Annot >>
endobj
146 0 obj
<< /A << /D [ 8 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 490.574 623.198 497.547 634.102 ] /Subtype /Link /Type /Annot >>
endobj
147 0 obj
<< /A << /D [ 361 0 R /XYZ 50.112 562.111 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 434.609 611.243 442.141 622.147 ] /Subtype /Link /Type /Annot >>
endobj
148 0 obj
<< /A << /D [ 10 0 R /XYZ 50.112 468.497 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 436.184 587.333 450.63 598.237 ] /Subtype /Link /Type /Annot >>
endobj
149 0 obj
<< /A << /D [ 8 0 R /XYZ 50.112 725.978 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 424.088 504.364 431.062 514.55 ] /Subtype /Link /Type /Annot >>
endobj
150 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 452.005 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 331.078 416.675 343.033 425.422 ] /Subtype /Link /Type /Annot >>
endobj
151 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 546.65 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 346.27 416.675 358.225 425.422 ] /Subtype /Link /Type /Annot >>
endobj
152 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 711.034 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 361.462 416.575 373.418 425.422 ] /Subtype /Link /Type /Annot >>
endobj
153 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 545.654 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 376.655 416.575 388.61 425.422 ] /Subtype /Link /Type /Annot >>
endobj
154 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 569.564 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 391.847 416.575 403.802 425.422 ] /Subtype /Link /Type /Annot >>
endobj
155 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 311.532 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 311.183 404.719 323.138 413.466 ] /Subtype /Link /Type /Annot >>
endobj
156 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 240.797 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 325.66 404.62 337.615 413.466 ] /Subtype /Link /Type /Annot >>
endobj
157 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 617.385 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 340.137 404.62 352.092 413.466 ] /Subtype /Link /Type /Annot >>
endobj
158 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 430.087 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 354.614 404.62 366.569 413.466 ] /Subtype /Link /Type /Annot >>
endobj
159 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 113.275 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 369.091 404.62 381.046 413.466 ] /Subtype /Link /Type /Annot >>
endobj
160 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 334.446 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 383.568 404.62 395.523 413.466 ] /Subtype /Link /Type /Annot >>
endobj
161 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 228.842 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 398.045 404.62 410 413.466 ] /Subtype /Link /Type /Annot >>
endobj
162 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 182.017 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 412.522 404.62 424.477 413.466 ] /Subtype /Link /Type /Annot >>
endobj
163 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 323.487 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 426.998 404.62 438.954 413.466 ] /Subtype /Link /Type /Annot >>
endobj
164 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 675.168 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 338.474 392.665 345.448 401.242 ] /Subtype /Link /Type /Annot >>
endobj
165 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 464.956 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 348.34 392.665 360.295 401.511 ] /Subtype /Link /Type /Annot >>
endobj
166 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 363.188 392.665 375.143 401.511 ] /Subtype /Link /Type /Annot >>
endobj
167 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 277.659 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 378.035 392.665 389.99 401.511 ] /Subtype /Link /Type /Annot >>
endobj
168 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 218.879 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 392.883 392.665 404.838 401.511 ] /Subtype /Link /Type /Annot >>
endobj
169 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 230.834 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 407.731 392.764 419.686 401.511 ] /Subtype /Link /Type /Annot >>
endobj
170 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 172.055 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 422.578 392.764 434.533 401.511 ] /Subtype /Link /Type /Annot >>
endobj
171 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 510.785 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 437.426 392.665 449.381 401.511 ] /Subtype /Link /Type /Annot >>
endobj
172 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 721.993 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 380.37 356.799 387.343 365.646 ] /Subtype /Link /Type /Annot >>
endobj
173 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 336.438 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 467.772 356.799 479.728 365.646 ] /Subtype /Link /Type /Annot >>
endobj
174 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 675.168 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 343.462 308.978 350.436 317.556 ] /Subtype /Link /Type /Annot >>
endobj
175 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 336.438 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 354.99 308.978 366.945 317.825 ] /Subtype /Link /Type /Annot >>
endobj
176 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 184.01 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 423.567 308.859 435.522 317.825 ] /Subtype /Link /Type /Annot >>
endobj
177 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 515.725 297.023 527.68 305.87 ] /Subtype /Link /Type /Annot >>
endobj
178 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 383.263 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 476.008 235.321 487.963 244.168 ] /Subtype /Link /Type /Annot >>
endobj
179 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 276.663 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 528.345 175.546 540.3 184.392 ] /Subtype /Link /Type /Annot >>
endobj
180 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 664.209 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 357.384 163.59 369.339 172.437 ] /Subtype /Link /Type /Annot >>
endobj
181 0 obj
<< /A << /D [ 15 0 R /XYZ 50.112 640.299 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 450.117 163.59 462.073 172.437 ] /Subtype /Link /Type /Annot >>
endobj
182 0 obj
<< /Length 14553 >>
stream
q
q
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
BT
/F87 8.9664 Tf 50.112 712.329 Td [(T)80(able)-278(3.)-394(Multi)1(plicati)25(v)15(e)-278(speed)-278(up)-278(of)-278(inference)-278(for)-278(a)-278(smoothed)-277(V)60(iT)]TJ 0 -10.959 Td [(with)-374(dropped)-374(tok)10(ens)-373(o)15(v)14(e)1(r)-374(a)-374(smoothed)-374(ResNet,)-405(measured)-374(o)15(v)15(er)-373(a)]TJ 0 -10.959 Td [(batch)-250(of)-250(1024)-250(images)-250(with)]TJ/F102 8.9664 Tf 97.374 0 Td [(b)]TJ/F101 8.9664 Tf 6.509 0 Td [(=)-285(19)]TJ/F87 8.9664 Tf 18.943 0 Td [(.)]TJ
0 g 0 G
0 g 0 G
0 g 0 G
ET
q
1 0 0 1 68.716 676.762 cm
[]0 d 0 J 0.797 w 0 0 m 199.042 0 l S
Q
q
1 0 0 1 105.169 661.62 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 111.147 665.207 Td [(ResNet-18)-1200(ResNet-50)-1200(WRN-101)]TJ
ET
q
1 0 0 1 68.716 659.656 cm
[]0 d 0 J 0.498 w 0 0 m 199.042 0 l S
Q
BT
/F87 9.9626 Tf 74.972 648.25 Td [(V)60(iT)92(-T)]TJ
ET
q
1 0 0 1 105.169 644.663 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F86 9.9626 Tf 121.243 648.25 Td [(5.85x)]TJ/F87 9.9626 Tf 52.075 0 Td [(21.96x)-2421(101.99x)]TJ -98.072 -11.955 Td [(V)60(iT)92(-S)]TJ
ET
q
1 0 0 1 105.169 632.708 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 121.243 636.295 Td [(2.85x)]TJ/F86 9.9626 Tf 52.075 0 Td [(10.68x)]TJ/F87 9.9626 Tf 54.012 0 Td [(49.62x)]TJ -152.637 -11.956 Td [(V)60(iT)92(-B)]TJ
ET
q
1 0 0 1 105.169 620.753 cm
[]0 d 0 J 0.398 w 0 0 m 0 11.955 l S
Q
BT
/F87 9.9626 Tf 121.243 624.339 Td [(1.26x)-3227(4.75x)]TJ/F86 9.9626 Tf 106.087 0 Td [(22.04x)]TJ
ET
q
1 0 0 1 68.716 618.639 cm
[]0 d 0 J 0.797 w 0 0 m 199.042 0 l S
Q
0 g 0 G
BT
/F87 9.9626 Tf 50.112 575.839 Td [(and)-271(linear)-270(rate,)-276(respecti)25(v)15(ely)65(.)-372(F)15(or)-271(a)-271(small)-270(number)-271(of)-271(tok)10(ens,)]TJ 0 -11.955 Td [(the)-301(linear)-301(scaling)-301(from)-301(the)-302(fully-c)1(o)-1(nnec)1(ted)-302(operators)-301(tends)]TJ 0 -11.955 Td [(to)-285(dominate.)-415(The)-285(cost)-285(of)-285(processing)-285(column)-285(ablations)-285(thus)]TJ 0 -11.955 Td [(scales)-252(linearly)-252(with)-253(the)-252(width)-252(of)-252(the)-252(column,)-253(which)-252(we)-253(em-)]TJ 0 -11.955 Td [(pirically)-264(v)25(alidate)-263(in)-264(Figure)]TJ
1 0 0 rg 1 0 0 RG
[-264(6)]TJ
0 g 0 G
[(.)-351(Further)-264(details)-263(about)-264(ho)25(w)-264(we)]TJ 0 -11.955 Td [(time)-250(these)-250(models)-250(can)-250(be)-250(found)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(A.4)]TJ
0 g 0 G
[(.)]TJ
0 g 0 G
ET
1 0 0 1 50.112 404.302 cm
q
.4122 0 0 .4122 0 0 cm
q
1 0 0 1 0 0 cm
/Im9 Do
Q
Q
0 g 0 G
1 0 0 1 -50.112 -404.302 cm
BT
/F87 8.9664 Tf 50.112 386.668 Td [(Figure)-239(6.)-306(The)-239(a)20(v)15(erage)-238(time)-239(to)-238(compute)-239(a)-239(forw)10(ard)-238(pass)-239(for)-239(V)60(iTs)-238(on)]TJ/F101 8.9664 Tf 0 -10.959 Td [(1024)]TJ/F87 8.9664 Tf 20.546 0 Td [(column)-236(ablated)-236(images)-236(with)-236(v)25(arying)-236(a)1(blation)-236(sizes,)-239(with)-236(and)]TJ -20.546 -10.959 Td [(without)-221(dropping)-221(mask)10(ed)-220(tok)10(ens.)-301(The)-220(cost)-221(of)-221(processing)-221(a)-221(full)-220(im-)]TJ 0 -10.959 Td [(age)-220(without)-220(dropping)-220(mask)10(ed)-220(tok)10(ens)-220(corresponds)-220(to)-220(the)-219(maximum)]TJ 0 -10.959 Td [(ablation)-250(size)]TJ/F102 8.9664 Tf 47.315 0 Td [(b)]TJ/F101 8.9664 Tf 6.509 0 Td [(=)-285(224)]TJ/F87 8.9664 Tf 23.55 0 Td [(.)]TJ
0 g 0 G
0 g 0 G
/F86 10.9589 Tf -77.374 -38.111 Td [(4.2.)-250(Empirical)-250(speedup)-250(f)25(or)-250(smoothed)-250(V)37(iTs)]TJ/F87 9.9626 Tf 11.955 -19.208 Td [(Smoothed)-233(classi\002ers)-234(must)-233(process)-234(a)-233(lar)18(ge)-234(number)-233(of)-234(im-)]TJ -11.955 -11.955 Td [(age)-359(ablations)-358(in)-359(order)-359(to)-359(mak)10(e)-358(predictions)-359(and)-359(certify)-359(ro-)]TJ 0 -11.955 Td [(b)20(ustness.)-650(Consequently)65(,)-392(using)-364(our)-363(V)60(iT)-364(\(with)-363(dropped)-364(to-)]TJ 0 -11.956 Td [(k)10(ens\))-251(as)-250(the)-251(base)-251(classi\002er)-251(for)-250(derandomized)-251(smoothing)-251(di-)]TJ 0 -11.955 Td [(rectly)-268(speeds)-268(up)-268(inference)-268(time.)-364(In)-267(this)-268(section,)-273(we)-268(e)15(xplore)]TJ 0 -11.955 Td [(ho)25(w)-250(much)-250(f)10(aster)-250(smoothed)-250(V)60(iTs)-250(are)-250(in)-250(practice.)]TJ 11.955 -13.23 Td [(W)80(e)-313<02727374>-314(measure)-313(the)-314(number)-313(of)-313(images)-314(per)-313(second)-314(that)]TJ -11.955 -11.955 Td [(smoothed)-234(V)60(iTs)-233(and)-234(smoothed)-234(ResNets)-234(can)-233(process.)-305(W)80(e)-234(use)]TJ 0 -11.955 Td [(column)-355(ablations)-354(of)-355(size)]TJ/F11 9.9626 Tf 103.782 0 Td [(b)]TJ/F8 9.9626 Tf 8.972 0 Td [(=)-471(19)]TJ/F87 9.9626 Tf 25.94 0 Td [(on)-355(ImageNet,)-380(follo)25(wing)]TJ -138.694 -11.956 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(].)-307(In)-239(T)80(able)]TJ
1 0 0 rg 1 0 0 RG
[-240(3)]TJ
0 g 0 G
[-239(that)-240(describes)-239(our)-240(results,)-242(we)-239<026e64>-240(speedups)]TJ 0 -11.955 Td [(of)-219(5-22x)-219(for)-220(smoothed)-219(V)60(iTs)-219(o)15(v)15(er)-219(smoothed)-219(ResNets)-220(of)-219(sim-)]TJ 0 -11.955 Td [(ilar)-406(size,)-444(with)-406(lar)18(ger)-406(architectures)-405(sho)25(wing)-406(greater)-406(g)5(ains.)]TJ 0 -11.955 Td [(Notably)65(,)-364(using)-342(our)-341(lar)18(gest)-342(V)60(iT)-341(\(V)60(iT)92(-B\))-341(as)-342(the)-341(base)-342(classi-)]TJ 0 -11.955 Td [<026572>-368(is)-367(1.25x)-368(f)10(aster)-367(than)-368(using)-368(a)-367(ResNet-18,)-397(despite)-368(being)]TJ 0 -11.956 Td [(8x)-243(lar)18(ger)-242(in)-243(parameter)-242(count.)-308(Dropping)-243(mask)10(ed)-242(tok)10(ens)-243(thus)]TJ 0 -11.955 Td [(substantially)-321(speeds)-321(up)-322(inference)-321(time)-321(for)-321(smoothed)-322(V)60(iTs,)]TJ 0 -11.955 Td [(to)-244(the)-244(point)-244(where)-244(using)-244(a)-244(lar)18(ge)-244(V)60(iT)-245(is)-244(comparable)-244(in)-244(speed)]TJ 0 -11.955 Td [(to)-250(using)-250(a)-250(small)-250(ResNet.)]TJ
0 g 0 G
0 g 0 G
/F86 9.9626 Tf 258.75 629.037 Td [(Strided)-470(ablations.)]TJ/F87 9.9626 Tf 87.439 0 Td [(W)80(e)-470(no)25(w)-470(consi)1(der)-470(a)-470(complementary)]TJ -87.439 -11.955 Td [(means)-280(of)-280(speeding)-280(up)-280(smoothed)-280(classi\002ers:)-371(directly)-280(reduc-)]TJ 0 -11.955 Td [(ing)-243(the)-243(size)-243(of)-243(the)-243(ablation)-243(set)-243(via)]TJ/F91 9.9626 Tf 135.582 0 Td [(strided)]TJ/F87 9.9626 Tf 30.366 0 Td [(ablations.)-308(Specif-)]TJ -165.948 -11.955 Td [(ically)65(,)-252(instead)-252(of)-252(using)-251(e)25(v)15(ery)-252(possible)-252(ablation,)-252(we)-252(can)-252(sub-)]TJ 0 -11.955 Td [(sample)-398(e)25(v)15(ery)]TJ/F11 9.9626 Tf 57.89 0 Td [(s)]TJ/F87 9.9626 Tf 4.67 0 Td [(-th)-398(ablation)-399(for)-398(a)-399(gi)25(v)15(en)-398(stride)]TJ/F11 9.9626 Tf 126.897 0 Td [(s)]TJ/F87 9.9626 Tf 4.67 0 Td [(.)-755(Striding)]TJ -194.127 -11.956 Td [(can)-263(reduce)-264(the)-263(total)-264(number)-263(of)-264(ablations)-263(\(and)-264(consequently)]TJ 0 -11.955 Td [(speed)-330(up)-330(inference\))-330(by)-330(a)-331(f)10(actor)-330(of)]TJ/F11 9.9626 Tf 141.865 0 Td [(s)]TJ/F87 9.9626 Tf 4.67 0 Td [(,)]TJ/F91 9.9626 Tf 5.979 0 Td [(without)]TJ/F87 9.9626 Tf 33.366 0 Td [(substantially)]TJ -185.88 -11.955 Td [(hurting)-314(standard)-314(or)-314(certi\002ed)-314(accurac)15(y)-314(\(T)80(able)]TJ
1 0 0 rg 1 0 0 RG
[-314(1)]TJ
0 g 0 G
[(\).)-503(W)80(e)-314(study)]TJ 0 -11.955 Td [(this)-250(in)-250(more)-250(detail)-250(in)-250(Appendix)]TJ
1 0 0 rg 1 0 0 RG
[-250(F)]TJ
0 g 0 G
[(.)]TJ 11.955 -11.955 Td [(Strided)-405(ablations,)-444(in)-406(conjunction)-405(with)-405(the)-405(dropped)-406(to-)]TJ -11.955 -11.955 Td [(k)10(ens)-264(optimization)-265(fr)1(o)-1(m)-264(Section)]TJ
1 0 0 rg 1 0 0 RG
[-264(4.1)]TJ
0 g 0 G
[(,)-268(lead)-264(to)-264(smoothed)-265(V)60(iTs)]TJ 0 -11.956 Td [(ha)20(ving)-219(inference)-219(times)-219(comparable)-219(to)-220(standard)-219(\(non-rob)20(ust\))]TJ 0 -11.955 Td [(models.)-428(F)15(or)-290(e)15(xample,)-299(when)-290(using)-289(stride)]TJ/F11 9.9626 Tf 165.145 0 Td [(s)]TJ/F8 9.9626 Tf 8.166 0 Td [(=)-351(10)]TJ/F87 9.9626 Tf 24.09 0 Td [(and)-289(drop-)]TJ -197.401 -11.955 Td [(ping)-361(mask)10(ed)-360(tok)10(ens,)-388(a)-361(smoothed)-361(V)60(iT)92(-S)-360(is)-361(only)-360(2x)-361(slo)25(wer)]TJ 0 -11.955 Td [(than)-268(a)-267(single)-268(inference)-268(step)-267(of)-268(a)-268(standard)-268(ResNet-50,)-272(while)]TJ 0 -11.955 Td [(a)-330(smoothed)-330(V)60(iT)92(-B)-330(is)-330(only)-331(5x)-330(slo)25(wer)55(.)-550(W)80(e)-330(report)-331(the)-330(infer)20(-)]TJ 0 -11.955 Td [(ence)-376(time)-375(of)-376(these)-375(models,)-407(along)-376(with)-376(their)-375(standard)-376(and)]TJ 0 -11.956 Td [(certi\002ed)-250(accuracies,)-250(in)-250(T)80(able)]TJ
1 0 0 rg 1 0 0 RG
[-250(1)]TJ
0 g 0 G
[(.)]TJ/F86 11.9552 Tf 0 -22.379 Td [(5.)-250(Related)-250(w)10(ork)]TJ/F86 9.9626 Tf 0 -18.929 Td [(Certi\002ed)-448(defenses.)]TJ/F87 9.9626 Tf 89.966 0 Td [(An)-448(e)15(xtensi)25(v)15(e)-449(body)-448(of)-449(research)-448(has)]TJ -89.966 -11.955 Td [(studied)-376(the)-376(de)25(v)15(elopment)-376(of)-376(certi\002ed)-376(or)-376(pro)15(v)25(able)-376(defenses)]TJ 0 -11.955 Td [(to)-364(adv)15(ersarial)-364(perturbations.)-652(This)-364(line)-364(of)-364(research)-364(lar)18(gely)]TJ 0 -11.955 Td [(f)10(alls)-463(into)-463(one)-463(of)-463(three)-463(cate)15(gories:)-736(tighter)-464(or)-463(e)15(xact)-463(v)15(eri-)]TJ 0 -11.955 Td [<02657273>-275([)]TJ
0 1 0 rg 0 1 0 RG
[(11)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-275(21)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-275(31)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-275(46)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-275(57)]TJ
0 g 0 G
[(],)-281(con)40(v)15(e)15(x)-275(relaxation-based)-275(defenses)]TJ 0 -11.956 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(14)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(15)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(33)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(37)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(43)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-204(50)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(52)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(53)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-203(62)]TJ
0 g 0 G
[(],)-212(and)-204(smoothing-based)-203(de-)]TJ 0 -11.955 Td [(fenses)-240([)]TJ
0 1 0 rg 0 1 0 RG
[(7)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-241(23)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-240(25)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-240(27)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-241(28)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-240(41)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-240(42)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-241(58)]TJ
0 g 0 G
[(].)-306(In)-241(the)-240(case)-240(of)-241(patches,)]TJ 0 -11.955 Td [(the)-273(earliest)-273(certi\002ed)-273(defense)-273(used)-273(an)-273(instance)-273(of)-274(con)40(v)15(e)15(x)-273(re-)]TJ 0 -11.955 Td [(laxation)-308(\(interv)25(al)-308(bounds\))-308(to)-308(deri)25(v)15(e)-308(pro)14(v)25(abl)1(e)-309(guarantees)-308(to)]TJ 0 -11.955 Td [(adv)15(ersarial)-203(patch)-204([)]TJ
0 1 0 rg 0 1 0 RG
[(6)]TJ
0 g 0 G
[(].)-294(Subsequent)-203(w)10(ork)-204([)]TJ
0 1 0 rg 0 1 0 RG
[(26)]TJ
0 g 0 G
[(])-203(focused)-203(on)-204(ran-)]TJ 0 -11.955 Td [(domized)-207(smoothing.)-295(This)-207(approach)-206(smooths)-207(classi\002ers)-207(o)15(v)15(er)]TJ 0 -11.956 Td [(random)-239(noise,)-241(b)20(ut)-239(tend)-239(to)-238(be)-239(e)15(xtremely)-239(e)15(xpensi)25(v)15(e)-239(to)-239(use)-239(\(4-)]TJ 0 -11.955 Td [(5)-312(orders)-312(of)-312(magnitudes)-313(slo)25(wer)-312(than)-312(a)-312(standard,)-328(non-rob)20(ust)]TJ 0 -11.955 Td [(model\))-407([)]TJ
0 1 0 rg 0 1 0 RG
[(7)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-407(26)]TJ
0 g 0 G
[(].)-781(Recently)65(,)-447([)]TJ
0 1 0 rg 0 1 0 RG
[(29)]TJ
0 g 0 G
[(])-407(proposed)-407(a)-407(v)25(ariant)-407(based)]TJ 0 -11.955 Td [(on)-259(randomized)-258(cropping)-259(that)-259(performs)-259(similarly)-258(to)-259([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])-259(b)20(ut)]TJ 0 -11.955 Td [(with)-307(better)-307(guarantees)-307(under)-308(w)10(ors)1(e-case)-308(patch)-307(transforma-)]TJ 0 -11.955 Td [(tions.)]TJ/F86 9.9626 Tf 0 -25.837 Td [(Deterministic)-335(smoothing)15(.)]TJ/F87 9.9626 Tf 117.472 0 Td [(T)80(o)-335(mitig)5(ate)-336(the)-335(e)15(xpensi)25(v)15(e)-335(in-)]TJ -117.472 -11.955 Td [(ference)-280(times)-280(of)-280(randomized)-281(smoothing,)-287([)]TJ
0 1 0 rg 0 1 0 RG
[(25)]TJ
0 g 0 G
[(])-281(proposed)-280(de-)]TJ 0 -11.955 Td [(randomized)-468(smoothing,)-523(which)-468(used)-468(a)-468(\002nite)-468(set)-469(of)-468(abla-)]TJ 0 -11.955 Td [(tions)-457(to)-457(smooth)-457(a)-457(base)-457(classi\002er)55(.)-932(This)-457(substantially)-457(re-)]TJ 0 -11.956 Td [(duced)-425(the)-426(computational)-425(requirements)-426(of)-425(smoothing,)-470(b)20(ut)]TJ 0 -11.955 Td [(is)-293(still)-294(tw)10(o)-293(orders)-293(of)-294(ma)1(gn)-1(i)1(tude)-294(slo)25(wer)-293(than)-293(standard)-294(mod-)]TJ 0 -11.955 Td [(els.)-306(Se)25(v)15(eral)-237(other)-236(defenses,)-240(including)-237(Clipped)-237(BagNet)-237([)]TJ
0 1 0 rg 0 1 0 RG
[(63)]TJ
0 g 0 G
[(],)]TJ 0.249 -11.955 Td [(B)]TJ/F87 7.9701 Tf 6.834 0 Td [(A)-22(G)]TJ/F87 9.9626 Tf 12.175 0 Td [(C)]TJ/F87 7.9701 Tf 7.143 0 Td [(E)-61(R)-2(T)]TJ/F87 9.9626 Tf 19.8 0 Td [([)]TJ
0 1 0 rg 0 1 0 RG
[(32)]TJ
0 g 0 G
[(],)-439(and)-402(P)15(atchGuard)-401([)]TJ
0 1 0 rg 0 1 0 RG
[(56)]TJ
0 g 0 G
[(],)-439(rely)-402(on)-401(restricting)]TJ -46.201 -11.955 Td [(the)-422(model')55(s)-421(recepti)25(v)15(e)-422(\002eld.)-824(These)-422(approaches)-421(are)-422(f)10(aster)]TJ 0 -11.955 Td [(than)-355(derandomized)-356(smoothing,)-382(b)20(ut)-355(ha)20(v)15(e)-355(other)-356(limitations.)]TJ 0 -11.956 Td [(Clipped)-448(BagNet)-449(\(CBN\))-448(has)-449(substantially)-448(weak)10(er)-449(rob)20(ust-)]TJ 0 -11.955 Td [(ness)-294(guarantees)-294(than)-295(derandomized)-294(smoothing.)-468(B)]TJ/F87 7.9701 Tf 201.132 0 Td [(A)-22(G)]TJ/F87 9.9626 Tf 12.174 0 Td [(C)]TJ/F87 7.9701 Tf 7.144 0 Td [(E)-61(R)-2(T)]TJ/F87 9.9626 Tf -220.45 -11.955 Td [(achie)25(v)15(es)-249(higher)-248(rob)20(ustness)-249(guarantees)-248(than)-249(CBN,)-248(b)20(ut)-249(lo)25(wer)]TJ 0 -11.955 Td [(standard)-299(accurac)15(y)65(.)-457(P)15(atchGuard)-299(has)-299(further)-300(higher)-299(b)20(ut)]TJ/F91 9.9626 Tf 218.537 0 Td [(brit-)]TJ -218.537 -11.955 Td [(tle)]TJ/F87 9.9626 Tf 14.414 0 Td [(guarantees:)-704(a)-447(defended)-446(model)-447(is)-447(optimally)-447(defended)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/ifylqQ9R4v4YdYwNyKRQ8w Do
Q
endstream
endobj
183 0 obj
<< /CS /DeviceRGB /S /Transparency /Type /Group >>
endobj
184 0 obj
<< /Font << /F101 351 0 R /F102 348 0 R /F11 331 0 R /F8 339 0 R /F86 322 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /Im9 362 0 R /ifylqQ9R4v4YdYwNyKRQ8w 363 0 R >> >>
endobj
185 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 593.474 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 143.113 609.477 155.068 618.323 ] /Subtype /Link /Type /Annot >>
endobj
186 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 152.731 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 229.178 609.477 236.152 618.323 ] /Subtype /Link /Type /Annot >>
endobj
187 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 358.356 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 238.652 609.477 250.608 618.323 ] /Subtype /Link /Type /Annot >>
endobj
188 0 obj
<< /A << /D [ 13 0 R /XYZ 308.862 125.23 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 253.109 609.477 265.064 618.323 ] /Subtype /Link /Type /Annot >>
endobj
189 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 246.38 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 124.916 597.521 131.89 606.368 ] /Subtype /Link /Type /Annot >>
endobj
190 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 687.123 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 134.927 597.621 146.882 606.368 ] /Subtype /Link /Type /Annot >>
endobj
191 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 604.433 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 149.919 597.521 161.874 606.368 ] /Subtype /Link /Type /Annot >>
endobj
192 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 187.6 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 143.293 585.666 150.267 594.413 ] /Subtype /Link /Type /Annot >>
endobj
193 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 152.731 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 152.738 585.566 159.712 594.413 ] /Subtype /Link /Type /Annot >>
endobj
194 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 358.356 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 162.183 585.566 174.138 594.413 ] /Subtype /Link /Type /Annot >>
endobj
195 0 obj
<< /A << /D [ 12 0 R /XYZ 313.843 152.731 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 202.346 573.611 209.32 582.458 ] /Subtype /Link /Type /Annot >>
endobj
196 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 358.356 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 212.801 573.611 224.756 582.458 ] /Subtype /Link /Type /Annot >>
endobj
197 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 158.107 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 229.877 561.656 241.832 570.503 ] /Subtype /Link /Type /Annot >>
endobj
198 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 547.646 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 111.478 549.701 123.434 558.547 ] /Subtype /Link /Type /Annot >>
endobj
199 0 obj
<< /A << /D [ 13 0 R /XYZ 55.093 721.993 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 175.043 537.746 182.017 546.592 ] /Subtype /Link /Type /Annot >>
endobj
200 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 336.438 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 252.955 537.626 264.91 546.592 ] /Subtype /Link /Type /Annot >>
endobj
201 0 obj
<< /A << /D [ 14 0 R /XYZ 50.112 570.56 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 225.987 525.79 237.942 534.637 ] /Subtype /Link /Type /Annot >>
endobj
202 0 obj
<< /A << /D [ 13 0 R /XYZ 50.112 534.695 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 177.105 462.191 189.06 471.038 ] /Subtype /Link /Type /Annot >>
endobj
203 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 393.225 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 272.086 450.116 284.041 459.082 ] /Subtype /Link /Type /Annot >>
endobj
204 0 obj
<< /A << /D [ 14 0 R /XYZ 308.862 498.829 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 195.806 438.281 207.761 447.127 ] /Subtype /Link /Type /Annot >>
endobj
205 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 537.423 277.219 544.397 288.004 ] /Subtype /Link /Type /Annot >>
endobj
206 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 467.984 242.35 474.958 253.134 ] /Subtype /Link /Type /Annot >>
endobj
207 0 obj
<< /A << /D [ 343 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 477.947 242.35 489.902 253.134 ] /Subtype /Link /Type /Annot >>
endobj
208 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 394.73 183.859 401.703 194.355 ] /Subtype /Link /Type /Annot >>
endobj
209 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 536.644 160.537 543.618 171.441 ] /Subtype /Link /Type /Annot >>
endobj
210 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 329.445 150.639 336.418 159.486 ] /Subtype /Link /Type /Annot >>
endobj
211 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 394.341 77.847 401.315 88.751 ] /Subtype /Link /Type /Annot >>
endobj
212 0 obj
<< /Length 13288 >>
stream
q
q
0 g 0 G
0 g 0 G
BT
/F87 9.9626 Tf 50.112 710.037 Td [(ag)5(ainst)-293(a)-292(speci\002c)-293(patch)-293(size,)-303(and)-293(achie)25(v)15(es)-292(no)-293(rob)20(ustness)-293(at)]TJ 0 -11.955 Td [(all)-261(ag)5(ainst)-262(patches)-261(that)-262(are)-261(e)25(v)15(en)-262(slightly)-261(lar)18(ger)-262(than)-261(the)-262(one)]TJ 0 -11.955 Td [(considered.)]TJ/F86 9.9626 Tf 0 -27.734 Td [(Empirical)-235(methods:)-303(attacks)-235(and)-235(defenses.)]TJ/F87 9.9626 Tf 186.317 0 Td [(Another)-235(line)]TJ -186.317 -11.955 Td [(of)-268(w)10(ork)-268(studies)-268(empirical)-268(approaches)-268(for)-269(generating)-268(adv)15(er)20(-)]TJ 0 -11.955 Td [(sarial)-278(patches)-278(and)-278(desi)1(gning)-278(empirical)-278(defenses.)-394(Adv)15(ersar)20(-)]TJ 0 -11.956 Td [(ial)-255(patches)-255(ha)20(v)15(e)-256(been)-255(de)25(v)15(eloped)-255(for)-255(do)25(wnstream)-256(t)1(asks)-256(such)]TJ 0 -11.955 Td [(as)-201(image)-201(classi\002cation)-201([)]TJ
0 1 0 rg 0 1 0 RG
[(20)]TJ
0 g 0 G
[(],)-211(object)-201(detection)-201([)]TJ
0 1 0 rg 0 1 0 RG
[(5)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-201(13)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-201(30)]TJ
0 g 0 G
[(],)-211(and)]TJ 0 -11.955 Td [(f)10(acial)-255(recognition)-255([)]TJ
0 1 0 rg 0 1 0 RG
[(3)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-254(44)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-255(45)]TJ
0 g 0 G
[(].)-325(Se)25(v)15(eral)-254(of)-255(these)-255(attacks)-255(w)10(ork)]TJ 0 -11.955 Td [(in)-198(the)-198(ph)5(ysical)-198(domain)-198([)]TJ
0 1 0 rg 0 1 0 RG
[(4)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-198(5)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-198(13)]TJ
0 g 0 G
[(],)-209(and)-198(can)-198(successfully)-198(tar)18(get)]TJ 0 -11.955 Td [(tasks)-299(such)-300(as)-299(traf)25<0263>-300(sign)-299(recognition)-300([)]TJ
0 1 0 rg 0 1 0 RG
[(5)]TJ
0 g 0 G
[(,)]TJ
0 1 0 rg 0 1 0 RG
[-299(13)]TJ
0 g 0 G
[(].)-458(Heuristic)-300(de-)]TJ 0 -11.955 Td [(fenses)-202(to)-203(these)-202(attacks)-202(include)-203(w)10(atermarking)-202([)]TJ
0 1 0 rg 0 1 0 RG
[(16)]TJ
0 g 0 G
[(])-202(and)-203(gradi-)]TJ 0 -11.956 Td [(ent)-241(smoothing)-241([)]TJ
0 1 0 rg 0 1 0 RG
[(35)]TJ
0 g 0 G
[(];)-244(ho)25(we)25(v)15(er)40(,)-242(these)-241(defenses)-241(were)-241(sho)25(wn)-241(to)]TJ 0 -11.955 Td [(be)-254(vulnerable)-255(adapti)26(v)14(e)-254(attacks)-254([)]TJ
0 1 0 rg 0 1 0 RG
[(6)]TJ
0 g 0 G
[(].)-323(More)-254(recently)65(,)-255([)]TJ
0 1 0 rg 0 1 0 RG
[(39)]TJ
0 g 0 G
[(])-255(pro-)]TJ 0 -11.955 Td [(posed)-259(an)-258(adv)15(ersarial)-259(training)-258(approach)-259(and)-259([)]TJ
0 1 0 rg 0 1 0 RG
[(34)]TJ
0 g 0 G
[(])-258(proposed)-259(a)]TJ 0 -11.955 Td [(rob)20(ust)-271(attention)-271(module)-270(to)-271(impro)15(v)15(e)-271(empirical)-271(rob)20(ustness)-271(to)]TJ 0 -11.955 Td [(patch)-250(attacks.)]TJ/F86 9.9626 Tf 0 -27.734 Td [(V)37(ision)-638(transf)25(ormers.)]TJ/F87 9.9626 Tf 101.201 0 Td [(Our)-638(w)10(ork)-638(le)25(v)15(erages)-638(the)-639(vision)]TJ -101.201 -11.955 Td [(transformer)-304(\(V)60(iT\))-304(architecture)-304([)]TJ
0 1 0 rg 0 1 0 RG
[(10)]TJ
0 g 0 G
[(],)-318(which)-304(adapts)-304(the)-304(pop-)]TJ 0 -11.956 Td [(ular)-349(attenti)1(on-based)-349(model)-349(from)-348(the)-349(language)-348(setting)-349([)]TJ
0 1 0 rg 0 1 0 RG
[(49)]TJ
0 g 0 G
[(])]TJ 0 -11.955 Td [(to)-331(the)-331(vision)-331(setting.)-552(Recent)-331(w)10(ork)-331([)]TJ
0 1 0 rg 0 1 0 RG
[(47)]TJ
0 g 0 G
[(])-331(has)-331(released)-331(more)]TJ 0 -11.955 Td [(ef)25(\002cient)-343(training)-344(methods)-343(as)-343(well)-344(as)-343(pre-trained)-343(V)60(iTs)-344(that)]TJ 0 -11.955 Td [(ha)20(v)15(e)-268(made)-268(these)-268(architectures)-268(more)-268(accessible)-269(to)-268(the)-268(wider)]TJ 0 -11.955 Td [(research)-250(community)65(.)]TJ/F86 11.9552 Tf 0 -24.57 Td [(6.)-250(Conclusion)]TJ/F87 9.9626 Tf 11.955 -19.149 Td [(W)80(e)-736(demonstrate)-735(ho)25(w)-736(applying)-735(visual)-736(transformers)]TJ -11.955 -11.955 Td [(\(V)60(iTs\))-441(within)-441(the)-441(smoothing)-441(frame)25(w)10(ork)-442(l)1(eads)-442(to)-441(signi\002-)]TJ 0 -11.955 Td [(cantly)-306(impro)15(v)15(ed)-307(certi\002ed)-306(rob)20(ustness)-307(to)-306(adv)15(ersarial)-307(patches)]TJ 0 -11.955 Td [(while)-298(maintaining)-298(standard)-299(accuracies)-298(that)-298(are)-298(on)-298(par)-299(with)]TJ 0 -11.955 Td [(re)15(gular)-272(\(non-rob)20(ust\))-272(models.)-377(Further)40(,)-278(we)-272(put)-272(forth)-273(changes)]TJ 0 -11.955 Td [(to)-405(the)-404(V)60(iT)-405(architecture)-405(and)-404(the)-405(corresponding)-405(smoothing)]TJ 0 -11.956 Td [(procedure)-194(that)-194(greatly)-194(speed)-194(up)-194(the)-195(resulting)-194(inference)-194(times)]TJ 0 -11.955 Td [(o)15(v)15(er)-247(pre)25(vious)-248(smoothing)-247(approaches)-248(by)-247(up)-247(to)-248(tw)10(o)-247(orders)-248(of)]TJ 0 -11.955 Td [(magnitude\227the)15(y)-331(end)-330(up)-331(being)-330(only)-331(2-5x)-331(slo)25(wer)-330(than)-331(that)]TJ 0 -11.955 Td [(of)-229(a)-229(re)15(gular)-229(ResNet.)-302(W)80(e)-229(belie)25(v)15(e)-229(that)-229(these)-229(impro)15(v)15(ements)-229<022d>]TJ 0 -11.955 Td [(nally)-201(establish)-200(models)-201(that)-201(are)-201(certi\002ably)-200(rob)20(ust)-201(to)-201(adv)15(ersar)20(-)]TJ 0 -11.956 Td [(ial)-333(patches)-334(as)-333(a)-334(viable)-333(alternati)25(v)15(e)-334(to)-333(standard)-334(\(non-rob)20(ust\))]TJ 0 -11.955 Td [(models.)]TJ/F86 9.9626 Tf 0 -27.734 Td [(Limitations.)]TJ/F87 9.9626 Tf 61.718 0 Td [(Similarly)-518(to)-519(other)-519(certi\002ed)-518(defenses,)-586(our)]TJ -61.718 -11.955 Td [(method)-333(speci\002cally)-332(focuses)-333(on)-333(patch)-333(attacks)-332(and)-333(does)-333(not)]TJ 0 -11.955 Td [(guarantee)-510(rob)20(ustness)-510(to)-510(attacks)-510(that)-510(f)10(all)-510(outside)-510(of)-510(this)]TJ 0 -11.955 Td [(threat)-261(model.)-342(Furthermore,)-263(although)-261(our)-260(approach)-261(is)-261(v)25(astly)]TJ 0 -11.955 Td [(f)10(aster)-268(than)-268(other)-267(smoothed)-268(models,)-272(smoothed)-268(V)60(iTs)-268(are)-268(still)]TJ 0 -11.956 Td [(slightly)-283(slo)25(wer)-283(than)-283(standard)-283(\(non-rob)20(ust\))-283(models.)-410(Finally)65(,)]TJ 0 -11.955 Td [(the)-304(standard)-304(accurac)15(y)-304(of)-303(our)-304(models)-304(may)-304(suf)25(fer)-304(if)-304(the)-304(pre-)]TJ 0 -11.955 Td [(dicti)25(v)15(e)-305(signal)-305(in)-305(an)-304(image)-305(comes)-305(only)-305(from)-305(a)-305(small)-305(re)15(gion)]TJ 0 -11.955 Td [(of)-331(the)-331(image,)-352(as)-331(that)-331(re)15(gion)-331(might)-331(not)-331(be)-331(present)-332(in)-331(man)15(y)]TJ 0 -11.955 Td [(image)-250(ablations.)]TJ
0 g 0 G
0 g 0 G
/F86 9.9626 Tf 258.75 629.037 Td [(P)20(otential)-215(negati)10(v)10(e)-215(impact.)]TJ/F87 9.9626 Tf 119.268 0 Td [(A)-215(possible)-215(ne)15(g)5(ati)25(v)15(e)-214(impact)-215(of)]TJ -119.268 -11.955 Td [(our)-217(w)10(ork)-217(is)-217(that)-217(it)-217(might)-217(instill)-217(o)15(v)15(ercon\002dence)-218(in)-217(the)-217(model.)]TJ 0 -11.955 Td [(At)-282(test)-282(t)1(ime,)-290(our)-282(rob)20(ustness)-282(guarantees)-281(ensure)-282(that)-282(the)-282(pre-)]TJ 0 -11.955 Td [(diction)-294(is)-293(stable)-294(b)20(ut)-294(might)-293(be)-294(not)-294(necessaril)1(y)-294(correct,)-305(lead-)]TJ 0 -11.956 Td [(ing)-288(to)-288(a)-288(f)10(alse)-288(sense)-288(of)-288(con\002dence.)-423(Additionally)65(,)-298(users)-288(may)]TJ 0 -11.955 Td [(erroneously)-266(e)15(xtrapolate)-267(other)-266(forms)-267(of)-266(rob)20(ustness)-266(from)-267(our)]TJ 0 -11.955 Td [(guarantees)-345(of)-346(patch)-345(rob)20(ustness.)-597(The)-345(guarantees)-346(presented)]TJ 0 -11.955 Td [(in)-283(this)-283(paper)-283(are)]TJ/F91 9.9626 Tf 67.72 0 Td [(r)45(ob)20(ustness)]TJ/F87 9.9626 Tf 44.792 0 Td [(guarantees)-283(and)-283(not)]TJ/F91 9.9626 Tf 78.18 0 Td [(corr)37(ectness)]TJ/F87 9.9626 Tf -190.692 -11.955 Td [(guarantees,)-287(in)-280(the)-280(sense)-279(that)-280(our)-280(models)-279(can)-280(guarantee)-280(that)]TJ 0 -11.955 Td [(a)-265(prediction)-265(is)-264(stable)-265(if)-265(a)-265(certain)-265(re)15(gion)-264(of)-265(the)-265(image)-265(is)-265(ma-)]TJ 0 -11.956 Td [(nipulate,)-297(b)20(ut)-288(it)-287(cannot)-288(guarantee)-287(that)-288(the)-288(prediction)-287(will)-288(be)]TJ 0 -11.955 Td [(correct.)-305(Therefore,)-239(we)-235(encourage)-236(users)-236(to)-236(be)-235(a)15(w)10(are)-236(of)-236(these)]TJ 0 -11.955 Td [(subtleties)-250(before)-250(using)-250(our)-250(technique.)]TJ/F86 11.9552 Tf 0 -22.613 Td [(7.)-250(Ackno)10(wledgements)]TJ/F87 9.9626 Tf 11.955 -18.929 Td [(W)80(ork)-227(supported)-227(in)-227(part)-227(by)-227(the)-228(NSF)-227(grants)-227(CCF-1553428)]TJ -11.955 -11.956 Td [(and)-332(CNS-1815221,)-352(and)-332(Open)-332(Philanthrop)10(y)65(.)-555(This)-332(material)]TJ 0 -11.955 Td [(is)-407(based)-406(upon)-407(w)10(ork)-407(supported)-407(by)-406(the)-407(Defense)-407(Adv)25(anced)]TJ 0 -11.955 Td [(Research)-436(Projects)-436(Agenc)15(y)-436(\(D)40(ARP)92(A\))-436(under)-436(Contract)-436(No.)]TJ 0 -11.955 Td [(HR001120C0015.)]TJ 11.955 -11.955 Td [(Research)-290(w)10(as)-290(sponsored)-290(by)-290(the)-290(United)-291(States)-290(Air)-290(F)15(orce)]TJ -11.955 -11.955 Td [(Research)-358(Laboratory)-358(and)-359(the)-358(United)-358(States)-358(Air)-358(F)15(orce)-359(Ar)20(-)]TJ 0 -11.956 Td [(ti\002cial)-325(Intelligence)-326(Accelerat)1(o)-1(r)-325(and)-325(w)10(as)-325(accomplished)-326(un-)]TJ 0 -11.955 Td [(der)-479(Cooperati)25(v)15(e)-479(Agreement)-479(Number)-479(F)74(A8750-19-2-1000.)]TJ 0 -11.955 Td [(The)-301(vie)25(ws)-301(and)-301(conclusions)-301(contained)-301(in)-302(this)-301(document)-301(are)]TJ 0 -11.955 Td [(those)-350(of)-349(the)-350(authors)-349(and)-350(should)-349(not)-350(be)-350(interpreted)-349(as)-350(rep-)]TJ 0 -11.955 Td [(resenting)-328(the)-327(of)25(\002cial)-328(policies,)-347(either)-327(e)15(xpressed)-328(or)-328(implied,)]TJ 0 -11.955 Td [(of)-433(the)-434(United)-433(States)-434(Air)-433(F)15(orce)-433(or)-434(the)-433(U.S.)-434(Go)15(v)15(ernment.)]TJ 0 -11.956 Td [(The)-350(U.S.)-351(Go)15(v)15(ernment)-350(is)-351(authorized)-350(to)-351(reproduce)-350(and)-351(dis-)]TJ 0 -11.955 Td [(trib)20(ute)-387(reprints)-386(for)-387(Go)15(v)15(ernment)-386(purposes)-387(notwithstanding)]TJ 0 -11.955 Td [(an)15(y)-250(cop)10(yright)-250(notation)-250(herein.)]TJ/F86 11.9552 Tf 0 -22.613 Td [(Refer)18(ences)]TJ
0 g 0 G
/F87 9.9626 Tf 4.981 -18.929 Td [([1])]TJ
0 g 0 G
[-500(Mitali)-201(Bafna,)-210(Jack)-201(Murtagh,)-211(and)-201(Nikhil)-200(Vyas.)-254(Thw)10(art-)]TJ 16.598 -11.955 Td [(ing)-244(adv)15(ersarial)-245(e)15(xamples:)-307(An)]TJ/F11 9.9626 Tf 119.076 0 Td [(l)]TJ/F87 9.9626 Tf 3.169 0 Td [(_)]TJ/F8 9.9626 Tf 4.981 0 Td [(0)]TJ/F87 9.9626 Tf 4.981 0 Td [(-rob)20(ustsparse)-244(fourier)]TJ -132.207 -11.956 Td [(transform.)]TJ/F91 9.9626 Tf 44.811 0 Td [(arXiv)-250(pr)37(eprint)-250(arXiv:1812.05013)]TJ/F87 9.9626 Tf 132.184 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-193.593 -10.959 Td [([2])]TJ
0 g 0 G
[-500(Y)111(utong)-319(Bai,)-337(Jieru)-319(Mei,)-336(Alan)-319(Y)111(uille,)-336(and)-320(Cihang)-319(Xie.)]TJ 16.598 -11.955 Td [(Are)-502(transformers)-502(more)-501(rob)20(ust)-502(than)-502(cnns?)]TJ/F91 9.9626 Tf 192.534 0 Td [(arXiv)]TJ -192.534 -11.955 Td [(pr)37(eprint)-250(arXiv:2111.05464)]TJ/F87 9.9626 Tf 107.556 0 Td [(,)-250(2021.)]TJ
1 0 0 rg 1 0 0 RG
[-360(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(14)]TJ
0 g 0 G
0 g 0 G
-124.154 -10.959 Td [([3])]TJ
0 g 0 G
[-500(A)74(vishek)-426(Joe)15(y)-426(Bose)-426(and)-426(P)15(arham)-426(Aarabi.)-923(Adv)15(ersar)20(-)]TJ 16.598 -11.955 Td [(ial)-418(attacks)-417(on)-418(f)10(ace)-417(detectors)-418(using)-418(neural)-417(net)-418(based)]TJ 0 -11.955 Td [(constrained)-370(optimization.)-746(In)]TJ/F91 9.9626 Tf 121.896 0 Td [(2018)-371(IEEE)-370(20th)-370(Inter)20(-)]TJ -121.896 -11.955 Td [(national)-337(W)92(orkshop)-337(on)-337(Multimedia)-337(Signal)-337(Pr)45(ocessing)]TJ 0 -11.956 Td [(\(MMSP\))]TJ/F87 9.9626 Tf 34.301 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-50.899 -10.958 Td [([4])]TJ
0 g 0 G
[-500(T)80(om)-292(B.)-291(Bro)25(wn,)-302(Dandelion)-292(Man,)-302(Aurk)10(o)-292(Ro)10(y)65(,)-302(Martn)]TJ 16.598 -11.956 Td [(Abadi,)-251(and)-251(Justin)-251(Gilmer)55(.)-363(Adv)15(ersarial)-251(patch,)-252(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-363(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
0 -11.955 Td [(8)]TJ
0 g 0 G
0 g 0 G
-16.598 -10.959 Td [([5])]TJ
0 g 0 G
[-500(Shang-Tse)-344(Chen,)-367(Cory)-344(Cornelius,)-367(Jason)-344(Martin,)-367(and)]TJ 16.598 -11.955 Td [(Duen)-321(Horng)-321(Polo)-321(Chau.)-588(Shapeshifter:)-452(Rob)20(ust)-321(ph)5(ys-)]TJ 0 -11.955 Td [(ical)-312(adv)15(ersarial)-312(attack)-311(on)-312(f)10(aster)-312(r)20(-cnn)-312(object)-312(detector)55(.)]TJ 0 -11.955 Td [(In)]TJ/F91 9.9626 Tf 11.814 0 Td [(J)25(oint)-353(Eur)45(opean)-353(Confer)37(enc)1(e)-353(on)-353(Mac)15(hine)-353(Learning)]TJ -11.814 -11.955 Td [(and)-205(Knowledg)10(e)-204(Disco)10(very)-205(in)-204(Databases)]TJ/F87 9.9626 Tf 157.931 0 Td [(,)-214(pages)-204(52\22668.)]TJ -157.931 -11.956 Td [(Springer)40(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/UaaUC4FE0TXgXdOOwbkf-A Do
Q
endstream
endobj
213 0 obj
<< /Font << /F11 331 0 R /F8 339 0 R /F86 322 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /UaaUC4FE0TXgXdOOwbkf-A 364 0 R >> >>
endobj
214 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 174.455 671.736 181.429 681.923 ] /Subtype /Link /Type /Annot >>
endobj
215 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 184.418 671.736 191.392 681.923 ] /Subtype /Link /Type /Annot >>
endobj
216 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 194.381 671.736 201.354 681.923 ] /Subtype /Link /Type /Annot >>
endobj
217 0 obj
<< /A << /D [ 6 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 195.058 624.314 202.031 635.098 ] /Subtype /Link /Type /Annot >>
endobj
218 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 205.02 624.314 211.994 635.098 ] /Subtype /Link /Type /Annot >>
endobj
219 0 obj
<< /A << /D [ 343 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 203.785 577.744 215.74 588.274 ] /Subtype /Link /Type /Annot >>
endobj
220 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 183.76 530.665 190.734 541.449 ] /Subtype /Link /Type /Annot >>
endobj
221 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 235.246 447.975 242.22 458.76 ] /Subtype /Link /Type /Annot >>
endobj
222 0 obj
<< /A << /D [ 6 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 245.209 447.975 252.183 458.76 ] /Subtype /Link /Type /Annot >>
endobj
223 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 255.171 447.975 262.145 458.76 ] /Subtype /Link /Type /Annot >>
endobj
224 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 265.134 447.975 272.108 458.76 ] /Subtype /Link /Type /Annot >>
endobj
225 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 275.097 447.975 287.052 458.76 ] /Subtype /Link /Type /Annot >>
endobj
226 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 244.93 413.106 251.904 423.89 ] /Subtype /Link /Type /Annot >>
endobj
227 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 259.993 354.326 266.967 365.111 ] /Subtype /Link /Type /Annot >>
endobj
228 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 248.437 307.382 255.411 318.286 ] /Subtype /Link /Type /Annot >>
endobj
229 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 238.705 77.669 247.283 ] /Subtype /Link /Type /Annot >>
endobj
230 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 118.286 154.675 125.26 164.862 ] /Subtype /Link /Type /Annot >>
endobj
231 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 245.767 107.133 252.741 118.037 ] /Subtype /Link /Type /Annot >>
endobj
232 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 255.73 107.133 262.704 118.037 ] /Subtype /Link /Type /Annot >>
endobj
233 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 409.962 695.338 416.936 705.833 ] /Subtype /Link /Type /Annot >>
endobj
234 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 419.925 695.338 431.88 705.833 ] /Subtype /Link /Type /Annot >>
endobj
235 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 433.205 648.822 440.179 659.009 ] /Subtype /Link /Type /Annot >>
endobj
236 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 382.007 590.042 388.981 600.229 ] /Subtype /Link /Type /Annot >>
endobj
237 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 437.37 543.218 444.344 553.405 ] /Subtype /Link /Type /Annot >>
endobj
238 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 355.447 485.778 362.421 494.625 ] /Subtype /Link /Type /Annot >>
endobj
239 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 510.474 460.807 517.448 471.711 ] /Subtype /Link /Type /Annot >>
endobj
240 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 520.437 460.807 532.392 471.711 ] /Subtype /Link /Type /Annot >>
endobj
241 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 535.291 414.102 542.265 424.887 ] /Subtype /Link /Type /Annot >>
endobj
242 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 433.205 379.831 440.179 390.017 ] /Subtype /Link /Type /Annot >>
endobj
243 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 536.644 344.364 543.618 355.148 ] /Subtype /Link /Type /Annot >>
endobj
244 0 obj
<< /A << /D [ 6 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 329.445 333.006 336.418 343.193 ] /Subtype /Link /Type /Annot >>
endobj
245 0 obj
<< /A << /D [ 8 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 339.407 333.006 346.381 343.193 ] /Subtype /Link /Type /Annot >>
endobj
246 0 obj
<< /A << /D [ 9 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 349.37 333.006 356.344 343.193 ] /Subtype /Link /Type /Annot >>
endobj
247 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 359.333 333.006 366.306 343.193 ] /Subtype /Link /Type /Annot >>
endobj
248 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 369.295 333.006 381.25 343.193 ] /Subtype /Link /Type /Annot >>
endobj
249 0 obj
<< /A << /D [ 365 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 384.239 333.006 396.194 343.193 ] /Subtype /Link /Type /Annot >>
endobj
250 0 obj
<< /A << /D [ 350 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 399.183 333.006 411.138 343.193 ] /Subtype /Link /Type /Annot >>
endobj
251 0 obj
<< /A << /D [ 328 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 414.127 333.006 426.082 343.193 ] /Subtype /Link /Type /Annot >>
endobj
252 0 obj
<< /A << /D [ 345 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 429.071 333.006 441.026 343.193 ] /Subtype /Link /Type /Annot >>
endobj
253 0 obj
<< /A << /D [ 366 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 444.015 333.006 455.97 343.193 ] /Subtype /Link /Type /Annot >>
endobj
254 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 355.447 274.227 362.421 284.413 ] /Subtype /Link /Type /Annot >>
endobj
255 0 obj
<< /A << /D [ 6 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 365.41 274.227 372.384 284.413 ] /Subtype /Link /Type /Annot >>
endobj
256 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 375.372 274.227 382.346 284.413 ] /Subtype /Link /Type /Annot >>
endobj
257 0 obj
<< /A << /D [ 365 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 385.335 274.227 397.29 284.413 ] /Subtype /Link /Type /Annot >>
endobj
258 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 412.463 215.447 419.437 225.634 ] /Subtype /Link /Type /Annot >>
endobj
259 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 519.72 179.98 526.694 190.765 ] /Subtype /Link /Type /Annot >>
endobj
260 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 420.881 121.201 427.855 131.985 ] /Subtype /Link /Type /Annot >>
endobj
261 0 obj
<< /Length 15587 >>
stream
q
q
0 g 0 G
0 g 0 G
0 g 0 G
BT
/F87 9.9626 Tf 55.093 710.037 Td [([6])]TJ
0 g 0 G
[-500(Ping-yeh)-499(Chiang,)-561(Renkun)-498(Ni,)-561(Ahmed)-499(Abdelkader)40(,)]TJ 16.598 -11.955 Td [(Chen)-217(Zhu,)-224(Christoph)-217(Studor)40(,)-224(and)-217(T)80(om)-217(Goldstein.)-289(Cer)20(-)]TJ 0 -11.955 Td [(ti\002ed)-273(defenses)-273(for)-273(adv)15(ersarial)-273(patches.)]TJ/F91 9.9626 Tf 157.526 0 Td [(arXiv)-273(pr)37(eprint)]TJ -157.526 -11.955 Td [(arXiv:2003.06693)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(7)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(8)]TJ
0 g 0 G
0 g 0 G
-89.375 -10.959 Td [([7])]TJ
0 g 0 G
[-500(Jeremy)-697(M)-698(Cohen,)-809(Elan)-697(Rosenfeld,)-810(and)-697(J)-698(Zico)]TJ 16.598 -11.955 Td [(K)35(olter)55(.)-711(Certi\002ed)-359(adv)15(ersarial)-360(rob)20(ustness)-359(via)-360(random-)]TJ 0 -11.955 Td [(ized)-305(smoothing.)-535(In)]TJ/F91 9.9626 Tf 80.862 0 Td [(International)-305(Confer)37(ence)-304(on)-305(Ma-)]TJ -80.862 -11.956 Td [(c)15(hine)-250(Learning)-250(\(ICML\))]TJ/F87 9.9626 Tf 93.379 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(2)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(7)]TJ
0 g 0 G
0 g 0 G
-109.977 -10.958 Td [([8])]TJ
0 g 0 G
[-500(Ekin)-438(D)-438(Cub)20(uk,)-485(Barret)-438(Zoph,)-485(Jonathon)-439(Shlens,)-485(and)]TJ 16.598 -11.956 Td [(Quoc)-566(V)-566(Le.)-1373(Randaugment:)-942(Practical)-566(data)-567(aug-)]TJ 0 -11.955 Td [(mentation)-447(with)-447(no)-447(separate)-448(search.)]TJ/F91 9.9626 Tf 155.791 0 Td [(arXiv)-447(pr)37(eprint)]TJ -155.791 -11.955 Td [(arXiv:1909.13719)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2\(4\):7,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(14)]TJ
0 g 0 G
0 g 0 G
-89.375 -10.959 Td [([9])]TJ
0 g 0 G
[-500(Jia)-349(Deng,)-374(W)80(ei)-350(Dong,)-374(Richard)-349(Socher)40(,)-374(Li-Jia)-350(Li,)-374(Kai)]TJ 16.598 -11.955 Td [(Li,)-261(and)-260(Li)-259(Fei-Fei.)-389(Imagenet:)-328(A)-260(lar)18(ge-scale)-259(hierarchi-)]TJ 0 -11.955 Td [(cal)-321(image)-320(database.)-586(In)]TJ/F91 9.9626 Tf 96.476 0 Td [(Computer)-321(V)74(ision)-320(and)-321(P)80(attern)]TJ -96.476 -11.955 Td [(Reco)10(gnition)-250(\(CVPR\))]TJ/F87 9.9626 Tf 82.082 0 Td [(,)-250(2009.)]TJ
1 0 0 rg 1 0 0 RG
[-360(3)]TJ
0 g 0 G
0 g 0 G
-103.661 -10.959 Td [([10])]TJ
0 g 0 G
[-500(Ale)15(x)15(e)15(y)-1046(Doso)15(vit)1(skiy)65(,)-1245(Lucas)-1045(Be)15(yer)40(,)-1245(Ale)15(xander)]TJ 21.579 -11.955 Td [(K)35(olesnik)10(o)15(v)65(,)-1116(Dirk)-942(W)80(eissenborn,)-1116(Xiaohua)-943(Zhai,)]TJ 0 -11.956 Td [(Thomas)-606(Unterthiner)40(,)-694(Mostaf)10(a)-606(Dehghani,)-695(Matthias)]TJ 0 -11.955 Td [(Minderer)40(,)-432(Geor)18(g)-396(Heigold,)-432(Sylv)25(ain)-396(Gelly)65(,)-432(et)-395(al.)-827(An)]TJ 0 -11.955 Td [(image)-266(is)-266(w)10(orth)-267(16x16)-266(w)10(ords:)-342(T)35(ransformers)-266(for)-267(image)]TJ 0 -11.955 Td [(recognition)-339(at)-338(scale.)-644(In)]TJ/F91 9.9626 Tf 99.818 0 Td [(International)-339(Confer)37(ence)-338(on)]TJ -99.818 -11.955 Td [(Learning)-250(Repr)37(esentations)-250(\(ICLR\))]TJ/F87 9.9626 Tf 133.568 0 Td [(,)-250(2021.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(2)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(8)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
0 g 0 G
-155.147 -10.959 Td [([11])]TJ
0 g 0 G
[-500(Rdiger)-250(Ehlers.)-359(F)15(ormal)-250(v)15(eri\002cation)-250(of)-250(piece-wise)-250(lin-)]TJ 21.579 -11.955 Td [(ear)-220(feed-forw)10(ard)-220(neural)-221(netw)10(orks.)-295(In)]TJ/F91 9.9626 Tf 147.889 0 Td [(A)20(utomated)-220(T)92(ec)15(h-)]TJ -147.889 -11.956 Td [(nolo)10(gy)-250(for)-250(V)111(eri\002cation)-250(and)-250(Analysis)]TJ/F87 9.9626 Tf 143.251 0 Td [(,)-250(2017.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-164.83 -10.958 Td [([12])]TJ
0 g 0 G
[-500(Iv)25(an)-195(Evtimo)15(v)65(,)-206(K)25(e)25(vin)-195(Eykholt,)-206(Earlence)-196(Fernandes,)-206(T)80(a-)]TJ 21.579 -11.956 Td [(dayoshi)-314(K)35(ohno,)-331(Bo)-315(Li,)-330(Atul)-315(Prakash,)-330(Amir)-315(Rahmati,)]TJ 0 -11.955 Td [(and)-401(Da)15(wn)-401(Song.)-844(Rob)20(ust)-401(ph)5(ysical-w)10(orld)-402(attac)1(ks)-402(on)]TJ 0 -11.955 Td [(machine)-212(learning)-212(models.)-278(In)]TJ/F91 9.9626 Tf 115.075 0 Td [(Confer)37(ence)-212(on)-212(Computer)]TJ -115.075 -11.955 Td [(V)74(ision)-250(and)-250(P)80(attern)-250(Reco)10(gnition)-250(\(CVPR\))]TJ/F87 9.9626 Tf 158.315 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-179.894 -10.959 Td [([13])]TJ
0 g 0 G
[-500(K)25(e)25(vin)-221(Eykholt,)-227(Iv)25(an)-221(Evtimo)15(v)65(,)-227(Earlence)-222(Fernandes,)-227(Bo)]TJ 21.579 -11.955 Td [(Li,)-312(Amir)-300(Rahmati,)-313(Florian)-300(T)35(ramer)40(,)-312(Atul)-300(Prakash,)-313(T)80(a-)]TJ 0 -11.955 Td [(dayoshi)-251(K)35(ohno,)-252(and)-251(Da)15(wn)-251(Song.)-364(Ph)5(ysical)-252(adv)15(ersarial)]TJ 0 -11.956 Td [(e)15(xamples)-250(for)-250(object)-250(detectors.)]TJ/F91 9.9626 Tf 122.958 0 Td [(CoRR)]TJ/F87 9.9626 Tf 23.8 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-168.337 -10.958 Td [([14])]TJ
0 g 0 G
[-500(Sv)15(en)-254(Go)25(w)10(al,)-255(Kri)1(shnamurth)5(y)-254(Dvijotham,)-255(Robert)-254(Stan-)]TJ 21.579 -11.956 Td [(forth,)-526(Rudy)-472(Bunel,)-526(Chongli)-471(Qin,)-527(Jonathan)-471(Uesato,)]TJ 0 -11.955 Td [(Relja)-506(Arandjelo)15(vic,)-571(T)35(imoth)5(y)-506(Mann,)-570(and)-507(Pushmeet)]TJ 0 -11.955 Td [(K)35(ohli.)-731(On)-366(the)-366(ef)25(fecti)25(v)15(eness)-366(of)-366(interv)25(al)-366(bound)-366(prop-)]TJ 0 -11.955 Td [(ag)5(ation)-376(for)-376(training)-377(v)15(eri\002ably)-376(rob)20(ust)-376(models.)-764(2018.)]TJ
1 0 0 rg 1 0 0 RG
0 -11.955 Td [(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([15])]TJ
0 g 0 G
[-500(Sv)15(en)-456(Go)25(w)10(al,)-507(Krishnamurth)5(y)-456(Dj)-456(Dvijot)1(ham,)-508(Robert)]TJ 21.579 -11.955 Td [(Stanforth,)-480(Rudy)-434(Bunel,)-480(Chongli)-434(Qin,)-481(Jonathan)-434(Ue-)]TJ 0 -11.956 Td [(sato,)-418(Relja)-385(Arandjelo)15(vic,)-419(T)35(imoth)5(y)-384(Mann,)-419(and)-385(Push-)]TJ 0 -11.955 Td [(meet)-406(K)35(ohli.)-860(Scalable)-406(v)15(eri\002ed)-406(training)-406(for)-407(pro)15(v)25(ably)]TJ 0 -11.955 Td [(rob)20(ust)-464(image)-464(classi\002cation.)-1045(In)]TJ/F91 9.9626 Tf 136.146 0 Td [(Pr)45(oceedings)-464(of)-464(the)]TJ -136.146 -11.955 Td [(IEEE/CVF)-243(International)-243(Confer)37(ence)-243(on)-244(Computer)-243(V)74(i-)]TJ 0 -11.955 Td [(sion)]TJ/F87 9.9626 Tf 16.608 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-38.187 -10.959 Td [([16])]TJ
0 g 0 G
[-500(Jamie)-316(Hayes.)-570(On)-316(visible)-316(adv)15(ersarial)-316(perturbations)-316(&)]TJ 21.579 -11.955 Td [(digital)-449(w)10(atermarking.)-998(In)]TJ/F91 9.9626 Tf 110.382 0 Td [(Pr)45(oceedings)-449(of)-450(the)-449(IEEE)]TJ -110.382 -11.956 Td [(Confer)37(ence)-375(on)-375(Computer)-375(V)74(ision)-375(and)-376(P)80(attern)-375(Reco)10(g-)]TJ 0 -11.955 Td [(nition)-250(W)92(orkshops)]TJ/F87 9.9626 Tf 69.1 0 Td [(,)-250(pages)-250(1597\2261604,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(8)]TJ
0 g 0 G
0 g 0 G
-90.679 -10.959 Td [([17])]TJ
0 g 0 G
[-500(Kaiming)-240(He,)-243(Xiangyu)-240(Zhang,)-243(Shaoqing)-240(Ren,)-242(and)-241(Jian)]TJ 21.579 -11.955 Td [(Sun.)-353(Deep)-247(residual)-247(learning)-247(for)-247(image)-246(recognition.)-354(In)]TJ
0 g 0 G
0 g 0 G
/F91 9.9626 Tf 258.75 622.665 Td [(Confer)37(ence)-245(on)-246(Computer)-245(V)74(ision)-246(and)-245(P)80(attern)-246(Reco)10(gni-)]TJ 0 -11.955 Td [(tion)-250(\(CVPR\))]TJ/F87 9.9626 Tf 49.534 0 Td [(,)-250(2016.)]TJ
1 0 0 rg 1 0 0 RG
[-360(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
0 g 0 G
-71.113 -10.959 Td [([18])]TJ
0 g 0 G
[-500(Shahar)-527(Hoory)65(,)-595(Tzvika)-527(Shapira,)-595(Asaf)-527(Shabtai,)-596(and)]TJ 21.579 -11.955 Td [(Y)111(uv)25(al)-720(Elo)15(vici.)-1865(Dynamic)-720(adv)15(ersarial)-720(patch)-721(for)]TJ 0 -11.955 Td [(e)25(v)25(ading)-578(object)-577(detection)-578(models.)]TJ/F91 9.9626 Tf 154.49 0 Td [(arXiv)-578(pr)37(eprint)]TJ -154.49 -11.955 Td [(arXiv:2010.13070)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-94.356 -10.959 Td [([19])]TJ
0 g 0 G
[-500(K)25(yle)-264(D)-263(Julian)-264(and)-263(Myk)10(el)-264(J)-263(K)35(ochenderfer)55(.)-404(Guarantee-)]TJ 21.579 -11.955 Td [(ing)-335(safety)-334(for)-335(neural)-335(netw)10(ork-bas)1(ed)-335(aircraft)-335(collision)]TJ 0 -11.956 Td [(a)20(v)20(oidance)-393(systems.)-819(In)]TJ/F91 9.9626 Tf 98.321 0 Td [(2019)-393(IEEE/AIAA)-393(38th)-394(Digi-)]TJ -98.321 -11.955 Td [(tal)-243(A)55(vionics)-242(Systems)-243(Confer)37(ence)-242(\(D)35(ASC\))]TJ/F87 9.9626 Tf 162.245 0 Td [(,)-243(pages)-242(1\22610.)]TJ -162.245 -11.955 Td [(IEEE,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([20])]TJ
0 g 0 G
[-500(Dann)15(y)-416(Karmon,)-457(Daniel)-415(Zoran,)-457(and)-416(Y)110(oa)20(v)-416(Goldber)18(g.)]TJ 21.579 -11.955 Td [(La)20(v)25(an:)-332(Localiz)1(ed)-261(and)-261(visible)-261(adv)15(ersarial)-260(noise.)-395(In)]TJ/F91 9.9626 Tf 203.055 0 Td [(In-)]TJ -203.055 -11.955 Td [(ternational)-365(Confer)37(ence)-364(on)-365(Mac)15(hine)-364(Learning)]TJ/F87 9.9626 Tf 185.578 0 Td [(,)-393(pages)]TJ -185.578 -11.955 Td [(2507\2262515.)-250(PMLR,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([21])]TJ
0 g 0 G
[-500(Guy)-495(Katz,)-557(Clark)-495(Barrett,)-557(Da)20(vid)-495(Dill,)-556(K)25(yle)-496(Julian,)]TJ 21.579 -11.955 Td [(and)-292(Myk)10(el)-291(K)35(ochenderfer)55(.)-493(Reluple)15(x:)-394(An)-291(ef)25(\002cient)-292(smt)]TJ 0 -11.956 Td [(solv)15(er)-365(for)-365(v)15(erifying)-365(deep)-365(neural)-365(netw)10(orks.)-729(In)]TJ/F91 9.9626 Tf 192.186 0 Td [(Inter)20(-)]TJ -192.186 -11.955 Td [(national)-289(Confer)37(ence)-290(on)-289(Computer)-289(Aided)-290(V)111(eri\002cation)]TJ/F87 9.9626 Tf 212.18 0 Td [(,)]TJ -212.18 -11.955 Td [(2017.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([22])]TJ
0 g 0 G
[-500(Ale)15(x)-239(Krizhe)25(vsk)15(y)65(.)-337(Learning)-240(multiple)-239(layers)-239(of)-240(features)]TJ 21.579 -11.955 Td [(from)-250(tin)15(y)-250(images.)-360(In)]TJ/F91 9.9626 Tf 84.791 0 Td [(T)92(ec)15(hnical)-250(r)37(eport)]TJ/F87 9.9626 Tf 65.255 0 Td [(,)-250(2009.)]TJ
1 0 0 rg 1 0 0 RG
[-360(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
0 g 0 G
-171.625 -10.959 Td [([23])]TJ
0 g 0 G
[-500(Mathias)-332(Lecuyer)40(,)-353(V)111(aggelis)-333(Atl)1(idakis,)-353(Roxana)-333(Geam-)]TJ 21.579 -11.955 Td [(basu,)-316(Daniel)-304(Hsu,)-316(and)-303(Suman)-303(Jana.)-531(Certi\002ed)-303(rob)20(ust-)]TJ 0 -11.955 Td [(ness)-266(to)-267(adv)15(ersarial)-266(e)15(xamples)-267(with)-266(dif)25(ferential)-267(pri)25(v)25(ac)15(y)65(.)]TJ 0 -11.955 Td [(In)]TJ/F91 9.9626 Tf 10.789 0 Td [(Symposium)-250(on)-250(Security)-250(and)-250(Privacy)-250(\(SP\))]TJ/F87 9.9626 Tf 164.074 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-196.442 -10.959 Td [([24])]TJ
0 g 0 G
[-500(Mark)-572(Lee)-572(and)-572(Zico)-572(K)35(olter)55(.)-1390(On)-572(ph)5(ysical)-572(adv)15(er)20(-)]TJ 21.579 -11.956 Td [(sarial)-468(pat)1(ches)-468(for)-468(object)-467(detection.)]TJ/F91 9.9626 Tf 155.588 0 Td [(arXiv)-468(pr)37(epri)1(nt)]TJ -155.588 -11.955 Td [(arXiv:1906.11897)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-94.356 -10.959 Td [([25])]TJ
0 g 0 G
[-500(Ale)15(xander)-468(Le)25(vine)-468(and)-468(Soheil)-468(Feizi.)-1058(\(de\))-468(random-)]TJ 21.579 -11.955 Td [(ized)-408(smoothing)-407(for)-408(certi\002able)-407(defense)-408(ag)5(ainst)-408(patch)]TJ 0 -11.955 Td [(attacks.)]TJ/F91 9.9626 Tf 37.155 0 Td [(arXiv)-357(pr)37(eprint)-357(arXiv:2002.10733)]TJ/F87 9.9626 Tf 134.316 0 Td [(,)-384(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-702(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
-171.471 -11.955 Td [(2)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(4)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(5)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(7)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(13)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(15)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(18)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(20)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(21)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([26])]TJ
0 g 0 G
[-500(Ale)15(xander)-337(Le)25(vine)-338(and)-337(Soheil)-337(Feizi.)-639(Rob)20(ustness)-338(cer)20(-)]TJ 21.579 -11.955 Td [(ti\002cates)-317(for)-317(sparse)-317(adv)15(ersarial)-317(attacks)-317(by)-317(randomized)]TJ 0 -11.955 Td [(ablation.)-600(In)]TJ/F91 9.9626 Tf 52.104 0 Td [(Pr)45(oceedings)-325(of)-325(the)-325(AAAI)-325(Confer)37(ence)-325(on)]TJ -52.104 -11.956 Td [(Arti\002cial)-345(Intellig)10(ence)]TJ/F87 9.9626 Tf 85.799 0 Td [(,)-369(v)20(olume)-345(34,)-369(pages)-346(4585\2264593,)]TJ -85.799 -11.955 Td [(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(2)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(7)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(13)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([27])]TJ
0 g 0 G
[-500(Ale)15(xander)-567(Le)25(vine)-567(and)-568(Soheil)-567(Feizi.)-1375(W)80(asserstein)]TJ 21.579 -11.955 Td [(smoothing:)-653(Certi\002ed)-421(rob)20(ustness)-421(ag)5(ainst)-422(w)10(asserstein)]TJ 0 -11.955 Td [(adv)15(ersarial)-403(attacks.)-851(In)]TJ/F91 9.9626 Tf 98.529 0 Td [(International)-403(Confer)37(ence)-404(on)]TJ -98.529 -11.955 Td [(Arti\002cial)-610(Intellig)10(ence)-611(and)-610(Statistics)]TJ/F87 9.9626 Tf 151.53 0 Td [(,)-700(pages)-611(3938\226)]TJ -151.53 -11.955 Td [(3947.)-250(PMLR,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([28])]TJ
0 g 0 G
[-500(Bai)-251(Li,)-250(Changyou)-251(Chen,)-251(W)80(enlin)-250(W)80(ang,)-251(and)-251(La)15(wrence)]TJ 21.579 -11.955 Td [(Carin.)-663(Certi\002ed)-345(adv)15(ersarial)-344(rob)20(ustness)-345(with)-345(additi)25(v)15(e)]TJ 0 -11.956 Td [(noise.)]TJ/F91 9.9626 Tf 27.108 0 Td [(arXiv)-250(pr)37(eprint)-250(arXiv:1809.03113)]TJ/F87 9.9626 Tf 132.183 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-180.87 -10.958 Td [([29])]TJ
0 g 0 G
[-500(W)80(an-Y)55(i)-488(Lin,)-548(F)15(atemeh)-488(Sheikholeslami,)-548(jinghao)-488(shi,)]TJ 21.579 -11.956 Td [(Leslie)-364(Rice,)-393(and)-364(J)-364(Zico)-364(K)35(olter)55(.)-725(Certi\002ed)-364(rob)20(ustness)]TJ 0 -11.955 Td [(ag)5(ainst)-225(adv)15(ersarial)-226(patch)-225(attacks)-225(via)-225(randomized)-226(crop-)]TJ 0 -11.955 Td [(ping.)-742(In)]TJ/F91 9.9626 Tf 39.569 0 Td [(ICML)-369(2021)-369(W)92(orkshop)-370(on)-369(Adver)10(sarial)-369(Ma-)]TJ -39.569 -11.955 Td [(c)15(hine)-250(Learning)]TJ/F87 9.9626 Tf 60.453 0 Td [(,)-250(2021.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-82.032 -10.959 Td [([30])]TJ
0 g 0 G
[-500(Xin)-438(Liu,)-484(Huanrui)-438(Y)100(ang,)-485(Ziwei)-437(Liu,)-485(Linghao)-438(Song,)]TJ 21.579 -11.955 Td [(Hai)-532(Li,)-602(and)-532(Y)55(iran)-532(Chen.)-1261(Dpatch:)-874(An)-532(adv)15(ersar)20(-)]TJ 0 -11.955 Td [(ial)-399(patch)-398(attack)-399(on)-398(object)-399(detectors.)]TJ/F91 9.9626 Tf 156.275 0 Td [(arXiv)-399(pr)37(eprint)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/Z9pvMy30vo9YFi8vvPthcA Do
Q
endstream
endobj
262 0 obj
<< /Font << /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /Z9pvMy30vo9YFi8vvPthcA 367 0 R >> >>
endobj
263 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 174.455 707.602 181.429 717.788 ] /Subtype /Link /Type /Annot >>
endobj
264 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 662.117 77.669 670.695 ] /Subtype /Link /Type /Annot >>
endobj
265 0 obj
<< /A << /D [ 8 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 150.016 613.953 156.99 624.139 ] /Subtype /Link /Type /Annot >>
endobj
266 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 159.979 613.953 166.953 624.139 ] /Subtype /Link /Type /Annot >>
endobj
267 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 208.338 566.531 215.312 577.315 ] /Subtype /Link /Type /Annot >>
endobj
268 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 255.161 543.497 262.134 554.401 ] /Subtype /Link /Type /Annot >>
endobj
269 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 173.071 485.435 180.045 495.621 ] /Subtype /Link /Type /Annot >>
endobj
270 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 183.033 485.435 190.007 495.621 ] /Subtype /Link /Type /Annot >>
endobj
271 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 426.655 77.669 436.842 ] /Subtype /Link /Type /Annot >>
endobj
272 0 obj
<< /A << /D [ 343 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 80.657 426.655 92.612 436.842 ] /Subtype /Link /Type /Annot >>
endobj
273 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 172.801 379.522 179.775 390.017 ] /Subtype /Link /Type /Annot >>
endobj
274 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 256.188 332.289 263.162 343.193 ] /Subtype /Link /Type /Annot >>
endobj
275 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 269.816 297.42 276.79 308.324 ] /Subtype /Link /Type /Annot >>
endobj
276 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 241.822 226.804 253.777 237.589 ] /Subtype /Link /Type /Annot >>
endobj
277 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 273.064 168.025 280.038 178.809 ] /Subtype /Link /Type /Annot >>
endobj
278 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 111.183 77.669 119.761 ] /Subtype /Link /Type /Annot >>
endobj
279 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 435.406 683.093 442.38 693.878 ] /Subtype /Link /Type /Annot >>
endobj
280 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 536.644 612.239 543.618 623.143 ] /Subtype /Link /Type /Annot >>
endobj
281 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 329.445 602.341 336.418 611.188 ] /Subtype /Link /Type /Annot >>
endobj
282 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 454.326 541.624 461.299 552.408 ] /Subtype /Link /Type /Annot >>
endobj
283 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 470.196 494.8 477.169 505.584 ] /Subtype /Link /Type /Annot >>
endobj
284 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 433.205 436.618 440.179 446.804 ] /Subtype /Link /Type /Annot >>
endobj
285 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 443.168 436.618 455.123 446.804 ] /Subtype /Link /Type /Annot >>
endobj
286 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 433.205 389.793 440.179 399.98 ] /Subtype /Link /Type /Annot >>
endobj
287 0 obj
<< /A << /D [ 6 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 355.447 331.014 362.421 341.2 ] /Subtype /Link /Type /Annot >>
endobj
288 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 365.41 331.014 372.384 341.2 ] /Subtype /Link /Type /Annot >>
endobj
289 0 obj
<< /A << /D [ 12 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 375.372 331.014 382.346 341.2 ] /Subtype /Link /Type /Annot >>
endobj
290 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 355.447 261.619 362.421 270.466 ] /Subtype /Link /Type /Annot >>
endobj
291 0 obj
<< /A << /S /URI /Type /Action /URI (https://github.com/rwightman/pytorch-image-models) >> /Border [ 0 0 0 ] /C [ 0 1 1 ] /H /I /Rect [ 496.077 248.603 546.108 259.507 ] /Subtype /Link /Type /Annot >>
endobj
292 0 obj
<< /A << /S /URI /Type /Action /URI (https://github.com/rwightman/pytorch-image-models) >> /Border [ 0 0 0 ] /C [ 0 1 1 ] /H /I /Rect [ 329.445 237.27 546.108 247.168 ] /Subtype /Link /Type /Annot >>
endobj
293 0 obj
<< /A << /S /URI /Type /Action /URI (https://github.com/rwightman/pytorch-image-models) >> /Border [ 0 0 0 ] /C [ 0 1 1 ] /H /I /Rect [ 329.445 225.41 367.303 235.596 ] /Subtype /Link /Type /Annot >>
endobj
294 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 396.294 225.41 403.268 235.596 ] /Subtype /Link /Type /Annot >>
endobj
295 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 406.257 225.41 418.212 235.596 ] /Subtype /Link /Type /Annot >>
endobj
296 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 467.088 177.988 474.062 188.772 ] /Subtype /Link /Type /Annot >>
endobj
297 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 401.375 131.452 408.348 141.948 ] /Subtype /Link /Type /Annot >>
endobj
298 0 obj
<< /Length 14478 >>
stream
q
q
0 g 0 G
0 g 0 G
BT
/F91 9.9626 Tf 71.691 710.037 Td [(arXiv:1806.02299)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-94.356 -10.959 Td [([31])]TJ
0 g 0 G
[-500(Alessio)-389(Lomuscio)-389(and)-389(Lalit)-389(Mag)5(anti.)-805(An)-389(approach)]TJ 21.579 -11.955 Td [(to)-400(reachability)-399(analysis)-400(for)-399(feed-forw)10(ard)-400(relu)-400(neural)]TJ 0 -11.955 Td [(netw)10(orks.)-390(In)]TJ/F91 9.9626 Tf 53.682 0 Td [(ArXiv)-259(pr)37(eprint)-260(arXiv:1706.07351)]TJ/F87 9.9626 Tf 133.475 0 Td [(,)-262(2017.)]TJ
1 0 0 rg 1 0 0 RG
-187.157 -11.955 Td [(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([32])]TJ
0 g 0 G
[-500(Jan)-336(Hendrik)-336(Metzen)-336(and)-336(Maksym)-336(Y)100(atsura.)-636(Ef)25(\002cient)]TJ 21.579 -11.955 Td [(certi\002ed)-246(defenses)-247(ag)5(ainst)-246(patch)-247(attacks)-246(on)-246(image)-247(clas-)]TJ 0 -11.955 Td [(si\002ers.)-383(In)]TJ/F91 9.9626 Tf 40.972 0 Td [(International)-257(Confer)37(ence)-258(on)-257(Learning)-257(Rep-)]TJ -40.972 -11.956 Td [(r)37(esentations)]TJ/F87 9.9626 Tf 48.338 0 Td [(,)-250(2021.)]TJ
1 0 0 rg 1 0 0 RG
[-360(4)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(7)]TJ
0 g 0 G
0 g 0 G
-69.917 -10.958 Td [([33])]TJ
0 g 0 G
[-500(Matthe)25(w)-394(Mirman,)-430(T)35(imon)-394(Gehr)40(,)-430(and)-394(Martin)-394(V)111(eche)25(v)65(.)]TJ 21.579 -11.956 Td [(Dif)25(ferentiable)-324(abstract)-323(interpretation)-324(for)-324(pro)15(v)25(ably)-324(ro-)]TJ 0 -11.955 Td [(b)20(ust)-275(neural)-274(netw)10(orks.)-439(In)]TJ/F91 9.9626 Tf 101.096 0 Td [(International)-275(Confer)37(ence)-274(on)]TJ -101.096 -11.955 Td [(Mac)15(hine)-250(Learning)-250(\(ICML\))]TJ/F87 9.9626 Tf 106.659 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-128.238 -10.959 Td [([34])]TJ
0 g 0 G
[-500(Norman)-381(Mu)-381(and)-381(Da)20(vid)-381(W)80(agner)55(.)-780(Defending)-381(ag)5(ainst)]TJ 21.579 -11.955 Td [(adv)15(ersarial)-250(patches)-250(with)-250(rob)20(ust)-250(self-attention.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([35])]TJ
0 g 0 G
[-500(Muzammal)-347(Naseer)40(,)-372(Salman)-347(Khan,)-372(and)-347(F)15(atih)-348(Porikli.)]TJ 21.579 -11.955 Td [(Local)-263(gradients)-264(smoothing:)-336(Defense)-263(ag)5(ainst)-264(localized)]TJ 0 -11.955 Td [(adv)15(ersarial)-287(attacks)1(.)-478(In)]TJ/F91 9.9626 Tf 92.474 0 Td [(2019)-287(IEEE)-286(W)55(inter)-287(Confer)37(ence)]TJ -92.474 -11.955 Td [(on)-401(Applications)-401(of)-401(Computer)-401(V)74(ision)-402(\(W)60(A)30(CV\))]TJ/F87 9.9626 Tf 185.499 0 Td [(,)-401(pages)]TJ -185.499 -11.956 Td [(1300\2261307.)-250(IEEE,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(8)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([36])]TJ
0 g 0 G
[-500(Muzammal)-493(Naseer)40(,)-553(Kanchana)-493(Ranasinghe,)-554(Salman)]TJ 21.579 -11.955 Td [(Khan,)-530(Muna)15(w)10(ar)-473(Hayat,)-530(F)15(ahad)-473(Shahbaz)-474(Khan,)-530(and)]TJ 0 -11.955 Td [(Ming-Hsuan)-464(Y)100(ang.)-1044(Intriguing)-464(properties)-464(of)-464(vision)]TJ 0 -11.955 Td [(transformers.)]TJ/F91 9.9626 Tf 55.844 0 Td [(arXiv)-223(pr)37(eprint)-223(arXiv:2105.10497)]TJ/F87 9.9626 Tf 131.645 0 Td [(,)-228(2021.)]TJ
1 0 0 rg 1 0 0 RG
-187.489 -11.955 Td [(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(14)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([37])]TJ
0 g 0 G
[-500(Aditi)-681(Raghunathan,)-789(Jacob)-681(Steinhardt,)-789(and)-681(Perc)15(y)]TJ 21.579 -11.955 Td [(Liang.)-795(Certi\002ed)-385(defenses)-386(ag)5(ainst)-386(adv)15(ersarial)-386(e)15(xam-)]TJ 0 -11.955 Td [(ples.)-376(In)]TJ/F91 9.9626 Tf 33.13 0 Td [(International)-255(Confer)37(ence)-255(on)-255(Learning)-255(Repr)37(e-)]TJ -33.13 -11.956 Td [(sentations)-250(\(ICLR\))]TJ/F87 9.9626 Tf 71.122 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-92.701 -10.959 Td [([38])]TJ
0 g 0 G
[-500(Anurag)-597(Ranjan,)-684(Joel)-597(Janai,)-684(Andreas)-597(Geiger)40(,)-684(and)]TJ 21.579 -11.955 Td [(Michael)-435(J)-434(Black.)-950(Attacking)-435(optical)-435<036f>25(w)65(.)-950(In)]TJ/F91 9.9626 Tf 196.858 0 Td [(Pr)45(o-)]TJ -196.858 -11.955 Td [(ceedings)-373(of)-373(the)-373(IEEE/CVF)-373(International)-373(Confer)37(ence)]TJ 0 -11.955 Td [(on)-250(Computer)-250(V)74(ision)]TJ/F87 9.9626 Tf 79.521 0 Td [(,)-250(pages)-250(2404\2262413,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-101.1 -10.959 Td [([39])]TJ
0 g 0 G
[-500(Sukrut)-330(Rao,)-349(Da)20(vid)-330(Stutz,)-349(and)-330(Bernt)-330(Schiele.)-615(Adv)15(er)20(-)]TJ 21.579 -11.955 Td [(sarial)-379(training)-379(ag)5(ainst)-379(location-optimized)-379(adv)15(ersarial)]TJ 0 -11.955 Td [(patches.)]TJ/F91 9.9626 Tf 35.955 0 Td [(arXiv)-250(pr)37(eprint)-250(arXiv:2005.02313)]TJ/F87 9.9626 Tf 132.183 0 Td [(,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-189.717 -10.959 Td [([40])]TJ
0 g 0 G
[-500(Olg)5(a)-640(Russak)10(o)15(vsk)15(y)65(,)-737(Jia)-640(Deng,)-737(Hao)-640(Su,)-738(Jonathan)]TJ 21.579 -11.955 Td [(Krause,)-295(Sanjee)25(v)-286(Satheesh,)-295(Sean)-286(Ma,)-296(Zhiheng)-286(Huang,)]TJ 0 -11.956 Td [(Andrej)-333(Karpath)5(y)65(,)-353(Aditya)-333(Khosla,)-353(Michael)-333(Bernstein,)]TJ 0 -11.955 Td [(Ale)15(xander)-326(C.)-325(Ber)18(g,)-345(and)-326(Li)-326(Fei-Fei.)-602(ImageNet)-326(Lar)18(ge)]TJ 0 -11.955 Td [(Scale)-273(V)60(isual)-273(Recognition)-273(Challenge.)-434(In)]TJ/F91 9.9626 Tf 162.089 0 Td [(International)]TJ -162.089 -11.955 Td [(J)25(ournal)-250(of)-250(Computer)-250(V)74(ision)-250(\(IJCV\))]TJ/F87 9.9626 Tf 140.143 0 Td [(,)-250(2015.)]TJ
1 0 0 rg 1 0 0 RG
[-360(12)]TJ
0 g 0 G
0 g 0 G
-161.722 -10.959 Td [([41])]TJ
0 g 0 G
[-500(Hadi)-313(Salman,)-330(Jerry)-313(Li,)-329(Ilya)-313(Razenshte)15(yn,)-330(Pengchuan)]TJ 21.579 -11.955 Td [(Zhang,)-566(Huan)-503(Zhang,)-565(Sebastien)-503(Bubeck,)-566(and)-503(Gre)15(g)]TJ 0 -11.955 Td [(Y)100(ang.)-373(Pro)15(v)25(ably)-254(rob)20(ust)-254(deep)-255(learni)1(ng)-255(via)-254(adv)15(ersarially)]TJ 0 -11.956 Td [(trained)-356(smoothed)-357(classi\002ers.)-700(In)]TJ/F91 9.9626 Tf 134.117 0 Td [(Advances)-356(in)-357(Neur)15(al)]TJ -134.117 -11.955 Td [(Information)-250(Pr)45(ocessing)-250(Systems)-250(\(NeurIPS\))]TJ/F87 9.9626 Tf 171.385 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-192.964 -10.959 Td [([42])]TJ
0 g 0 G
[-500(Hadi)-665(Salman,)-769(Mingjie)-665(Sun,)-769(Gre)15(g)-666(Y)100(ang,)-769(Ashish)]TJ 21.579 -11.955 Td [(Kapoor)40(,)-374(and)-349(J)-350(Zico)-349(K)35(olter)55(.)-678(Denoised)-349(smoothing:)-509(A)]TJ 0 -11.955 Td [(pro)15(v)25(able)-310(defense)-309(for)-310(pretrained)-309(classi\002ers.)]TJ/F91 9.9626 Tf 176.494 0 Td [(Advances)]TJ -176.494 -11.955 Td [(in)-314(Neur)15(al)-313(Information)-314(Pr)45(ocessing)-314(Systems)]TJ/F87 9.9626 Tf 170.744 0 Td [(,)-330(33,)-329(2020.)]TJ
1 0 0 rg 1 0 0 RG
-170.744 -11.955 Td [(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([43])]TJ
0 g 0 G
[-500(Hadi)-608(Salman,)-697(Gre)15(g)-608(Y)100(ang,)-697(Huan)-608(Zhang,)-698(Cho-Jui)]TJ 21.579 -11.955 Td [(Hsieh,)-424(and)-390(Pengchuan)-389(Zhang.)-807(A)-389(con)40(v)15(e)15(x)-390(relaxation)]TJ
0 g 0 G
0 g 0 G
258.75 620.672 Td [(barrier)-377(to)-378(tight)-377(rob)20(ustness)-378(v)15(eri\002cation)-377(of)-377(neural)-378(net-)]TJ 0 -11.955 Td [(w)10(orks.)]TJ/F91 9.9626 Tf 34.549 0 Td [(Advances)-382(in)-383(Neur)15(al)-382(Information)-383(Pr)45(ocessing)]TJ -34.549 -11.955 Td [(Systems)-250(\(NeurIPS\))]TJ/F87 9.9626 Tf 74.978 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-96.557 -10.959 Td [([44])]TJ
0 g 0 G
[-500(Mahmood)-275(Sharif,)-281(Sruti)-275(Bhag)5(a)20(v)25(atula,)-281(Lujo)-275(Bauer)40(,)-281(and)]TJ 21.579 -11.955 Td [(Michael)-304(K.)-304(Reiter)55(.)-533(Accessorize)-304(to)-304(a)-304(crime:)-418(Real)-304(and)]TJ 0 -11.955 Td [(stealth)5(y)-225(attacks)-225(on)-225(state-of-)1(the-art)-225(f)10(ace)-225(recognition.)-306(In)]TJ/F91 9.9626 Tf 0 -11.956 Td [(Pr)45(oceedings)-234(of)-234(the)-233(2016)-234(A)30(CM)-234(SIGSA)30(C)-234(Confer)37(ence)-234(on)]TJ 0 -11.955 Td [(Computer)-190(and)-191(Communications)-190(Security)55(,)-202(V)74(ienna,)-203(A)20(us-)]TJ 0 -11.955 Td [(tria,)-234(October)-231(24-28,)-234(2016)]TJ/F87 9.9626 Tf 102.157 0 Td [(,)-234(pages)-231(1528\2261540,)-234(2016.)]TJ
1 0 0 rg 1 0 0 RG
[-318(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
-102.157 -11.955 Td [(8)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([45])]TJ
0 g 0 G
[-500(Simen)-355(Th)5(ys,)-381(W)40(iebe)-355(V)111(an)-355(Ranst,)-381(and)-355(T)80(oon)-355(Goedem.)]TJ 21.579 -11.955 Td [(F)15(ooling)-346(automated)-347(surv)15(eillance)-346(cameras:)-503(adv)15(ersarial)]TJ 0 -11.955 Td [(patches)-291(to)-291(attack)-290(person)-291(detection.)-491(In)]TJ/F91 9.9626 Tf 154.668 0 Td [(Pr)45(oceedings)-291(of)]TJ -154.668 -11.956 Td [(the)-241(IEEE)-240(Confer)37(ence)-241(on)-241(Computer)-240(V)74(ision)-241(and)-241(P)80(attern)]TJ 0 -11.955 Td [(Reco)10(gnition)-250(W)92(orkshops)]TJ/F87 9.9626 Tf 93.897 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
0 g 0 G
-115.476 -10.959 Td [([46])]TJ
0 g 0 G
[-500(V)60(incent)-267(Tjeng,)-271(Kai)-267(Xi)1(ao,)-271(and)-267(Russ)-267(T)70(edrak)10(e.)-414(Ev)25(aluat-)]TJ 21.579 -11.955 Td [(ing)-294(rob)20(ustness)-293(of)-294(neural)-293(netw)10(orks)-294(with)-293(mix)15(ed)-294(inte)15(ger)]TJ 0 -11.955 Td [(programming.)-399(In)]TJ/F91 9.9626 Tf 71.613 0 Td [(International)-262(Confer)37(ence)-262(on)-263(Learn-)]TJ -71.613 -11.955 Td [(ing)-250(Repr)37(esentations)-250(\(ICLR\))]TJ/F87 9.9626 Tf 109.767 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-131.346 -10.959 Td [([47])]TJ
0 g 0 G
[-500(Hugo)-248(T)80(ouvron,)-249(Matthieu)-248(Cord,)-249(Matthijs)-248(Douze,)-249(Fran-)]TJ 21.579 -11.955 Td [(cisco)-651(Massa,)-752(Ale)15(xandre)-651(Sablayrolles,)-751(and)-652(Herv)]TJ 0 -11.955 Td [(Jgou.)-1236(T)35(raining)-523(data-ef)25(\002cient)-524(image)-524(transformers)]TJ 0 -11.956 Td [(&)-640(distillation)-640(through)-639(attention.)]TJ/F91 9.9626 Tf 153.871 0 Td [(arXiv)-640(pr)37(eprint)]TJ -153.871 -11.955 Td [(arXiv:2012.12877)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(8)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
0 g 0 G
-94.356 -10.959 Td [([48])]TJ
0 g 0 G
[-500(Florian)-629(T)35(ramer)40(,)-723(Nicholas)-629(Carlini,)-723(W)40(ieland)-629(Bren-)]TJ 21.579 -11.955 Td [(del,)-586(and)-518(Aleksander)-519(Madry)65(.)-1220(On)-518(adapti)25(v)15(e)-519(attacks)]TJ 0 -11.955 Td [(to)-598(adv)15(ersarial)-599(e)15(xample)-598(defenses.)]TJ/F91 9.9626 Tf 154.284 0 Td [(arXiv)-598(pr)37(eprint)]TJ -154.284 -11.955 Td [(arXiv:2002.08347)]TJ/F87 9.9626 Tf 72.777 0 Td [(,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-94.356 -10.959 Td [([49])]TJ
0 g 0 G
[-500(Ashish)-345(V)111(asw)10(ani,)-368(Noam)-345(Shaze)1(er)39(,)-368(Niki)-344(P)15(armar)40(,)-369(Jak)10(ob)]TJ 21.579 -11.955 Td [(Uszk)10(oreit,)-637(Llion)-559(Jones,)-637(Aidan)-560(N)-559(Gomez,)-637(\006ukasz)]TJ 0 -11.955 Td [(Kaiser)40(,)-226(and)-220(Illia)-219(Polosukhin.)-295(Attention)-219(is)-220(all)-220(you)-220(need.)]TJ/F91 9.9626 Tf 0 -11.956 Td [(Advances)-316(in)-317(Neur)15(al)-316(Information)-316(Pr)45(ocessing)-317(Systems)]TJ/F87 9.9626 Tf 212.18 0 Td [(,)]TJ -212.18 -11.955 Td [(2017.)]TJ
1 0 0 rg 1 0 0 RG
[-360(2)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(8)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([50])]TJ
0 g 0 G
[-500(Tsui-W)80(ei)-434(W)80(eng,)-479(Huan)-434(Zhang,)-479(Hongge)-434(Chen,)-480(Zhao)]TJ 21.579 -11.955 Td [(Song,)-748(Cho-Jui)-648(Hsieh,)-747(Duane)-648(Boning,)-748(Inderjit)-648(S)]TJ 0 -11.955 Td [(Dhillon,)-317(and)-304(Luca)-304(Daniel.)-532(T)80(o)25(w)10(ards)-304(f)10(ast)-304(computation)]TJ 0 -11.955 Td [(of)-334(certi\002ed)-333(rob)20(ustness)-334(for)-334(ReLU)-333(netw)10(orks.)-628(In)]TJ/F91 9.9626 Tf 192.186 0 Td [(Inter)20(-)]TJ -192.186 -11.955 Td [(national)-437(Confer)37(ence)-437(on)-437(Mac)15(hine)-437(Learning)-437(\(ICML\))]TJ/F87 9.9626 Tf 212.18 0 Td [(,)]TJ -212.18 -11.956 Td [(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.958 Td [([51])]TJ
0 g 0 G
[-500(Ross)-270(W)40(ightman.)-423(Pytorch)-269(image)-270(models.)]TJ
0 1 0 0 k 0 1 0 0 K
/F89 9.9626 Tf 188.212 0 Td [(https)-7(:)-8(/)-7(/)]TJ -166.633 -11.956 Td [(github)-50(.)-49(com)-50(/)-50(rwightman)-50(/)-49(pytorch)-50(-)-100(image)-50(-)]TJ 0 -11.955 Td [(models)]TJ
0 g 0 G
/F87 9.9626 Tf 35.866 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
0 g 0 G
-57.445 -10.959 Td [([52])]TJ
0 g 0 G
[-500(Eric)-502(W)80(ong)-502(and)-502(J)-502(Zico)-502(K)35(olter)55(.)-1167(Pro)15(v)25(able)-502(defenses)]TJ 21.579 -11.955 Td [(ag)5(ainst)-285(adv)15(ersari)1(al)-285(e)15(xamples)-285(via)-284(the)-285(con)40(v)15(e)15(x)-284(outer)-285(ad-)]TJ 0 -11.955 Td [(v)15(ersarial)-434(polytope.)-949(In)]TJ/F91 9.9626 Tf 97.917 0 Td [(International)-434(Confer)37(ence)-434(on)]TJ -97.917 -11.955 Td [(Mac)15(hine)-250(Learning)-250(\(ICML\))]TJ/F87 9.9626 Tf 106.659 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-128.238 -10.959 Td [([53])]TJ
0 g 0 G
[-500(Eric)-288(W)80(ong,)-298(Frank)-289(Schmidt,)-298(Jan)-288(Hendrik)-289(Metzen,)-298(and)]TJ 21.579 -11.955 Td [(Zico)-241(K)35(olter)55(.)-340(Scaling)-240(pro)15(v)25(able)-241(adv)15(ersarial)-241(defenses.)-340(In)]TJ/F91 9.9626 Tf 0 -11.955 Td [(Advances)-366(in)-367(Neur)15(al)-366(Information)-366(Pr)45(ocessing)-367(Systems)]TJ 0 -11.956 Td [(\(NeurIPS\))]TJ/F87 9.9626 Tf 40.946 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-62.525 -10.959 Td [([54])]TJ
0 g 0 G
[-500(Eric)-401(W)80(ong,)-438(T)35(im)-400(Schneider)40(,)-438(Joer)18(g)-401(Schmitt,)-438(Frank)-401(R)]TJ 21.579 -11.955 Td [(Schmidt,)-399(and)-369(J)-368(Zico)-369(K)35(olter)55(.)-741(Neural)-369(netw)10(ork)-369(virtual)]TJ 0 -11.955 Td [(sensors)-238(for)-238(fuel)-238(injection)-238(quantities)-238(with)-239(pro)15(v)25(able)-238(per)20(-)]TJ 0 -11.955 Td [(formance)-475(speci\002cations.)-1079(In)]TJ/F91 9.9626 Tf 122.854 0 Td [(2020)-475(IEEE)-474(Intellig)10(ent)]TJ
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/LacexmtO3Ad-CSw5C1IBJA Do
Q
endstream
endobj
299 0 obj
<< /Font << /F87 323 0 R /F89 324 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /LacexmtO3Ad-CSw5C1IBJA 368 0 R >> >>
endobj
300 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 96.697 696.986 103.671 705.833 ] /Subtype /Link /Type /Annot >>
endobj
301 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 135.591 636.15 142.565 647.053 ] /Subtype /Link /Type /Annot >>
endobj
302 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 232.415 577.036 239.389 588.991 ] /Subtype /Link /Type /Annot >>
endobj
303 0 obj
<< /A << /D [ 8 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 242.539 577.036 249.513 588.991 ] /Subtype /Link /Type /Annot >>
endobj
304 0 obj
<< /A << /D [ 9 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 252.664 577.036 259.637 588.991 ] /Subtype /Link /Type /Annot >>
endobj
305 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 262.788 577.036 269.762 588.991 ] /Subtype /Link /Type /Annot >>
endobj
306 0 obj
<< /A << /D [ 345 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 272.912 577.036 284.868 588.991 ] /Subtype /Link /Type /Annot >>
endobj
307 0 obj
<< /A << /D [ 366 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 567.572 82.65 576.319 ] /Subtype /Link /Type /Annot >>
endobj
308 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 180.731 507.044 187.705 517.539 ] /Subtype /Link /Type /Annot >>
endobj
309 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 205.438 471.766 212.412 482.67 ] /Subtype /Link /Type /Annot >>
endobj
310 0 obj
<< /A << /D [ 343 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 193.275 401.031 205.23 411.935 ] /Subtype /Link /Type /Annot >>
endobj
311 0 obj
<< /A << /D [ 7 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 366.879 77.669 377.066 ] /Subtype /Link /Type /Annot >>
endobj
312 0 obj
<< /A << /D [ 344 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 80.657 366.879 92.612 377.066 ] /Subtype /Link /Type /Annot >>
endobj
313 0 obj
<< /A << /D [ 343 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 96.697 321.395 108.652 330.241 ] /Subtype /Link /Type /Annot >>
endobj
314 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 259.316 272.633 266.29 283.417 ] /Subtype /Link /Type /Annot >>
endobj
315 0 obj
<< /A << /D [ 5 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 70.695 214.451 77.669 224.638 ] /Subtype /Link /Type /Annot >>
endobj
316 0 obj
<< /A << /D [ 8 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 80.657 214.451 87.631 224.638 ] /Subtype /Link /Type /Annot >>
endobj
317 0 obj
<< /A << /D [ 11 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 90.62 214.451 97.594 224.638 ] /Subtype /Link /Type /Annot >>
endobj
318 0 obj
<< /A << /D [ 345 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 100.583 214.451 112.538 224.638 ] /Subtype /Link /Type /Annot >>
endobj
319 0 obj
<< /A << /D [ 366 0 R /XYZ 49.112 721 null ] /S /GoTo >> /Border [ 0 0 0 ] /C [ 1 0 0 ] /H /I /Rect [ 115.527 214.451 127.482 224.638 ] /Subtype /Link /Type /Annot >>
endobj
320 0 obj
<< /Length 6279 >>
stream
q
q
0 g 0 G
0 g 0 G
BT
/F91 9.9626 Tf 71.691 710.037 Td [(V)111(ehicles)-483(Sympos)1(ium)-483(\(IV\))]TJ/F87 9.9626 Tf 103.681 0 Td [(,)-483(pages)-482(1753\2261758.)-483(IEEE,)]TJ -103.681 -11.955 Td [(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([55])]TJ
0 g 0 G
[-500(Zuxuan)-336(W)50(u,)-357(Ser)20(-Nam)-335(Lim,)-357(Larry)-336(S)-335(Da)20(vis,)-357(and)-336(T)80(om)]TJ 21.579 -11.955 Td [(Goldstein.)-634(Making)-336(an)-336(in)40(visibility)-336(cl)1(oak:)-482(Real)-336(w)10(orld)]TJ 0 -11.955 Td [(adv)15(ersarial)-538(attacks)-538(on)-539(object)-538(detectors.)-1282(In)]TJ/F91 9.9626 Tf 191.877 0 Td [(Eur)45(o-)]TJ -191.877 -11.955 Td [(pean)-453(Confer)37(ence)-454(on)-453(Computer)-454(V)74(ision)]TJ/F87 9.9626 Tf 157.537 0 Td [(,)-504(pages)-454(1\22617.)]TJ -157.537 -11.955 Td [(Springer)40(,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(1)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([56])]TJ
0 g 0 G
[-500(Chong)-358(Xiang,)-385(Arjun)-358(Nitin)-358(Bhagoji,)-385(V)60(ikash)-358(Sehw)10(ag,)]TJ 21.579 -11.955 Td [(and)-387(Prateek)-387(Mittal.)-799(P)15(atchguard:)-584(A)-387(pro)15(v)25(ably)-387(rob)20(ust)]TJ 0 -11.956 Td [(defense)-213(ag)5(ainst)-214(adv)15(ersarial)-213(patches)-214(via)-213(small)-214(recepti)25(v)15(e)]TJ 0 -11.955 Td [(\002elds)-262(and)-261(masking.)-397(In)]TJ/F91 9.9626 Tf 92.303 0 Td [(30th)]TJ/F14 9.9626 Tf 20.319 0 Td [(f)]TJ/F91 9.9626 Tf 4.982 0 Td [(USENIX)]TJ/F14 9.9626 Tf 34.311 0 Td [(g)]TJ/F91 9.9626 Tf 7.587 0 Td [(Security)-262(Sym-)]TJ -159.502 -11.955 Td [(posium)-263(\()]TJ/F14 9.9626 Tf 34.719 0 Td [(f)]TJ/F91 9.9626 Tf 4.982 0 Td [(USENIX)]TJ/F14 9.9626 Tf 34.311 0 Td [(g)]TJ/F91 9.9626 Tf 7.601 0 Td [(Security)-263(21\))]TJ/F87 9.9626 Tf 48.548 0 Td [(,)-266(2021.)]TJ
1 0 0 rg 1 0 0 RG
[-402(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-266(4)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-266(5)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-266(7)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-267(20)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
-130.161 -11.955 Td [(21)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([57])]TJ
0 g 0 G
[-500(Kai)-260(Y)129(.)-259(Xiao,)-263(V)60(incent)-259(Tjeng,)-262(Nur)-260(Muhammad)-260(Sha\002ul-)]TJ 21.579 -11.955 Td [(lah,)-258(and)-257(Aleksander)-256(Madry)65(.)-381(T)35(raining)-257(for)-256(f)10(aster)-257(adv)15(er)20(-)]TJ 0 -11.955 Td [(sarial)-338(rob)20(ustness)-339(v)15(eri\002cation)-338(via)-338(inducing)-338(ReLU)-339(sta-)]TJ 0 -11.956 Td [(bility)65(.)-517(In)]TJ/F91 9.9626 Tf 39.31 0 Td [(International)-299(Confer)37(ence)-299(on)-299(Learning)-299(Rep-)]TJ -39.31 -11.955 Td [(r)37(esentations)-250(\(ICLR\))]TJ/F87 9.9626 Tf 79.052 0 Td [(,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-100.631 -10.959 Td [([58])]TJ
0 g 0 G
[-500(Gre)15(g)-297(Y)100(ang,)-309(T)80(on)15(y)-297(Duan,)-308(J.)-297(Edw)10(ard)-297(Hu,)-309(Hadi)-297(Salman,)]TJ 21.579 -11.955 Td [(Ilya)-265(Razens)1(h)-1(t)1(e)15(yn)-1(,)-268(and)-264(Jerry)-265(Li.)-406(Randomized)-265(smooth-)]TJ 0 -11.955 Td [(ing)-250(of)-250(all)-250(shapes)-250(and)-250(sizes,)-250(2020.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([59])]TJ
0 g 0 G
[-500(Sangdoo)-663(Y)111(un,)-767(Dongyoon)-664(Han,)-767(Seong)-663(Joon)-664(Oh,)]TJ 21.579 -11.955 Td [(Sangh)5(yuk)-373(Chun,)-404(Junsuk)-373(Choe,)-404(and)-373(Y)110(oungjoon)-374(Y)110(oo.)]TJ 0 -11.955 Td [(Cutmix:)-315(Re)15(gularization)-253(strate)15(gy)-253(to)-252(train)-253(strong)-253(classi-)]TJ 0 -11.955 Td [<02657273>-321(with)-321(localizable)-321(features.)-588(In)]TJ/F91 9.9626 Tf 138.994 0 Td [(Pr)45(oceedings)-321(of)-321(the)]TJ -138.994 -11.956 Td [(IEEE/CVF)-243(International)-243(Confer)37(ence)-243(on)-244(Computer)-243(V)74(i-)]TJ 0 -11.955 Td [(sion)]TJ/F87 9.9626 Tf 16.608 0 Td [(,)-250(pages)-250(6023\2266032,)-250(2019.)]TJ
1 0 0 rg 1 0 0 RG
[-360(14)]TJ
0 g 0 G
0 g 0 G
-38.187 -10.959 Td [([60])]TJ
0 g 0 G
[-500(Ser)18(ge)15(y)-217(Zagoruyk)10(o)-217(and)-217(Nik)10(os)-217(K)35(omodakis.)-289(W)40(ide)-217(resid-)]TJ 21.579 -11.955 Td [(ual)-215(netw)10(orks.)]TJ/F91 9.9626 Tf 56.064 0 Td [(arXiv)-215(pr)37(eprint)-215(arXiv:1605.07146)]TJ/F87 9.9626 Tf 131.488 0 Td [(,)-222(2016.)]TJ
1 0 0 rg 1 0 0 RG
-187.552 -11.955 Td [(3)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(12)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([61])]TJ
0 g 0 G
[-500(Hongyi)-388(Zhang,)-423(Moustapha)-389(Cisse,)-423(Y)100(ann)-388(N)-389(Dauphin,)]TJ 21.579 -11.955 Td [(and)-499(Da)20(vid)-499(Lopez-P)15(az.)-1157(mixup:)-808(Be)15(yond)-499(empirical)]TJ 0 -11.955 Td [(risk)-304(minimization.)]TJ/F91 9.9626 Tf 78.918 0 Td [(arXiv)-304(pr)37(eprint)-304(arXiv:1710.09412)]TJ/F87 9.9626 Tf 133.262 0 Td [(,)]TJ -212.18 -11.955 Td [(2017.)]TJ
1 0 0 rg 1 0 0 RG
[-360(14)]TJ
0 g 0 G
0 g 0 G
-21.579 -10.959 Td [([62])]TJ
0 g 0 G
[-500(Huan)-326(Zhang,)-346(Tsui-W)80(ei)-326(W)80(eng,)-346(Pin-Y)111(u)-326(Chen,)-346(Cho-Jui)]TJ 21.579 -11.956 Td [(Hsieh,)-518(and)-464(Luca)-464(Daniel.)-1046(Ef)25(\002cient)-464(neural)-465(netw)10(ork)]TJ 0 -11.955 Td [(rob)20(ustness)-369(certi\002cation)-368(with)-369(general)-369(acti)25(v)25(ation)-369(func-)]TJ 0 -11.955 Td [(tions.)]TJ/F91 9.9626 Tf 25.454 0 Td [(arXiv)-250(pr)37(eprint)-250(arXiv:1811.00866)]TJ/F87 9.9626 Tf 132.183 0 Td [(,)-250(2018.)]TJ
1 0 0 rg 1 0 0 RG
[-360(7)]TJ
0 g 0 G
0 g 0 G
-179.216 -10.959 Td [([63])]TJ
0 g 0 G
[-500(Zhan)15(yuan)-466(Zhang,)-519(Benson)-466(Y)111(uan,)-520(Michael)-466(McCo)10(yd,)]TJ 21.579 -11.955 Td [(and)-219(Da)20(vid)-219(W)80(agner)55(.)-292(Clipped)-219(bagnet:)-294(defending)-219(ag)5(ainst)]TJ 0 -11.955 Td [(stick)10(er)-322(attacks)-322(with)-322(clipped)-323(bag-of-features.)-591(In)]TJ/F91 9.9626 Tf 194.746 0 Td [(2020)]TJ -194.746 -11.955 Td [(IEEE)-339(Security)-338(and)-339(Privacy)-339(W)92(orkshops)-339(\(SPW\))]TJ/F87 9.9626 Tf 186.389 0 Td [(,)-339(2020.)]TJ
1 0 0 rg 1 0 0 RG
-186.389 -11.956 Td [(1)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(4)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(7)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(20)]TJ
0 g 0 G
[(,)]TJ
1 0 0 rg 1 0 0 RG
[-250(21)]TJ
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
0 g 0 G
ET
Q
Q
q
1 0 0 1 0 0 cm
/PoYM3fF_5KxXDObZC2xjtA Do
Q
endstream
endobj
321 0 obj
<< /Font << /F14 334 0 R /F87 323 0 R /F91 325 0 R >> /ProcSet [ /PDF /Text ] /XObject << /PoYM3fF_5KxXDObZC2xjtA 369 0 R >> >>
endobj
322 0 obj
<< /BaseFont /QVQWZT+NimbusRomNo9L-Medi /Encoding 370 0 R /FirstChar 2 /FontDescriptor 371 0 R /LastChar 173 /Subtype /Type1 /Type /Font /Widths 372 0 R >>
endobj
323 0 obj
<< /BaseFont /LHANFF+NimbusRomNo9L-Regu /Encoding 370 0 R /FirstChar 2 /FontDescriptor 373 0 R /LastChar 252 /Subtype /Type1 /Type /Font /Widths 374 0 R >>
endobj
324 0 obj
<< /BaseFont /QIWLSB+NimbusMonL-Regu /Encoding 370 0 R /FirstChar 45 /FontDescriptor 375 0 R /LastChar 121 /Subtype /Type1 /Type /Font /Widths 376 0 R >>
endobj
325 0 obj
<< /BaseFont /IUSOAZ+NimbusRomNo9L-ReguItal /Encoding 370 0 R /FirstChar 2 /FontDescriptor 377 0 R /LastChar 122 /Subtype /Type1 /Type /Font /Widths 378 0 R >>
endobj
326 0 obj
<< /BBox [ 0 0 612 792 ] /Group << /CS /DeviceRGB /I true /S /Transparency /Type /Group >> /Resources << /ExtGState << /a0 << /CA 1 /ca 1 >> /a1 << /CA 0.5 /ca 0.5 >> >> /XObject << /x6 379 0 R >> >> /Subtype /Form /Type /XObject /Length 382 /Filter /FlateDecode >>
stream
xe[n!Y7P|=Q'y(Ji;#$v0U-V\oZWɽ:5db,6IR6@6Pc"3K+GQ؎3T<9j`UT@
v5ڳtHN;9+7[^S؇:[E"8+sW\qEeКu6Bhsj;)y;Tp0nؚgʦFǃS-="z7ۺ9*&Q~ZPuí}C9嬂8l?Jܪmx%e8w](Rlq鞋t×e:=p=y0`XeJCWxau~uof{`r
endstream
endobj
327 0 obj
<< /BBox [ 0 0 612 792 ] /Matrix [ 1 0 0 1 0 0 ] /Resources << /Font 380 0 R /ProcSet [ /PDF /Text /ImageB /ImageC /ImageI ] >> /Subtype /Form /Type /XObject /Length 114 /Filter /FlateDecode >>
stream
x-0D|CDk2uT ;p>=%=&D
)`\+|ЖJSs<ن+R c+s*]76/2
endstream
endobj
328 0 obj
null
endobj
329 0 obj
<< /BaseFont /BNWWYZ+CMEX10 /FirstChar 18 /FontDescriptor 381 0 R /LastChar 88 /Subtype /Type1 /Type /Font /Widths 382 0 R >>
endobj
330 0 obj
<< /BaseFont /QXFESX+CMMI7 /FirstChar 59 /FontDescriptor 383 0 R /LastChar 121 /Subtype /Type1 /Type /Font /Widths 384 0 R >>
endobj
331 0 obj
<< /BaseFont /CCRXBW+CMMI10 /FirstChar 58 /FontDescriptor 385 0 R /LastChar 119 /Subtype /Type1 /Type /Font /Widths 386 0 R >>
endobj
332 0 obj
<< /BaseFont /EXPITJ+CMSY5 /FirstChar 48 /FontDescriptor 387 0 R /LastChar 48 /Subtype /Type1 /Type /Font /Widths 388 0 R >>
endobj
333 0 obj
<< /BaseFont /AVCWRG+CMSY7 /FirstChar 0 /FontDescriptor 389 0 R /LastChar 54 /Subtype /Type1 /Type /Font /Widths 390 0 R >>
endobj
334 0 obj
<< /BaseFont /SCYMPP+CMSY10 /FirstChar 0 /FontDescriptor 391 0 R /LastChar 103 /Subtype /Type1 /Type /Font /Widths 392 0 R >>
endobj
335 0 obj
<< /BaseFont /AQUIJZ+CMR7 /FirstChar 40 /FontDescriptor 393 0 R /LastChar 61 /Subtype /Type1 /Type /Font /Widths 394 0 R >>
endobj
336 0 obj
<< /BaseFont /JYDBGW+MSBM10 /FirstChar 73 /FontDescriptor 395 0 R /LastChar 82 /Subtype /Type1 /Type /Font /Widths 396 0 R >>
endobj
337 0 obj
<< /BaseFont /BGHSHM+CMBX10 /FirstChar 48 /FontDescriptor 397 0 R /LastChar 122 /Subtype /Type1 /Type /Font /Widths 398 0 R >>
endobj
338 0 obj
<< /BaseFont /NHBHOS+CMBX7 /FirstChar 120 /FontDescriptor 399 0 R /LastChar 120 /Subtype /Type1 /Type /Font /Widths 400 0 R >>
endobj
339 0 obj
<< /BaseFont /OSGHCI+CMR10 /FirstChar 1 /FontDescriptor 401 0 R /LastChar 120 /Subtype /Type1 /Type /Font /Widths 402 0 R >>
endobj
340 0 obj
<< /BaseFont /MPMQRA+CMMI5 /FirstChar 98 /FontDescriptor 403 0 R /LastChar 98 /Subtype /Type1 /Type /Font /Widths 404 0 R >>
endobj
341 0 obj
<< /BBox [ 0 0 804 160 ] /Filter /FlateDecode /FormType 1 /PTEX.FileName (/Users/hadi/papers/certified-vit-paper/figures/example_column_ablations_ellipses.pdf) /PTEX.InfoDict 405 0 R /PTEX.PageNumber 1 /Resources << /ColorSpace << /Cs1 406 0 R >> /Font << /TT2 407 0 R >> /ProcSet [ /PDF /Text /ImageB /ImageC /ImageI ] /XObject << /Im1 408 0 R /Im2 409 0 R /Im3 410 0 R /Im4 411 0 R /Im5 412 0 R /Im6 413 0 R >> >> /Subtype /Form /Type /XObject /Length 306 >>
stream
xN <Ÿ e¥ ¤OFswfΙ f)'[ v9t=~B8q"
IlQTTUbQTtUI)nq>)o}9K+礔XSΚăp
_u8z"ypV9(ۂrj5̚!osԑrnv\b5vD\,8XW!;
endstream
endobj
342 0 obj
<< /BBox [ 0 0 612 792 ] /Matrix [ 1 0 0 1 0 0 ] /Resources << /Font 414 0 R /ProcSet [ /PDF /Text /ImageB /ImageC /ImageI ] >> /Subtype /Form /Type /XObject /Length 114 /Filter /FlateDecode >>
stream
x-0D|i;ҮH0u T;p>=%=܌CVĂ--xዶDV:Xt%JEi>x ?3
endstream
endobj
343 0 obj
null
endobj
344 0 obj
null
endobj
345 0 obj
null
endobj
346 0 obj
<< /BitsPerComponent 8 /ColorSpace /DeviceRGB /Filter /FlateDecode /Height 421 /SMask 415 0 R /Subtype /Image /Type /XObject /Width 1828 /Length 248138 >>
stream
xYpTk¤*UJ(&ȩ|NSu0awK̚zڻGI- ?>XILBl10F`afM16[{jUWk{X{G~? 2s]vmݺ0yW֯_oj&j&j&j&j&j&j{M4<>vf #wUۧ~:lhDMDMDMDMDMDM,ޚwL2ּ}6F 'O|w_z%J^r믿FK۶mKMN>}[
<!o/[4{;fҫǎ 0}KaƍG `t?^1_yxcp ͛_}vq7nc `|;wa&
6yԹjժ?gϞH @w}7w=|0]W ;4