LATIDIA · Ciberseguridad
Revisión de la defensa certificada con privacidad diferencial en los transformadores de visión
arXiv:2609.31310v1 Tipo de Anuncio: nuevo Resumen: Las defensas certificadas que incorporan privacidad diferencial han demostrado ser efectivas en las Redes Neuronales Convolucionales (CNN), proporcionando rigurosas garantías de robustez contra
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.31310v1 Announce Type: new Abstract: Certified defenses that incorporate differential privacy have proven effective on Convolutional Neural Networks (CNNs), furnishing rigorous robustness guarantees against norm-bounded adversaries. However, the certified robustness behavior of Pixel Differential Privacy (PixelDP) remains largely unexplored with the self-attention architecture now dominating the deep-learning landscape. Given that the Transformer has a profound impact on our daily applications from the digital world to the physical world, it is crucial to study certified robustness through differential-privacy-style stability. To fill this research gap, we revisit this construction in Vision Transformers and identify a failure mode that is largely hidden in the convolutional setting. When noise is injected after the patch