| Category |
Method |
Off-the-shelf
|
Certified Accuracy at (%) |
| 0.25 |
0.50 |
0.75 |
1.00 |
1.25 |
1.50 |
| RS |
PixelDP (Lecuyer et al., 2019)
|
|
|
|
- |
- |
- |
- |
| Gaussian (Cohen et al., 2019)
|
|
|
|
|
|
|
|
| SmoothAdv (Salman et al., 2019)
|
|
|
|
|
|
|
|
| Consistency (Jeong & Shin, 2020)
|
|
|
|
|
|
|
|
| MACER (Zhai et al., 2020)
|
|
|
|
|
|
|
|
| Boosting (Horváth et al., 2022a)
|
|
|
|
|
|
|
|
| DRT (Yang et al., 2022)
|
|
|
|
|
|
|
|
| SmoothMix (Jeong et al., 2021)
|
|
|
|
|
|
|
|
| ACES (Horváth et al., 2022b)
|
|
|
|
|
|
|
|
| CAT-RS (Jeong et al., 2023)
|
|
|
|
|
|
|
|
| DS |
Denoised
(Salman et al., 2020)
|
|
|
|
|
|
|
|
| Score-based Denoised (Lee, 2021)
|
|
|
|
|
|
|
|
| Diffusion Denoised† (Carlini et al., 2023)
|
|
|
|
|
|
- |
- |
| Diffusion Denoised† (Carlini et al., 2023)
|
|
|
|
|
|
- |
- |
| Multi-scale Denoised† (Jeong & Shin, 2024)
|
|
- |
|
- |
|
- |
|
| FT-CADIS (Ours)† |
|
|
|
|
|
|
|