Class A region Class B region Input point x₀
drag to pan · scroll to zoom

Certified Robustness via Randomized Smoothing (2D)

Most adversarial-defense visualizations show an attack breaking a model. This one shows the opposite: a mathematical guarantee that no attack below a certain size can succeed. The top-down view renders a wavy binary decision boundary, plants an input point on it, and surrounds that point with a cloud of Gaussian-noise samples whose votes build the Cohen et al. (2019) randomized-smoothing certificate — a certified radius R = σ·Φ⁻¹(p_A) inside which the prediction is provably stable. The lower panel plots that same formula as a curve so you can see exactly how p_A maps to R. Tune the noise level, sample count and boundary curvature to watch the certified ball grow and shrink, then drag the attack-perturbation slider to see whether a given adversarial step falls safely inside it or breaches it. Drag the main view to pan, scroll to zoom.