Class A region Class B region Input point x₀
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Certified Robustness via Randomized Smoothing

Most adversarial-defense visualizations show an attack breaking a model. This one shows the opposite: a mathematical guarantee that no attack below a certain size can succeed. The scene renders a wavy binary decision surface in 3D, plants an input point on it, and surrounds that point with a cloud of Gaussian-noise samples whose votes build the Cohen et al. (2019) randomized-smoothing certificate — a certified radius R = σ·Φ⁻¹(p_A) inside which the prediction is provably stable. Tune the noise level, sample count and boundary curvature to watch the certified ball grow and shrink, then drag the attack-perturbation slider to see whether a given adversarial step falls safely inside it or breaches it.