Almost Tight L0-norm Certified Robustness of Top-k Predictions against Adversarial Perturbations
Top-$k$ predictions are used in many real-world applications such as machine learning as a service, recommender systems, and web searches. $\ell_0$-norm adversarial perturbation characterizes an attack that arbitrarily modifies some features of an input such that a classifier makes an incorrect pred…