Consistent Non-Parametric Methods for Maximizing Robustness
Robi Bhattacharjee, Kamalika Chaudhuri
Abstract
Learning classifiers that are robust to adversarial examples has received a great deal of recent attention. A major drawback of the standard robust learning framework is there is an artificial robustness radius that applies to all inputs. This ignores the fact that data may be highly heterogeneous, in which case it is plausible that robustness regions should be larger in some regions of data, and smaller in others. In this paper, we address this limitation by proposing a new limit classifier, called the neighborhood optimal classifier, that extends the Bayes optimal classifier outside its support by using the label of the closest in-support point. We then argue that this classifier maximizes the size of its robustness regions subject to the constraint of having accuracy equal to the Bayes optimal. We then present sufficient conditions under which general non-parametric methods that can be represented as weight functions converge towards this limit, and show that both nearest neighbors and kernel classifiers satisfy them under certain conditions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2c2362ce-54d3-49e3-93ca-4468d2e18342Cited by top-tier papers4
- Probabilistically Robust Learning: Balancing Average and Worst-case PerformanceAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed HassaniICML 2022 · 50 citations
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 9 citations
- Adversarially Robust Learning with Uncertain Perturbation SetsTosca Lechner, Vinayak Pathak, Ruth UrnerNeurIPS 2023 · 3 citations
- Adversarial Attack and Defense for Non-Parametric Two-Sample TestsXilie Xu, Jingfeng Zhang, Feng Liu, Masashi Sugiyama et al.ICML 2022 · 2 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- MMA Training: Direct Input Space Margin Maximization through Adversarial TrainingGavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, Ruitong HuangICLR 2020 · 308 citations
- When are Non-Parametric Methods Robust?Robi Bhattacharjee, Kamalika ChaudhuriICML 2020 · 28 citations
Related papers
- On the Existence of The Adversarial Bayes ClassifierPranjal Awasthi, Natalie Frank, Mehryar MohriNeurIPS 2021 · 29 citations
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 6 citations
- Bayes-optimal Learning of Deep Random Networks of Extensive-widthHugo Cui, Florent Krzakala, Lenka ZdeborováICML 2023 · 49 citations
- A Two-Stage Active Learning Algorithm for k-Nearest NeighborsNicholas Rittler, Kamalika ChaudhuriICML 2023 · 3 citations
- Consistent Adversarially Robust Linear Classification: Non-Parametric SettingElvis DohmatobICML 2024 · 2 citations
