When are Non-Parametric Methods Robust?
Robi Bhattacharjee, Kamalika Chaudhuri
Abstract
A growing body of research has shown that many classifiers are susceptible to adversarial examples -- small strategic modifications to test inputs that lead to misclassification. In this work, we study general non-parametric methods, with a view towards understanding when they are robust to these modifications. We establish general conditions under which non-parametric methods are r-consistent -- in the sense that they converge to optimally robust and accurate classifiers in the large sample limit. Concretely, our results show that when data is well-separated, nearest neighbors and kernel classifiers are r-consistent, while histograms are not. For general data distributions, we prove that preprocessing by Adversarial Pruning (Yang et. al., 2019) -- that makes data well-separated -- followed by nearest neighbors or kernel classifiers also leads to r-consistency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 320d01ab-4938-4690-834e-107ad77bbb7cCited by top-tier papers9
- Adversarial Risk via Optimal Transport and Optimal CouplingsMuni Sreenivas Pydi, Varun S. JogICML 2020 · 60 citations
- Distributionally Robust Local Non-parametric Conditional EstimationViet Anh Nguyen, Fan Zhang, José H. Blanchet, Erick Delage et al.NeurIPS 2020 · 28 citations
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 9 citations
- Consistent Non-Parametric Methods for Maximizing RobustnessRobi Bhattacharjee, Kamalika ChaudhuriNeurIPS 2021 · 8 citations
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 6 citations
Builds on2
Related papers
- Consistent Adversarially Robust Linear Classification: Non-Parametric SettingElvis DohmatobICML 2024 · 2 citations
- On the Error Resistance of Hinge-Loss MinimizationKunal TalwarNeurIPS 2020 · 7 citations
- Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessAmbar Pal, Jeremias Sulam, René VidalNeurIPS 2023 · 15 citations
- Robust Unsupervised Learning via L-statistic MinimizationAndreas Maurer, Daniela Angela Parletta, Andrea Paudice, Massimiliano PontilICML 2021 · 9 citations
- Exact Robustness Certification of k-Nearest NeighborsFrancesco Ranzato, Ahmad Shakeel, Marco ZanellaCCS 2025
