Distributional Robustness with IPMs and links to Regularization and GANs
Hisham Husain
Abstract
Robustness to adversarial attacks is an important concern due to the fragility of deep neural networks to small perturbations and has received an abundance of attention in recent years. Distributionally Robust Optimization (DRO), a particularly promising way of addressing this challenge, studies robustness via divergence-based uncertainty sets and has provided valuable insights into robustification strategies such as regularization. In the context of machine learning, the majority of existing results have chosen -divergences, Wasserstein distances and more recently, the Maximum Mean Discrepancy (MMD) to construct uncertainty sets. We extend this line of work for the purposes of understanding robustness via regularization by studying uncertainty sets constructed with Integral Probability Metrics (IPMs) - a large family of divergences including the MMD, Total Variation and Wasserstein distances. Our main result shows that DRO under any choice of IPM corresponds to a family of regularization penalties, which recover and improve upon existing results in the setting of MMD and Wasserstein distances. Due to the generality of our result, we show that other choices of IPMs correspond to other commonly used penalties in machine learning. Furthermore, we extend our results to shed light on adversarial generative modelling via -GANs, constituting the first study of distributional robustness for the -GAN objective. Our results unveil the inductive properties of the discriminator set with regards to robustness, allowing us to give positive comments for several penalty-based GAN methods such as Wasserstein-, MMD- and Sobolev-GANs. In summary, our results intimately link GANs to distributional robustness, extend previous results on DRO and contribute to our understanding of the link between regularization and robustness at large.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b751a9e-014d-4378-86c8-5f6ab70413aeCited by top-tier papers11
- Examining and Combating Spurious Features under Distribution ShiftChunting Zhou, Xuezhe Ma, Paul Michel, Graham NeubigICML 2021 · 78 citations
- Modeling the Second Player in Distributionally Robust OptimizationPaul Michel, Tatsunori Hashimoto, Graham NeubigICLR 2021 · 39 citations
- Distributionally Robust Bayesian Optimization with φ-divergencesHisham Husain, Vu Nguyen, Anton van den HengelNeurIPS 2023 · 26 citations
- Generalization Bounds for (Wasserstein) Robust OptimizationYang An, Rui GaoNeurIPS 2021 · 22 citations
- Distributionally Robust Models with Parametric Likelihood RatiosPaul Michel, Tatsunori Hashimoto, Graham NeubigICLR 2022 · 21 citations
Builds on2
- A Framework for robustness Certification of Smoothed Classifiers using F-DivergencesKrishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, J. Zico Kolter et al.ICLR 2020 · 74 citations
- Generalised Lipschitz Regularisation Equals Distributional RobustnessZac Cranko, Zhan Shi, Xinhua Zhang, Richard Nock et al.ICML 2021 · 26 citations
Related papers
- Certified Adversarial Robustness Under the Bounded Support SetYiwen Kou, Qinyuan Zheng, Yisen WangICML 2022 · 3 citations
- Function-space regularized Rényi divergencesJeremiah Birrell, Yannis Pantazis, Paul Dupuis, Luc Rey-Bellet et al.ICLR 2023 · 1 citation
- Provable Robust Overfitting Mitigation in Wasserstein Distributionally Robust OptimizationShuang Liu, Yihan Wang, Yifan Zhu, Yibo Miao et al.ICLR 2025
- Wasserstein distributional robustness of neural networksXingjian Bai, Guangyi He, Yifan Jiang, Jan OblójNeurIPS 2023 · 20 citations
- Generalization Bounds with Minimal Dependency on Hypothesis Class via Distributionally Robust OptimizationYibo Zeng, Henry LamNeurIPS 2022 · 11 citations
