Mixed Nash Equilibria in the Adversarial Examples Game
Laurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif, Yann Chevaleyre
Abstract
This paper tackles the problem of adversarial examples from a game theoretic point of view. We study the open question of the existence of mixed Nash equilibria in the zero-sum game formed by the attacker and the classifier. While previous works usually allow only one player to use randomized strategies, we show the necessity of considering randomization for both the classifier and the attacker. We demonstrate that this game has no duality gap, meaning that it always admits approximate Nash equilibria. We also provide the first optimization algorithms to learn a mixture of classifiers that approximately realizes the value of this game, i.e. procedures to build an optimally robust randomized classifier.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- The Many Faces of Adversarial RiskMuni Sreenivas Pydi, Varun S. JogNeurIPS 2021 · 33 citations
- Robustness between the worst and average caseLeslie Rice, Anna Bair, Huan Zhang, J. Zico KolterNeurIPS 2021 · 26 citations
- Towards Consistency in Adversarial ClassificationLaurent Meunier, Raphael Ettedgui, Rafael Pinot, Yann Chevaleyre et al.NeurIPS 2022 · 12 citations
- PubDef: Defending Against Transfer Attacks From Public ModelsChawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan et al.ICLR 2024 · 9 citations
- Adversarial Vulnerability of Randomized EnsemblesHassan Dbouk, Naresh R. ShanbhagICML 2022 · 8 citations
Builds on4
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre et al.ICML 2020 · 66 citations
- Adversarial Risk via Optimal Transport and Optimal CouplingsMuni Sreenivas Pydi, Varun S. JogICML 2020 · 60 citations
Related papers
- Towards Optimal Randomized Strategies in Adversarial Example GameJiahao Xie, Chao Zhang, Weijie Liu, Wensong Bai et al.AAAI 2023
- A Game Theoretic Analysis of Additive Adversarial Attacks and DefensesAmbar Pal, René VidalNeurIPS 2020 · 30 citations
- Strategic Classification With ExternalitiesSafwan Hossain, Evi Micha, Yiling Chen, Ariel D. ProcacciaICLR 2025
- A mean-field analysis of two-player zero-sum gamesCarles Domingo-Enrich, Samy Jelassi, Arthur Mensch, Grant M. Rotskoff et al.NeurIPS 2020 · 56 citations
- Characterizing the Optimal 0-1 Loss for Multi-class Classification with a Test-time AttackerSihui Dai, Wenxin Ding, Arjun Nitin Bhagoji, Daniel Cullina et al.NeurIPS 2023 · 6 citations
