Consistent Adversarially Robust Linear Classification: Non-Parametric Setting
Elvis Dohmatob
Abstract
For binary classification in d dimensions, it is known that with a sample size of n, an excess adversarial risk of O(d/n) is achievable under strong parametric assumptions about the underlying data distribution (e.g., assuming a Gaussian mixture model). In the case of well-separated distributions, this rate can be further refined to O(1/n). Our work studies the non-parametric setting, where very little is known. With only mild regularity conditions on the conditional distribution of the features, we examine adversarial attacks with respect to arbitrary norms and introduce a straightforward yet effective estimator with provable consistency w.r.t adversarial risk. Our estimator is given by minimizing a series of smoothed versions of the robust 0/1 loss, with a smoothing bandwidth that adapts to both n and d. Furthermore, we demonstrate that our estimator can achieve the minimax excess adversarial risk of O( d/n) for linear classifiers, at the cost of solving possibly rougher optimization problems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Adversarial Robustness of Nonparametric RegressionParsa Moradi, Hanzaleh Akbarinodehi, Mohammad Ali Maddah-AliNeurIPS 2025 · 1 citation
- On the existence of consistent adversarial attacks in high-dimensional linear classificationMatteo Vilucchio, Lenka Zdeborova, Bruno LoureiroICML 2026 · 1 citation
Builds on5
- Are aligned neural networks adversarially aligned?Nicholas Carlini, Milad Nasr, Christopher A. Choquette-Choo, Matthew Jagielski et al.NeurIPS 2023 · 412 citations
- Calibration and Consistency of Adversarial Surrogate LossesPranjal Awasthi, Natalie Frank, Anqi Mao, Mehryar Mohri et al.NeurIPS 2021 · 59 citations
- When are Non-Parametric Methods Robust?Robi Bhattacharjee, Kamalika ChaudhuriICML 2020 · 28 citations
- Sharp Statistical Guaratees for Adversarially Robust Gaussian ClassificationChen Dan, Yuting Wei, Pradeep RavikumarICML 2020 · 18 citations
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 6 citations
Related papers
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 9 citations
- Robust Nonparametric Regression under Poisoning AttackPuning Zhao, Zhiguo WanAAAI 2024 · 13 citations
- Gradient Flow Provably Learns Robust Classifiers for Orthonormal GMMsHancheng Min, René VidalICML 2025
- Benign Overfitting in Adversarial Training of Neural NetworksYunjuan Wang, Kaibo Zhang, Raman AroraICML 2024 · 3 citations
- Black-Box Certification with Randomized Smoothing: A Functional Optimization Based FrameworkDinghuai Zhang, Mao Ye, Chengyue Gong, Zhanxing Zhu et al.NeurIPS 2020 · 71 citations
