Black-box Certification and Learning under Adversarial Perturbations
Hassan Ashtiani, Vinayak Pathak, Ruth Urner
Abstract
We formally study the problem of classification under adversarial perturbations, both from the learner's perspective, and from the viewpoint of a third-party who aims at certifying the robustness of a given black-box classifier. We analyze a PAC-type framework of semi-supervised learning and identify possibility and impossibility results for proper learning of VC-classes in this setting. We further introduce and study a new setting of black-box certification under limited query budget. We analyze this for various classes of predictors and types of perturbation. We also consider the viewpoint of a black-box adversary that aims at finding adversarial examples, showing that the existence of an adversary with polynomial query complexity implies the existence of a robust learner with small sample complexity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 974333f8-15d2-4d2a-85eb-7cac2d85333fCited by top-tier papers10
- Cross-Entropy Loss Functions: Theoretical Analysis and ApplicationsAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2023 · 790 citations
- A Characterization of Semi-Supervised Adversarially Robust PAC LearnabilityIdan Attias, Steve Hanneke, Yishay MansourNeurIPS 2022 · 19 citations
- Query Complexity of Adversarial AttacksGrzegorz Gluch, Rüdiger L. UrbankeICML 2021 · 9 citations
- Adversarially Robust PAC Learnability of Real-Valued FunctionsIdan Attias, Steve HannekeICML 2023 · 8 citations
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 6 citations
Builds on1
Related papers
- Reducing Adversarially Robust Learning to Non-Robust PAC LearningOmar Montasser, Steve Hanneke, Nati SrebroNeurIPS 2020 · 35 citations
- On Proper Learnability between Average- and Worst-case RobustnessVinod Raman, Unique Subedi, Ambuj TewariNeurIPS 2023 · 5 citations
- Adversarially Robust Learning with Uncertain Perturbation SetsTosca Lechner, Vinayak Pathak, Ruth UrnerNeurIPS 2023 · 3 citations
- On the Learnability of Distribution Classes with Adaptive AdversariesTosca Lechner, Alex Bie, Gautam KamathICML 2025
- Fast Adversarial Robustness Certification of Nearest Prototype Classifiers for Arbitrary SeminormsSascha Saralajew, Lars Holdijk, Thomas VillmannNeurIPS 2020 · 27 citations
