Adversarial Risk via Optimal Transport and Optimal Couplings
Muni Sreenivas Pydi, Varun S. Jog
Abstract
Modern machine learning algorithms perform poorly on adversarially manipulated data. Adversarial risk quantifies the error of classifiers in adversarial settings; adversarial classifiers minimize adversarial risk. In this paper, we analyze adversarial risk and adversarial classifiers from an optimal transport perspective. We show that the optimal adversarial risk for binary classification with 0-1 loss is determined by an optimal transport cost between the probability distributions of the two classes. We develop optimal transport plans (probabilistic couplings) for univariate distributions such as the normal, the uniform, and the triangular distribution. We also derive optimal adversarial classifiers in these settings. Our analysis leads to algorithmindependent fundamental limits on adversarial risk, which we calculate for several real-world datasets. We extend our results to general loss functions under convexity and smoothness assumptions. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e1acf2c1-5c8f-41c1-9a5c-d8afab9f5981Cited by top-tier papers11
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov et al.NeurIPS 2020 · 336 citations
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre et al.ICML 2020 · 66 citations
- The Many Faces of Adversarial RiskMuni Sreenivas Pydi, Varun S. JogNeurIPS 2021 · 33 citations
- Mixed Nash Equilibria in the Adversarial Examples GameLaurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif et al.ICML 2021 · 32 citations
- On the Existence of The Adversarial Bayes ClassifierPranjal Awasthi, Natalie Frank, Mehryar MohriNeurIPS 2021 · 29 citations
Builds on5
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov et al.NeurIPS 2020 · 336 citations
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre et al.ICML 2020 · 66 citations
- When are Non-Parametric Methods Robust?Robi Bhattacharjee, Kamalika ChaudhuriICML 2020 · 28 citations
- Minimax Classification with 0-1 Loss and Performance GuaranteesSantiago Mazuelas, Andrea Zanoni, Aritz PérezNeurIPS 2020 · 18 citations
Related papers
- Fundamental Tradeoffs in Distributionally Adversarial TrainingMohammad Mehrabi, Adel Javanmard, Ryan A. Rossi, Anup B. Rao et al.ICML 2021 · 19 citations
- Achieving Robustness in Classification Using Optimal Transport With Hinge RegularizationMathieu Serrurier, Franck Mamalet, Alberto González-Sanz, Thibaut Boissin et al.CVPR 2021
- Margin-aware Adversarial Domain Adaptation with Optimal TransportSofien Dhouib, Ievgen Redko, Carole LartizienICML 2020 · 17 citations
- Analyzing and Improving Optimal-Transport-based Adversarial NetworksJaemoo Choi, Jaewoong Choi, Myungjoo KangICLR 2024 · 7 citations
- Optimal Transport of Classifiers to FairnessMaarten Buyl, Tijl De BieNeurIPS 2022 · 16 citations
