The Many Faces of Adversarial Risk
Muni Sreenivas Pydi, Varun S. Jog
Abstract
Adversarial risk quantifies the performance of classifiers on adversarially perturbed data. Numerous definitions of adversarial risk—not all mathematically rigorous and differing subtly in the details—have appeared in the literature. In this paper, we revisit these definitions, fix measure theoretic issues, and critically examine their similarities and differences. Our technical tools derive from optimal transport, robust statistics, functional analysis, and game theory. Our contributions include the following: generalizing Strassen’s theorem to the unbalanced optimal transport setting with applications to adversarial classification with unequal priors; showing an equivalence between adversarial robustness and robust hypothesis testing with <inline-formula> <tex-math notation="LaTeX"> </tex-math></inline-formula>-Wasserstein uncertainty sets; proving the existence of a pure Nash equilibrium in the two-player game between the adversary and the algorithm; and characterizing adversarial risk by the minimum Bayes error between a pair of distributions belonging to the <inline-formula> <tex-math notation="LaTeX"> </tex-math></inline-formula>-Wasserstein uncertainty sets. Our results generalize and deepen recently discovered connections between optimal transport and adversarial robustness and reveal new connections to Choquet capacities and game theory.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ef1aaa73-b722-4544-a644-882017ab5286Cited by top-tier papers4
- Towards Consistency in Adversarial ClassificationLaurent Meunier, Raphael Ettedgui, Rafael Pinot, Yann Chevaleyre et al.NeurIPS 2022 · 12 citations
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 9 citations
- Characterizing the Optimal 0-1 Loss for Multi-class Classification with a Test-time AttackerSihui Dai, Wenxin Ding, Arjun Nitin Bhagoji, Daniel Cullina et al.NeurIPS 2023 · 6 citations
- When are Local Queries Useful for Robust Learning?Pascale Gourdeau, Varun Kanade, Marta Kwiatkowska, James WorrellNeurIPS 2022 · 1 citation
Builds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre et al.ICML 2020 · 66 citations
- Adversarial Risk via Optimal Transport and Optimal CouplingsMuni Sreenivas Pydi, Varun S. JogICML 2020 · 60 citations
- Mixed Nash Equilibria in the Adversarial Examples GameLaurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif et al.ICML 2021 · 32 citations
Related papers
- Provable Robust Overfitting Mitigation in Wasserstein Distributionally Robust OptimizationShuang Liu, Yihan Wang, Yifan Zhu, Yibo Miao et al.ICLR 2025
- Fundamental Tradeoffs in Distributionally Adversarial TrainingMohammad Mehrabi, Adel Javanmard, Ryan A. Rossi, Anup B. Rao et al.ICML 2021 · 19 citations
- Achieving Robustness in Classification Using Optimal Transport With Hinge RegularizationMathieu Serrurier, Franck Mamalet, Alberto González-Sanz, Thibaut Boissin et al.CVPR 2021
- Generalised Lipschitz Regularisation Equals Distributional RobustnessZac Cranko, Zhan Shi, Xinhua Zhang, Richard Nock et al.ICML 2021 · 26 citations
- On the Role of Randomization in Adversarially Robust ClassificationLucas Gnecco Heredia, Muni Sreenivas Pydi, Laurent Meunier, Benjamin Négrevergne et al.NeurIPS 2023 · 7 citations
