Beyond Perturbations: Learning Guarantees with Arbitrary Adversarial Test Examples
Shafi Goldwasser, Adam Tauman Kalai, Yael Kalai, Omar Montasser
Abstract
We present a transductive learning algorithm that takes as input training examples from a distribution and arbitrary (unlabeled) test examples, possibly chosen by an adversary. This is unlike prior work that assumes that test examples are small perturbations of . Our algorithm outputs a selective classifier, which abstains from predicting on some examples. By considering selective transductive learning, we give the first nontrivial guarantees for learning classes of bounded VC dimension with arbitrary train and test distributions---no prior guarantees were known even for simple classes of functions such as intervals on the line. In particular, for any function in a class of bounded VC dimension, we guarantee a low test error rate and a low rejection rate with respect to . Our algorithm is efficient given an Empirical Risk Minimizer (ERM) for . Our guarantees hold even for test examples chosen by an unbounded white-box adversary. We also give guarantees for generalization, agnostic, and unsupervised settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fabfe0cc-ced7-4e72-bfa4-1429e39a3b09Cited by top-tier papers19
- Is Out-of-Distribution Detection Learnable?Zhen Fang, Yixuan Li, Jie Lu, Jiahua Dong et al.NeurIPS 2022 · 188 citations
- Planting Undetectable Backdoors in Machine Learning Models : [Extended Abstract]Shafi Goldwasser, Michael P. Kim, Vinod Vaikuntanathan, Or ZamirFOCS 2022 · 40 citations
- Towards Evaluating the Robustness of Neural Networks Learned by TransductionJiefeng Chen, Xi Wu, Yang Guo, Yingyu Liang et al.ICLR 2022 · 19 citations
- Generalizing Importance Weighting to A Universal Solver for Distribution Shift ProblemsTongtong Fang, Nan Lu, Gang Niu, Masashi SugiyamaNeurIPS 2023 · 17 citations
- Tolerant Algorithms for Learning with Arbitrary Covariate ShiftSurbhi Goel, Abhishek Shetty, Konstantinos Stavropoulos, Arsen VasilyanNeurIPS 2024 · 17 citations
Builds on2
Related papers
- Towards optimally abstaining from prediction with OOD test examplesAdam Kalai, Varun KanadeNeurIPS 2021 · 1 citation
- Tradeoffs between Mistakes and ERM Oracle Calls in Online and Transductive Online LearningIdan Attias, Steve Hanneke, Arvind RamaswamiNeurIPS 2025 · 1 citation
- Adversarial Resilience in Sequential Prediction via AbstentionSurbhi Goel, Steve Hanneke, Shay Moran, Abhishek ShettyNeurIPS 2023 · 17 citations
- A Trichotomy for Transductive Online LearningSteve Hanneke, Shay Moran, Jonathan ShaferNeurIPS 2023 · 15 citations
- Transformation-Invariant Learning and Theoretical Guarantees for OOD GeneralizationOmar Montasser, Han Shao, Emmanuel AbbeNeurIPS 2024 · 7 citations
