Consistent Non-Parametric Methods for Maximizing Robustness
Robi Bhattacharjee, Kamalika Chaudhuri
摘要
Learning classifiers that are robust to adversarial examples has received a great deal of recent attention. A major drawback of the standard robust learning framework is there is an artificial robustness radius that applies to all inputs. This ignores the fact that data may be highly heterogeneous, in which case it is plausible that robustness regions should be larger in some regions of data, and smaller in others. In this paper, we address this limitation by proposing a new limit classifier, called the neighborhood optimal classifier, that extends the Bayes optimal classifier outside its support by using the label of the closest in-support point. We then argue that this classifier maximizes the size of its robustness regions subject to the constraint of having accuracy equal to the Bayes optimal. We then present sufficient conditions under which general non-parametric methods that can be represented as weight functions converge towards this limit, and show that both nearest neighbors and kernel classifiers satisfy them under certain conditions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Probabilistically Robust Learning: Balancing Average and Worst-case PerformanceAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed HassaniICML 2022 · 被引用 50 次
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 被引用 9 次
- Adversarially Robust Learning with Uncertain Perturbation SetsTosca Lechner, Vinayak Pathak, Ruth UrnerNeurIPS 2023 · 被引用 3 次
- Adversarial Attack and Defense for Non-Parametric Two-Sample TestsXilie Xu, Jingfeng Zhang, Feng Liu, Masashi Sugiyama 等ICML 2022 · 被引用 2 次
它引用的顶会 Paper4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- MMA Training: Direct Input Space Margin Maximization through Adversarial TrainingGavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, Ruitong HuangICLR 2020 · 被引用 308 次
- When are Non-Parametric Methods Robust?Robi Bhattacharjee, Kamalika ChaudhuriICML 2020 · 被引用 28 次
相关 Paper
- On the Existence of The Adversarial Bayes ClassifierPranjal Awasthi, Natalie Frank, Mehryar MohriNeurIPS 2021 · 被引用 29 次
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 被引用 6 次
- Bayes-optimal Learning of Deep Random Networks of Extensive-widthHugo Cui, Florent Krzakala, Lenka ZdeborováICML 2023 · 被引用 49 次
- A Two-Stage Active Learning Algorithm for k-Nearest NeighborsNicholas Rittler, Kamalika ChaudhuriICML 2023 · 被引用 3 次
- Consistent Adversarially Robust Linear Classification: Non-Parametric SettingElvis DohmatobICML 2024 · 被引用 2 次
