When are Non-Parametric Methods Robust?
Robi Bhattacharjee, Kamalika Chaudhuri
摘要
A growing body of research has shown that many classifiers are susceptible to adversarial examples -- small strategic modifications to test inputs that lead to misclassification. In this work, we study general non-parametric methods, with a view towards understanding when they are robust to these modifications. We establish general conditions under which non-parametric methods are r-consistent -- in the sense that they converge to optimally robust and accurate classifiers in the large sample limit. Concretely, our results show that when data is well-separated, nearest neighbors and kernel classifiers are r-consistent, while histograms are not. For general data distributions, we prove that preprocessing by Adversarial Pruning (Yang et. al., 2019) -- that makes data well-separated -- followed by nearest neighbors or kernel classifiers also leads to r-consistency.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Adversarial Risk via Optimal Transport and Optimal CouplingsMuni Sreenivas Pydi, Varun S. JogICML 2020 · 被引用 60 次
- Distributionally Robust Local Non-parametric Conditional EstimationViet Anh Nguyen, Fan Zhang, José H. Blanchet, Erick Delage 等NeurIPS 2020 · 被引用 28 次
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 被引用 9 次
- Consistent Non-Parametric Methods for Maximizing RobustnessRobi Bhattacharjee, Kamalika ChaudhuriNeurIPS 2021 · 被引用 8 次
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 被引用 6 次
它引用的顶会 Paper2
相关 Paper
- Consistent Adversarially Robust Linear Classification: Non-Parametric SettingElvis DohmatobICML 2024 · 被引用 2 次
- On the Error Resistance of Hinge-Loss MinimizationKunal TalwarNeurIPS 2020 · 被引用 7 次
- Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessAmbar Pal, Jeremias Sulam, René VidalNeurIPS 2023 · 被引用 15 次
- Robust Unsupervised Learning via L-statistic MinimizationAndreas Maurer, Daniela Angela Parletta, Andrea Paudice, Massimiliano PontilICML 2021 · 被引用 9 次
- Exact Robustness Certification of k-Nearest NeighborsFrancesco Ranzato, Ahmad Shakeel, Marco ZanellaCCS 2025
