Distributional Robustness with IPMs and links to Regularization and GANs
Hisham Husain
摘要
Robustness to adversarial attacks is an important concern due to the fragility of deep neural networks to small perturbations and has received an abundance of attention in recent years. Distributionally Robust Optimization (DRO), a particularly promising way of addressing this challenge, studies robustness via divergence-based uncertainty sets and has provided valuable insights into robustification strategies such as regularization. In the context of machine learning, the majority of existing results have chosen -divergences, Wasserstein distances and more recently, the Maximum Mean Discrepancy (MMD) to construct uncertainty sets. We extend this line of work for the purposes of understanding robustness via regularization by studying uncertainty sets constructed with Integral Probability Metrics (IPMs) - a large family of divergences including the MMD, Total Variation and Wasserstein distances. Our main result shows that DRO under any choice of IPM corresponds to a family of regularization penalties, which recover and improve upon existing results in the setting of MMD and Wasserstein distances. Due to the generality of our result, we show that other choices of IPMs correspond to other commonly used penalties in machine learning. Furthermore, we extend our results to shed light on adversarial generative modelling via -GANs, constituting the first study of distributional robustness for the -GAN objective. Our results unveil the inductive properties of the discriminator set with regards to robustness, allowing us to give positive comments for several penalty-based GAN methods such as Wasserstein-, MMD- and Sobolev-GANs. In summary, our results intimately link GANs to distributional robustness, extend previous results on DRO and contribute to our understanding of the link between regularization and robustness at large.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Examining and Combating Spurious Features under Distribution ShiftChunting Zhou, Xuezhe Ma, Paul Michel, Graham NeubigICML 2021 · 被引用 78 次
- Modeling the Second Player in Distributionally Robust OptimizationPaul Michel, Tatsunori Hashimoto, Graham NeubigICLR 2021 · 被引用 39 次
- Distributionally Robust Bayesian Optimization with φ-divergencesHisham Husain, Vu Nguyen, Anton van den HengelNeurIPS 2023 · 被引用 26 次
- Generalization Bounds for (Wasserstein) Robust OptimizationYang An, Rui GaoNeurIPS 2021 · 被引用 22 次
- Distributionally Robust Models with Parametric Likelihood RatiosPaul Michel, Tatsunori Hashimoto, Graham NeubigICLR 2022 · 被引用 21 次
它引用的顶会 Paper2
- A Framework for robustness Certification of Smoothed Classifiers using F-DivergencesKrishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, J. Zico Kolter 等ICLR 2020 · 被引用 74 次
- Generalised Lipschitz Regularisation Equals Distributional RobustnessZac Cranko, Zhan Shi, Xinhua Zhang, Richard Nock 等ICML 2021 · 被引用 26 次
相关 Paper
- Certified Adversarial Robustness Under the Bounded Support SetYiwen Kou, Qinyuan Zheng, Yisen WangICML 2022 · 被引用 3 次
- Function-space regularized Rényi divergencesJeremiah Birrell, Yannis Pantazis, Paul Dupuis, Luc Rey-Bellet 等ICLR 2023 · 被引用 1 次
- Provable Robust Overfitting Mitigation in Wasserstein Distributionally Robust OptimizationShuang Liu, Yihan Wang, Yifan Zhu, Yibo Miao 等ICLR 2025
- Wasserstein distributional robustness of neural networksXingjian Bai, Guangyi He, Yifan Jiang, Jan OblójNeurIPS 2023 · 被引用 20 次
- Generalization Bounds with Minimal Dependency on Hypothesis Class via Distributionally Robust OptimizationYibo Zeng, Henry LamNeurIPS 2022 · 被引用 11 次
