Mixed Nash Equilibria in the Adversarial Examples Game
Laurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif, Yann Chevaleyre
摘要
This paper tackles the problem of adversarial examples from a game theoretic point of view. We study the open question of the existence of mixed Nash equilibria in the zero-sum game formed by the attacker and the classifier. While previous works usually allow only one player to use randomized strategies, we show the necessity of considering randomization for both the classifier and the attacker. We demonstrate that this game has no duality gap, meaning that it always admits approximate Nash equilibria. We also provide the first optimization algorithms to learn a mixture of classifiers that approximately realizes the value of this game, i.e. procedures to build an optimally robust randomized classifier.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- The Many Faces of Adversarial RiskMuni Sreenivas Pydi, Varun S. JogNeurIPS 2021 · 被引用 33 次
- Robustness between the worst and average caseLeslie Rice, Anna Bair, Huan Zhang, J. Zico KolterNeurIPS 2021 · 被引用 26 次
- Towards Consistency in Adversarial ClassificationLaurent Meunier, Raphael Ettedgui, Rafael Pinot, Yann Chevaleyre 等NeurIPS 2022 · 被引用 12 次
- PubDef: Defending Against Transfer Attacks From Public ModelsChawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan 等ICLR 2024 · 被引用 9 次
- Adversarial Vulnerability of Randomized EnsemblesHassan Dbouk, Naresh R. ShanbhagICML 2022 · 被引用 8 次
它引用的顶会 Paper4
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 等ICML 2020 · 被引用 66 次
- Adversarial Risk via Optimal Transport and Optimal CouplingsMuni Sreenivas Pydi, Varun S. JogICML 2020 · 被引用 60 次
相关 Paper
- Towards Optimal Randomized Strategies in Adversarial Example GameJiahao Xie, Chao Zhang, Weijie Liu, Wensong Bai 等AAAI 2023
- A Game Theoretic Analysis of Additive Adversarial Attacks and DefensesAmbar Pal, René VidalNeurIPS 2020 · 被引用 30 次
- Strategic Classification With ExternalitiesSafwan Hossain, Evi Micha, Yiling Chen, Ariel D. ProcacciaICLR 2025
- A mean-field analysis of two-player zero-sum gamesCarles Domingo-Enrich, Samy Jelassi, Arthur Mensch, Grant M. Rotskoff 等NeurIPS 2020 · 被引用 56 次
- Characterizing the Optimal 0-1 Loss for Multi-class Classification with a Test-time AttackerSihui Dai, Wenxin Ding, Arjun Nitin Bhagoji, Daniel Cullina 等NeurIPS 2023 · 被引用 6 次
