Black-box Certification and Learning under Adversarial Perturbations
Hassan Ashtiani, Vinayak Pathak, Ruth Urner
摘要
We formally study the problem of classification under adversarial perturbations, both from the learner's perspective, and from the viewpoint of a third-party who aims at certifying the robustness of a given black-box classifier. We analyze a PAC-type framework of semi-supervised learning and identify possibility and impossibility results for proper learning of VC-classes in this setting. We further introduce and study a new setting of black-box certification under limited query budget. We analyze this for various classes of predictors and types of perturbation. We also consider the viewpoint of a black-box adversary that aims at finding adversarial examples, showing that the existence of an adversary with polynomial query complexity implies the existence of a robust learner with small sample complexity.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Cross-Entropy Loss Functions: Theoretical Analysis and ApplicationsAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2023 · 被引用 790 次
- A Characterization of Semi-Supervised Adversarially Robust PAC LearnabilityIdan Attias, Steve Hanneke, Yishay MansourNeurIPS 2022 · 被引用 19 次
- Query Complexity of Adversarial AttacksGrzegorz Gluch, Rüdiger L. UrbankeICML 2021 · 被引用 9 次
- Adversarially Robust PAC Learnability of Real-Valued FunctionsIdan Attias, Steve HannekeICML 2023 · 被引用 8 次
- Sample Complexity of Robust Linear Classification on Separated DataRobi Bhattacharjee, Somesh Jha, Kamalika ChaudhuriICML 2021 · 被引用 6 次
它引用的顶会 Paper1
相关 Paper
- Reducing Adversarially Robust Learning to Non-Robust PAC LearningOmar Montasser, Steve Hanneke, Nati SrebroNeurIPS 2020 · 被引用 35 次
- On Proper Learnability between Average- and Worst-case RobustnessVinod Raman, Unique Subedi, Ambuj TewariNeurIPS 2023 · 被引用 5 次
- Adversarially Robust Learning with Uncertain Perturbation SetsTosca Lechner, Vinayak Pathak, Ruth UrnerNeurIPS 2023 · 被引用 3 次
- On the Learnability of Distribution Classes with Adaptive AdversariesTosca Lechner, Alex Bie, Gautam KamathICML 2025
- Fast Adversarial Robustness Certification of Nearest Prototype Classifiers for Arbitrary SeminormsSascha Saralajew, Lars Holdijk, Thomas VillmannNeurIPS 2020 · 被引用 27 次
