Adversarial Risk via Optimal Transport and Optimal Couplings
Muni Sreenivas Pydi, Varun S. Jog
摘要
Modern machine learning algorithms perform poorly on adversarially manipulated data. Adversarial risk quantifies the error of classifiers in adversarial settings; adversarial classifiers minimize adversarial risk. In this paper, we analyze adversarial risk and adversarial classifiers from an optimal transport perspective. We show that the optimal adversarial risk for binary classification with 0-1 loss is determined by an optimal transport cost between the probability distributions of the two classes. We develop optimal transport plans (probabilistic couplings) for univariate distributions such as the normal, the uniform, and the triangular distribution. We also derive optimal adversarial classifiers in these settings. Our analysis leads to algorithmindependent fundamental limits on adversarial risk, which we calculate for several real-world datasets. We extend our results to general loss functions under convexity and smoothness assumptions. 1
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov 等NeurIPS 2020 · 被引用 336 次
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 等ICML 2020 · 被引用 66 次
- The Many Faces of Adversarial RiskMuni Sreenivas Pydi, Varun S. JogNeurIPS 2021 · 被引用 33 次
- Mixed Nash Equilibria in the Adversarial Examples GameLaurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif 等ICML 2021 · 被引用 32 次
- On the Existence of The Adversarial Bayes ClassifierPranjal Awasthi, Natalie Frank, Mehryar MohriNeurIPS 2021 · 被引用 29 次
它引用的顶会 Paper5
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov 等NeurIPS 2020 · 被引用 336 次
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 等ICML 2020 · 被引用 66 次
- When are Non-Parametric Methods Robust?Robi Bhattacharjee, Kamalika ChaudhuriICML 2020 · 被引用 28 次
- Minimax Classification with 0-1 Loss and Performance GuaranteesSantiago Mazuelas, Andrea Zanoni, Aritz PérezNeurIPS 2020 · 被引用 18 次
相关 Paper
- Fundamental Tradeoffs in Distributionally Adversarial TrainingMohammad Mehrabi, Adel Javanmard, Ryan A. Rossi, Anup B. Rao 等ICML 2021 · 被引用 19 次
- Achieving Robustness in Classification Using Optimal Transport With Hinge RegularizationMathieu Serrurier, Franck Mamalet, Alberto González-Sanz, Thibaut Boissin 等CVPR 2021
- Margin-aware Adversarial Domain Adaptation with Optimal TransportSofien Dhouib, Ievgen Redko, Carole LartizienICML 2020 · 被引用 17 次
- Analyzing and Improving Optimal-Transport-based Adversarial NetworksJaemoo Choi, Jaewoong Choi, Myungjoo KangICLR 2024 · 被引用 7 次
- Optimal Transport of Classifiers to FairnessMaarten Buyl, Tijl De BieNeurIPS 2022 · 被引用 16 次
