The Many Faces of Adversarial Risk
Muni Sreenivas Pydi, Varun S. Jog
摘要
Adversarial risk quantifies the performance of classifiers on adversarially perturbed data. Numerous definitions of adversarial risk—not all mathematically rigorous and differing subtly in the details—have appeared in the literature. In this paper, we revisit these definitions, fix measure theoretic issues, and critically examine their similarities and differences. Our technical tools derive from optimal transport, robust statistics, functional analysis, and game theory. Our contributions include the following: generalizing Strassen’s theorem to the unbalanced optimal transport setting with applications to adversarial classification with unequal priors; showing an equivalence between adversarial robustness and robust hypothesis testing with <inline-formula> <tex-math notation="LaTeX"> </tex-math></inline-formula>-Wasserstein uncertainty sets; proving the existence of a pure Nash equilibrium in the two-player game between the adversary and the algorithm; and characterizing adversarial risk by the minimum Bayes error between a pair of distributions belonging to the <inline-formula> <tex-math notation="LaTeX"> </tex-math></inline-formula>-Wasserstein uncertainty sets. Our results generalize and deepen recently discovered connections between optimal transport and adversarial robustness and reveal new connections to Choquet capacities and game theory.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Towards Consistency in Adversarial ClassificationLaurent Meunier, Raphael Ettedgui, Rafael Pinot, Yann Chevaleyre 等NeurIPS 2022 · 被引用 12 次
- The Adversarial Consistency of Surrogate Risks for Binary ClassificationNatalie Frank, Jonathan Niles-WeedNeurIPS 2023 · 被引用 9 次
- Characterizing the Optimal 0-1 Loss for Multi-class Classification with a Test-time AttackerSihui Dai, Wenxin Ding, Arjun Nitin Bhagoji, Daniel Cullina 等NeurIPS 2023 · 被引用 6 次
- When are Local Queries Useful for Robust Learning?Pascale Gourdeau, Varun Kanade, Marta Kwiatkowska, James WorrellNeurIPS 2022 · 被引用 1 次
它引用的顶会 Paper5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre 等ICML 2020 · 被引用 66 次
- Adversarial Risk via Optimal Transport and Optimal CouplingsMuni Sreenivas Pydi, Varun S. JogICML 2020 · 被引用 60 次
- Mixed Nash Equilibria in the Adversarial Examples GameLaurent Meunier, Meyer Scetbon, Rafael Pinot, Jamal Atif 等ICML 2021 · 被引用 32 次
相关 Paper
- Provable Robust Overfitting Mitigation in Wasserstein Distributionally Robust OptimizationShuang Liu, Yihan Wang, Yifan Zhu, Yibo Miao 等ICLR 2025
- Fundamental Tradeoffs in Distributionally Adversarial TrainingMohammad Mehrabi, Adel Javanmard, Ryan A. Rossi, Anup B. Rao 等ICML 2021 · 被引用 19 次
- Achieving Robustness in Classification Using Optimal Transport With Hinge RegularizationMathieu Serrurier, Franck Mamalet, Alberto González-Sanz, Thibaut Boissin 等CVPR 2021
- Generalised Lipschitz Regularisation Equals Distributional RobustnessZac Cranko, Zhan Shi, Xinhua Zhang, Richard Nock 等ICML 2021 · 被引用 26 次
- On the Role of Randomization in Adversarially Robust ClassificationLucas Gnecco Heredia, Muni Sreenivas Pydi, Laurent Meunier, Benjamin Négrevergne 等NeurIPS 2023 · 被引用 7 次
