Adversarial Risk via Optimal Transport and Optimal Couplings

Adversarial Risk via Optimal Transport and Optimal Couplings
复制标题

DOI:
10.1109/tit.2021.3100107
复制
发表时间:
2019-12
影响因子:
2.5
通讯作者:
Muni Sreenivas Pydi;Varun Jog
Muni Sreenivas Pydi;Varun Jog
中科院分区:
计算机科学2区
文献类型:
--
作者:
Muni Sreenivas Pydi;Varun Jog

文献摘要

被引文献

相似文献

现代机器学习算法在被恶意操纵的数据上表现不佳。对抗性风险量化了对抗性环境中分类器的错误;对抗性分类器将对抗性风险降至最低。在本文中,我们从最优运输的角度分析了对抗性风险和对抗性分类器。我们证明了具有0-1损失的二分类的最优对抗风险是由两类概率分布之间的最优运输成本决定的。对于正态分布、均匀分布和三角分布等单变量分布,我们提出了最优运输计划(概率耦合)。在这些环境下,我们还得到了最优的对抗性分类器。我们的分析导致了与算法无关的对抗性风险的基本限制,我们对几个真实世界的数据集进行了计算。在凸性和光滑性的假设下,我们将我们的结果推广到一般损失函数。
Modern machine learning algorithms perform poorly on adversarially manipulated data. Adversarial risk quantifies the error of classifiers in adversarial settings; adversarial classifiers minimize adversarial risk. In this paper, we analyze adversarial risk and adversarial classifiers from an optimal transport perspective. We show that the optimal adversarial risk for binary classification with 0–1 loss is determined by an optimal transport cost between the probability distributions of the two classes. We develop optimal transport plans (probabilistic couplings) for univariate distributions such as the normal, the uniform, and the triangular distribution. We also derive optimal adversarial classifiers in these settings. Our analysis leads to algorithm-independent fundamental limits on adversarial risk, which we calculate for several real-world datasets. We extend our results to general loss functions under convexity and smoothness assumptions.