Sharp Statistical Guarantees for Adversarially Robust Gaussian Classification

Sharp Statistical Guarantees for Adversarially Robust Gaussian Classification
复制标题

DOI:
--
复制
发表时间:
2020-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Chen Dan;Yuting Wei;Pradeep Ravikumar
Chen Dan;Yuting Wei;Pradeep Ravikumar
中科院分区:
其他
文献类型:
--
作者:
Chen Dan;Yuting Wei;Pradeep Ravikumar

文献摘要

相似文献

对抗鲁棒性已成为现代机器学习应用的基本要求。然而,迄今为止,人们对统计的了解却少之又少。在本文中,我们在 \cite{schmidt2018adversarily} 提出的高斯混合模型下,提供了对抗鲁棒分类的超额风险的最佳极小极大保证的第一个结果。结果以对抗性信噪比(AdvSNR)表示,它将标准线性分类的类似概念推广到对抗性设置。对于 AdvSNR 值为 $r$ 的高斯混合,我们建立 $\Theta(e^{-(\frac{1}{8}+o(1)) r^2} \frac{d}{n})$ 阶的超额风险下界,并设计一个计算高效的估计器来实现此最佳速率。我们的结果建立在最小的假设集上,同时涵盖了广泛的对抗性扰动,包括任何 $p \ge 1$ 的 $\ell_p$ 球。
Adversarial robustness has become a fundamental requirement in modern machine learning applications. Yet, there has been surprisingly little statistical understanding so far. In this paper, we provide the first result of the optimal minimax guarantees for the excess risk for adversarially robust classification, under Gaussian mixture model proposed by \cite{schmidt2018adversarially}. The results are stated in terms of the Adversarial Signal-to-Noise Ratio (AdvSNR), which generalizes a similar notion for standard linear classification to the adversarial setting. For the Gaussian mixtures with AdvSNR value of $r$, we establish an excess risk lower bound of order $\Theta(e^{-(\frac{1}{8}+o(1)) r^2} \frac{d}{n})$ and design a computationally efficient estimator that achieves this optimal rate. Our results built upon minimal set of assumptions while cover a wide spectrum of adversarial perturbations including $\ell_p$ balls for any $p \ge 1$.