The geometry of adversarial training in binary classification

The geometry of adversarial training in binary classification
复制标题

二元分类中对抗训练的几何

DOI:
10.1093/imaiai/iaac029
复制
发表时间:
2023
期刊:
Information and Inference: A Journal of the IMA
影响因子:
--
通讯作者:
Murray, Ryan
Murray, Ryan
中科院分区:
--
文献类型:
--
作者:
Bungert, Leon;García Trillos, Nicolás;Murray, Ryan

文献摘要

相似文献

我们建立了一个非参数二进制分类的对抗训练问题的家庭和一个家庭的正则化风险最小化问题,其中正则化是一个非局部周边功能之间的等价性。由此产生的正则化风险最小化问题承认精确的凸松弛的类型,经常在图像分析和基于图形的学习研究的形式。一个丰富的几何结构,揭示了这个重新制定,这反过来又使我们能够建立一系列的性质,最佳解决方案的原始问题,包括存在的最小和最大的解决方案(解释在一个合适的意义上)和存在的正规解决方案(也解释在一个合适的意义上)。此外,我们强调了对抗训练和周长最小化问题之间的联系如何为涉及周长/总变差的正则化风险最小化问题家族提供了一种新颖的、可直接解释的统计动机。我们的大多数理论结果与用于定义对抗性攻击的距离无关。
We establish an equivalence between a family of adversarial training problems for non-parametric binary classification and a family of regularized risk minimization problems where the regularizer is a nonlocal perimeter functional. The resulting regularized risk minimization problems admit exact convex relaxations of the type, a form frequently studied in image analysis and graph-based learning. A rich geometric structure is revealed by this reformulation which in turn allows us to establish a series of properties of optimal solutions of the original problem, including the existence of minimal and maximal solutions (interpreted in a suitable sense) and the existence of regular solutions (also interpreted in a suitable sense). In addition, we highlight how the connection between adversarial training and perimeter minimization problems provides a novel, directly interpretable, statistical motivation for a family of regularized risk minimization problems involving perimeter/total variation. The majority of our theoretical results are independent of the distance used to define adversarial attacks.