On the Adversarial Robustness of Hypothesis Testing

On the Adversarial Robustness of Hypothesis Testing
复制标题

DOI:
10.1109/tsp.2020.3045206
复制
发表时间:
2021
影响因子:
5.4
通讯作者:
Yulu Jin;L. Lai
Yulu Jin;L. Lai
中科院分区:
工程技术1区
文献类型:
--
作者:
Yulu Jin;L. Lai

文献摘要

被引文献

相似文献

在本文中,我们研究了假设检验规则的对抗稳健性。在所考虑的模型中,生成样本后,它会在被决策者观察之前被对手修改。决策者需要决定从对抗性修改的数据生成样本的基本假设。我们将此问题表述为极小极大假设检验问题,其中对手的目标是设计攻击策略以最大化错误概率,而决策者的目标是设计决策规则以最小化错误概率。我们考虑假设感知情况(攻击者知道真正的潜在假设)和假设无感知情况(攻击者不知道真正的潜在假设)。我们解决了这个极小极大问题,并描述了两种情况下相应的最优策略。
In this paper, we investigate the adversarial robustness of hypothesis testing rules. In the considered model, after a sample is generated, it will be modified by an adversary before being observed by the decision maker. The decision maker needs to decide the underlying hypothesis that generates the sample from the adversarially-modified data. We formulate this problem as a minimax hypothesis testing problem, in which the goal of the adversary is to design attack strategy to maximize the error probability while the decision maker aims to design decision rules so as to minimize the error probability. We consider both hypothesis-aware case, in which the attacker knows the true underlying hypothesis, and hypothesis-unaware case, in which the attacker does not know the true underlying hypothesis. We solve this minimax problem and characterize the corresponding optimal strategies for both cases.