More Data Can Expand the Generalization Gap Between Adversarially Robust and Standard Models

More Data Can Expand the Generalization Gap Between Adversarially Robust and Standard Models
复制标题

DOI:
--
复制
发表时间:
2020-02
期刊:
--
影响因子:
--
通讯作者:
Lin Chen;Yifei Min;Mingrui Zhang;Amin Karbasi
Lin Chen;Yifei Min;Mingrui Zhang;Amin Karbasi
中科院分区:
其他
文献类型:
--
作者:
Lin Chen;Yifei Min;Mingrui Zhang;Amin Karbasi

文献摘要

被引文献

相似文献

尽管在实践中取得了显著的成功,但人们发现现代机器学习模型容易受到对抗性攻击的影响,这些攻击会对数据造成人类无法察觉的干扰,但会导致严重的和潜在的危险预测错误。为了解决这个问题,从业者经常使用对抗性训练来学习对此类攻击具有鲁棒性的模型,但在未扰动的测试集上会产生更高的泛化错误。传统观点认为,更多的训练数据应该缩小逆向训练模型和标准模型的泛化误差之间的差距。然而,我们研究了高斯和伯努利模型在$\ell_\infty$攻击下的鲁棒分类器的训练,我们证明了更多的数据实际上可能会增加这一差距。此外,我们的理论结果确定是否以及何时额外的数据将最终开始缩小差距。最后,我们通过实验证明了我们的结果也适用于线性回归模型,这可能表明这种现象发生得更广泛。
Despite remarkable success in practice, modern machine learning models have been found to be susceptible to adversarial attacks that make human-imperceptible perturbations to the data, but result in serious and potentially dangerous prediction errors. To address this issue, practitioners often use adversarial training to learn models that are robust against such attacks at the cost of higher generalization error on unperturbed test sets. The conventional wisdom is that more training data should shrink the gap between the generalization error of adversarially-trained models and standard models. However, we study the training of robust classifiers for both Gaussian and Bernoulli models under $\ell_\infty$ attacks, and we prove that more data may actually increase this gap. Furthermore, our theoretical results identify if and when additional data will finally begin to shrink the gap. Lastly, we experimentally demonstrate that our results also hold for linear regression models, which may indicate that this phenomenon occurs more broadly.