高维多指标模型下,神经网络可直接用标准特征学习实现对抗鲁棒性。
Robust Feature Learning for Multi-Index Models in High Dimensions
- 利用多指标模型的隐藏方向作为最优低维投影,提升对抗鲁棒性。
- 对抗鲁棒学习所需额外样本量与维度无关,与普通学习难度相当。
- 适用于追求高效鲁棒训练的高维数据建模场景。
近期关于神经网络特征学习的研究聚焦于单指标和多指标模型,其中目标函数是输入低维投影的函数。已有研究指出,在高维情况下,大部分计算与数据资源用于恢复低维投影;一旦该子空间被识别,剩余目标可独立于环境维度学习。然而,对抗环境下特征学习的影响尚未探索。本文首次探讨神经网络在对抗设置下的鲁棒特征学习。我们证明:在平方损失下,多指标模型的隐藏方向对ℓ₂有界对抗扰动提供贝叶斯最优低维投影,前提是多指标坐标与其他坐标统计独立。因此,可通过先进行标准特征学习,再对标准表示上的线性读出层进行鲁棒调优,实现鲁棒学习。特别地,对抗鲁棒学习与标准学习难度相当:相比标准学习,鲁棒学习所需的额外样本数不依赖维度。
原文摘要 · Abstract (English)
Recently, there have been numerous studies on feature learning with neural networks, specifically on learning single- and multi-index models where the target is a function of a low-dimensional projection of the input. Prior works have shown that in high dimensions, the majority of the compute and data resources are spent on recovering the low-dimensional projection; once this subspace is recovered, the remainder of the target can be learned independently of the ambient dimension. However, implications of feature learning in adversarial settings remain unexplored. In this work, we take the first steps towards understanding adversarially robust feature learning with neural networks. Specifically, we prove that the hidden directions of a multi-index model offer a Bayes optimal low-dimensional projection for robustness against $\ell_2$-bounded adversarial perturbations under the squared loss, assuming that the multi-index coordinates are statistically independent from the rest of the coordinates. Therefore, robust learning can be achieved by first performing standard feature learning, then robustly tuning a linear readout layer on top of the standard representations. In particular, we show that adversarially robust learning is just as easy as standard learning. Specifically, the additional number of samples needed to robustly learn multi-index models when compared to standard learning does not depend on dimensionality.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。