arXiv:2501.03402math.STcs.LG2025-01被引 2

发现贝叶斯-霍赫伯格方法在对抗攻击下易失效,仅需少量扰动即可突破错误发现率控制。

On the Adversarial Robustness of Benjamini Hochberg

  • 将BH过程重构成‘球入桶’模型,用组合数学分析其稳定性
  • 实验证明只需一次测试分数扰动,即可能大幅破坏FDR控制
  • 提供非渐近的对抗调整后FDR下界,适用于安全关键场景

Benjamini-Hochberg(BH)程序广泛用于多重检验中控制错误发现率(FDR),在药物发现、法医学、异常检测及机器学习中的无监督异常检测、分布外检测和单类分类等任务中均有应用。鉴于该控制在安全与隐私等关键场景中被依赖,本文研究其对抗鲁棒性。我们揭示了在何种条件下BH具有或不具有对抗鲁棒性,提出一类简单且易于实现的对抗测试分数扰动算法,并进行计算实验。结果表明,在特定条件下,仅通过少量(甚至单次)测试分数扰动即可显著破坏BH的FDR控制;同时提供了对抗调整后期望FDR的非渐近保证。技术分析将BH过程重新表述为‘球入桶’组合过程,并关联广义选票问题,从而采用信息论方法推导出非渐近下界。

原文摘要 · Abstract (English)

The Benjamini-Hochberg (BH) procedure is widely used to control the false detection rate (FDR) in multiple testing. Applications of this control abound in drug discovery, forensics, anomaly detection, and, in particular, machine learning, ranging from nonparametric outlier detection to out-of-distribution detection and one-class classification methods. Considering this control could be relied upon in critical safety/security contexts, we investigate its adversarial robustness. More precisely, we study under what conditions BH does and does not exhibit adversarial robustness, we present a class of simple and easily implementable adversarial test-perturbation algorithms, and we perform computational experiments. With our algorithms, we demonstrate that there are conditions under which BH's control can be significantly broken with relatively few (even just one) test score perturbation(s), and provide non-asymptotic guarantees on the expected adversarial-adjustment to FDR. Our technical analysis involves a combinatorial reframing of the BH procedure as a ``balls into bins'' process, and drawing a connection to generalized ballot problems to facilitate an information-theoretic approach for deriving non-asymptotic lower bounds.

FDR控制对抗鲁棒性多重检验统计安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。