arXiv:2502.14298cs.LGstat.ML2025-02

提出对抗鲁棒的贝叶斯线性回归,给出首个理论保证。

Generalization Certificates for Adversarially Robust Bayesian Linear Regression

  • 用Bregman散度构建对抗损失,闭式求解扰动。
  • 引入对抗鲁棒后验,比传统贝叶斯后验更抗干扰。
  • 首次在对抗场景下提供泛化保证,适合安全关键领域。

机器学习模型的对抗鲁棒性对数据扰动下的可靠性能至关重要。现有研究多集中于点估计器,本文考虑分布预测器。首先,通过指数族与Bregman散度的关联,将对抗Bregman散度损失形式化为对抗负对数似然;利用Bregman散度的几何性质,以闭式计算此类模型的对抗扰动。其次,在该损失下,通过广义贝叶斯推断的优化视角,引入对抗鲁棒后验。第三,借助PAC-Bayesian框架,首次推导出对抗扩展贝叶斯线性回归的严格泛化证书。最后,真实与合成数据集上的实验表明,所提对抗鲁棒后验在鲁棒性上优于贝叶斯后验,并验证了理论保证的有效性。

原文摘要 · Abstract (English)

Adversarial robustness of machine learning models is critical to ensuring reliable performance under data perturbations. Recent progress has been on point estimators, and this paper considers distributional predictors. First, using the link between exponential families and Bregman divergences, we formulate an adversarial Bregman divergence loss as an adversarial negative log-likelihood. Using the geometric properties of Bregman divergences, we compute the adversarial perturbation for such models in closed-form. Second, under such losses, we introduce \emph{adversarially robust posteriors}, by exploiting the optimization-centric view of generalized Bayesian inference. Third, we derive the \emph{first} rigorous generalization certificates in the context of an adversarial extension of Bayesian linear regression by leveraging the PAC-Bayesian framework. Finally, experiments on real and synthetic datasets demonstrate the superior robustness of the derived adversarially robust posterior over Bayes posterior, and also validate our theoretical guarantees.

贝叶斯推断对抗鲁棒泛化保证线性回归

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。