arXiv:2503.14299cs.LG2025-03中稿 · AISTATS 2025

用图论揭示多分类中随机化如何提升抗攻击能力

Unveiling the Role of Randomization in Multiclass Adversarial Classification: Insights from Graph Theory

  • 基于图论将多分类对抗风险最小化转化为集合打包问题
  • 发现三种数据分布结构下随机化可显著降低最优对抗风险
  • 首次在多分类中证明随机化比确定性策略更优的实例

随机化作为提升机器学习模型对抗鲁棒性的手段近年来受到广泛关注。然而,现有理论分析大多集中在二分类场景,对更复杂的多分类设置缺乏深入理解。本文受图论启发,针对离散数据分布,将对抗风险最小化问题置于成熟的集合打包问题框架中。通过该方法,我们识别出数据分布支撑集上三个必要结构条件,满足时随机化能有效提升鲁棒性。此外,我们构造了多个反例,显示在多分类中从确定性策略切换到随机化可显著降低最优对抗风险。这些发现揭示了随机化在多分类对抗防御中的关键作用。

原文摘要 · Abstract (English)

Randomization as a mean to improve the adversarial robustness of machine learning models has recently attracted significant attention. Unfortunately, much of the theoretical analysis so far has focused on binary classification, providing only limited insights into the more complex multiclass setting. In this paper, we take a step toward closing this gap by drawing inspiration from the field of graph theory. Our analysis focuses on discrete data distributions, allowing us to cast the adversarial risk minimization problems within the well-established framework of set packing problems. By doing so, we are able to identify three structural conditions on the support of the data distribution that are necessary for randomization to improve robustness. Furthermore, we are able to construct several data distributions where (contrarily to binary classification) switching from a deterministic to a randomized solution significantly reduces the optimal adversarial risk. These findings highlight the crucial role randomization can play in enhancing robustness to adversarial attacks in multiclass classification.

对抗鲁棒性图论随机化多分类

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。