arXiv:2505.17356cs.LG2025-05NeurIPS被引 1

研究非参数回归在对抗攻击下的鲁棒性,发现平滑样条可有效抵御数据污染。

Adversarial Robustness of Nonparametric Regression

  • 假设回归函数属二阶Sobolev空间,分析对抗鲁棒性边界。
  • 当少于o(n)样本被污染时,平滑样条估计误差随n增大趋近零。
  • 揭示了平滑样条在容忍污染样本数上的最优性,适合高可靠性场景。

本文研究非参数回归在对抗攻击下的鲁棒性,即对手可任意污染部分输入数据的情形。尽管参数回归的鲁棒性已有广泛研究,其非参数版本仍鲜有探索。我们假设回归函数属于二阶Sobolev空间(即其二阶导数平方可积),刻画了该设定下的对抗鲁棒性。主要贡献有两点:(i) 建立了估计误差的极小极大下界,揭示了任何估计器无法突破的根本极限;(ii) 意外发现,经适当正则化后,经典平滑样条估计器对对抗污染具有鲁棒性。结果表明:若$o(n)$个样本被污染,则当$n \to \infty$时,平滑样条的估计误差趋于零。而当恒定比例的数据被污染时,任何估计器都无法保证误差消失,说明平滑样条在最大容忍污染样本数上达到最优。

原文摘要 · Abstract (English)

In this paper, we investigate the adversarial robustness of nonparametric regression, a fundamental problem in machine learning, under the setting where an adversary can arbitrarily corrupt a subset of the input data. While the robustness of parametric regression has been extensively studied, its nonparametric counterpart remains largely unexplored. We characterize the adversarial robustness in nonparametric regression, assuming the regression function belongs to the second-order Sobolev space (i.e., it is square integrable up to its second derivative). The contribution of this paper is two-fold: (i) we establish a minimax lower bound on the estimation error, revealing a fundamental limit that no estimator can overcome, and (ii) we show that, perhaps surprisingly, the classical smoothing spline estimator, when properly regularized, exhibits robustness against adversarial corruption. These results imply that if $o(n)$ out of $n$ samples are corrupted, the estimation error of the smoothing spline vanishes as $n \to \infty$. On the other hand, when a constant fraction of the data is corrupted, no estimator can guarantee vanishing estimation error, implying the optimality of the smoothing spline in terms of maximum tolerable number of corrupted samples.

非参数回归对抗鲁棒性平滑样条

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。