arXiv:2506.01267stat.MLcs.LG2025-06被引 2

提出对抗性非参数回归的最优估计方法,揭示鲁棒学习的理论极限。

Adversarial learning for nonparametric regression: Minimax rate and adaptive estimation

  • 基于局部多项式构造对抗鲁棒估计器,实现理论最优。
  • 给出 $L_q$ 风险下对抗攻击的最小最大收敛速率,覆盖 $1\leq q\leq\infty$。
  • 设计自适应算法,对不同平滑度和扰动规模均近似最优,适合理论研究者。

尽管机器学习模型在诸多领域取得显著进展,但其对输入数据中细微、自然或人为构造的扰动(即对抗攻击)仍高度敏感。尽管已有大量对抗学习方法被提出,但在未来输入受 $X$-攻击情形下,其统计最优性仍未明确。本文在非参数回归框架下,针对回归函数光滑性与输入扰动集几何结构的合理假设,首次建立了 $L_q$ 风险下对抗攻击的最小最大收敛速率($1 \leq q \leq \infty$),并提出一种分段局部多项式估计器,达到该最优速率。该速率揭示了函数光滑程度与扰动幅度对鲁棒学习根本限制的影响。此外,我们构建了一种数据驱动的自适应估计器,可在对数因子内实现跨广泛非参数与对抗类别的最优速率。

原文摘要 · Abstract (English)

Despite tremendous advancements of machine learning models and algorithms in various application domains, they are known to be vulnerable to subtle, natural or intentionally crafted perturbations in future input data, known as adversarial attacks. While numerous adversarial learning methods have been proposed, fundamental questions about their statistical optimality in robust loss remain largely unanswered. In particular, the minimax rate of convergence and the construction of rate-optimal estimators under future $X$-attacks are yet to be worked out. In this paper, we address this issue in the context of nonparametric regression, under suitable assumptions on the smoothness of the regression function and the geometric structure of the input perturbation set. We first establish the minimax rate of convergence under adversarial $L_q$-risks with $1 \leq q \leq \infty$ and propose a piecewise local polynomial estimator that achieves the minimax optimality. The established minimax rate elucidates how the smoothness level and perturbation magnitude affect the fundamental limit of adversarial learning under future $X$-attacks. Furthermore, we construct a data-driven adaptive estimator that is shown to achieve, within a logarithmic factor, the optimal rate across a broad scale of nonparametric and adversarial classes.

对抗学习非参数回归最小最大率自适应估计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。