给出对抗性分类风险收敛速率的量化边界,揭示鲁棒模型训练的效率机制。
Adversarial Surrogate Risk Bounds for Binary Classification
- 通过构建对抗性代理风险上界,分析其与真实风险的逼近速度
- 首次量化了对抗性分类风险在优化序列中的收敛速率
- 为对抗训练的有效性提供理论依据,适合关注模型鲁棒性的研究者
分类任务中,机器学习模型易受对抗攻击是核心问题。对抗训练是提升分类器鲁棒性的主流方法,其核心是极小化对抗性代理风险。近期工作已刻画出在二分类场景下,任何最小化对抗性代理风险的序列同时使对抗性分类风险最小化的条件,这一性质称为对抗一致性。然而,这些结果未涉及该序列中对抗性分类风险趋近最优值的速度。本文提供了能量化此收敛速率的代理风险边界。
原文摘要 · Abstract (English)
A central concern in classification is the vulnerability of machine learning models to adversarial attacks. Adversarial training is one of the most popular techniques for training robust classifiers, which involves minimizing an adversarial surrogate risk. Recent work has characterized the conditions under which any sequence minimizing the adversarial surrogate risk also minimizes the adversarial classification risk in the binary setting, a property known as adversarial consistency. However, these results do not address the rate at which the adversarial classification risk approaches its optimal value along such a sequence. This paper provides surrogate risk bounds that quantify that convergence rate.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。