研究自适应对手下的分布学习,发现其要求比传统对手更强。
On the Learnability of Distribution Classes with Adaptive Adversaries
- 定义了自适应对手下的分布学习新标准,考虑对手的干扰预算。
- 证明自适应对手下可学习性比盲目对手更强。
- 适合关注对抗样本与鲁棒学习的研究者阅读。
我们研究在自适应对手存在下的分布类可学习性问题——即对手能截获学习者请求的样本,并在将其传递给学习者前,基于对样本的完全了解进行操纵。这与仅能修改样本分布但无法改变独立同分布性质的盲目对手形成对比。本文提出了一个关于自适应对手下可学习性的通用定义,同时考虑对手的干扰预算。我们证明,相对于加性自适应对手的可学习性,严格强于相对于加性盲目对手的可学习性。
原文摘要 · Abstract (English)
We consider the question of learnability of distribution classes in the presence of adaptive adversaries -- that is, adversaries capable of intercepting the samples requested by a learner and applying manipulations with full knowledge of the samples before passing it on to the learner. This stands in contrast to oblivious adversaries, who can only modify the underlying distribution the samples come from but not their i.i.d.\ nature. We formulate a general notion of learnability with respect to adaptive adversaries, taking into account the budget of the adversary. We show that learnability with respect to additive adaptive adversaries is a strictly stronger condition than learnability with respect to additive oblivious adversaries.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。