arXiv:2510.01969cs.LGmath.OC2025-10

提出多分类对抗鲁棒性的通用下界计算方法,突破0-1损失限制。

Lower Bounds on Adversarial Robustness for Multiclass Classification with General Loss Functions

  • 通过对偶与质心重构,统一处理任意损失函数的鲁棒风险
  • 在交叉熵、幂函数等损失下获得更紧的对抗风险下界
  • 连接对抗鲁棒性与α公平打包、广义质心问题,适合理论研究者

本文研究多分类场景下任意损失函数的对抗鲁棒性,推导了学习器无关鲁棒风险最小化问题的对偶与质心重构形式。针对交叉熵损失、幂形式损失和二次损失等重要情形,给出了明确表征,拓展了已有0-1损失的结果。这些重构形式支持高效计算对抗风险的紧下界,并促进超越0-1损失的鲁棒分类器设计。理论发现揭示了对抗鲁棒性与α-公平打包问题、带Kullback-Leibler或Tsallis熵惩罚的广义质心问题之间的深刻联系。数值实验表明,在交叉熵损失下可获得更紧的对抗风险下界。

原文摘要 · Abstract (English)

We consider adversarially robust classification in a multiclass setting under arbitrary loss functions and derive dual and barycentric reformulations of the corresponding learner-agnostic robust risk minimization problem. We provide explicit characterizations for important cases such as the cross-entropy loss, loss functions with a power form, and the quadratic loss, extending in this way available results for the 0-1 loss. These reformulations enable efficient computation of sharp lower bounds for adversarial risks and facilitate the design of robust classifiers beyond the 0-1 loss setting. Our paper uncovers interesting connections between adversarial robustness, $α$-fair packing problems, and generalized barycenter problems for arbitrary positive measures where Kullback-Leibler and Tsallis entropies are used as penalties. Our theoretical results are accompanied with illustrative numerical experiments where we obtain tighter lower bounds for adversarial risks with the cross-entropy loss function.

对抗鲁棒性多分类下界分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。