通过特征空间扰动实现高效对抗训练,自动适应噪声与函数平滑性。
Kernel Learning with Adversarial Features: Numerical Efficiency and Adaptive Regularization

- 在再生核希尔伯特空间中改用特征扰动,避免高成本极小极大问题。
- 可精确求解内层最大化,优化效率显著提升,且具自适应正则化能力。
- 适用于需要鲁棒性与计算效率的场景,如安全关键系统建模。
对抗训练已成为提升模型对输入扰动鲁棒性的关键技术。现有方法多依赖计算代价高昂的极小极大问题,限制了实际应用。本文提出一种在再生核希尔伯特空间中的新型对抗训练形式,将扰动从输入空间转移到特征空间。该重构使内层最大化可精确求解,从而实现高效优化。同时,所得估计器能自然适应噪声水平和底层函数的平滑性。我们建立了特征扰动形式作为原问题松弛的条件,并提出基于迭代核岭回归的高效优化算法。提供了泛化误差界以理解方法性质。此外,该框架可扩展至多核学习。实验表明,在干净与对抗环境下均表现良好。
原文摘要 · Abstract (English)
Adversarial training has emerged as a key technique to enhance model robustness against adversarial input perturbations. Many of the existing methods rely on computationally expensive min-max problems that limit their application in practice. We propose a novel formulation of adversarial training in reproducing kernel Hilbert spaces, shifting from input to feature-space perturbations. This reformulation enables the exact solution of inner maximization and efficient optimization. It also provides a regularized estimator that naturally adapts to the noise level and the smoothness of the underlying function. We establish conditions under which the feature-perturbed formulation is a relaxation of the original problem and propose an efficient optimization algorithm based on iterative kernel ridge regression. We provide generalization bounds that help to understand the properties of the method. We also extend the formulation to multiple kernel learning. Empirical evaluation shows good performance in both clean and adversarial settings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。