arXiv:2510.25121cs.LGmath.OC2025-10中稿 · Mathematics被引 1

用双层优化建模对抗攻击,揭示凸聚类模型的鲁棒性边界。

Bilevel Models for Adversarial Learning and A Case Study

  • 通过扰动分析构建双层优化模型,量化对抗攻击影响。
  • 在噪声较大时,δ-度量可作为凸聚类模型的偏差函数。
  • 理论验证结合数值实验,适合研究模型鲁棒性的学者参考。

对抗学习因机器学习与人工智能的快速发展而备受关注。然而,由于大多数机器学习模型结构复杂,对抗攻击的机制尚未清晰解释,攻击效果的衡量也仍不明确。本文从扰动分析角度研究对抗学习,通过解映射的平稳性刻画学习模型的鲁棒性。针对凸聚类模型,我们确定了在扰动下聚类结果保持不变的条件;当噪声水平较高时,即构成攻击。为此,我们提出两种用于对抗学习的双层模型,其攻击效果由某种偏差函数衡量。具体地,系统研究了δ-度量,并证明在特定条件下,该度量可作为凸聚类模型的偏差函数。最后,通过数值实验验证了上述理论结果及所提双层模型的有效性。

原文摘要 · Abstract (English)

Adversarial learning has been attracting more and more attention thanks to the fast development of machine learning and artificial intelligence. However, due to the complicated structure of most machine learning models, the mechanism of adversarial attacks is not well interpreted. How to measure the effect of attacks is still not quite clear. In this paper, we investigate the adversarial learning from the perturbation analysis point of view. We characterize the robustness of learning models through the calmness of the solution mapping. In the case of convex clustering models, we identify the conditions under which the clustering results remain the same under perturbations. When the noise level is large, it leads to an attack. Therefore, we propose two bilevel models for adversarial learning where the effect of adversarial learning is measured by some deviation function. Specifically, we systematically study the so-called $δ$-measure and show that under certain conditions, it can be used as a deviation function in adversarial learning for convex clustering models. Finally, we conduct numerical tests to verify the above theoretical results as well as the efficiency of the two proposed bilevel models.

对抗学习双层优化鲁棒性分析凸聚类

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。