arXiv:2604.25965stat.MLcs.LG2026-04

NTK神经网络在对抗攻击下表现如何?研究给出理论最优解。

Adversarial Robustness of NTK Neural Networks

  • 用梯度流+早停训练NTK网络,逼近对抗回归最优率
  • 在过拟合时,最小范数插值器易受对抗扰动
  • 为安全关键领域提供理论依据,适合关注鲁棒性的研究者

深度学习模型广泛应用于安全关键场景,但仍易受对抗攻击。本文研究非参数回归背景下NTK神经网络的对抗鲁棒性。我们建立了Sobolev空间中对抗回归的极小极大最优率,并证明通过梯度流结合早停训练的NTK网络可达到该最优率。然而,在过拟合区间,我们证明最小范数插值器对对抗扰动高度敏感。

原文摘要 · Abstract (English)

Deep learning models are widely deployed in safety-critical domains, but remain vulnerable to adversarial attacks. In this paper, we study the adversarial robustness of NTK neural networks in the context of nonparametric regression. We establish minimax optimal rates for adversarial regression in Sobolev spaces and then show that NTK neural networks, trained via gradient flow with early stopping, can achieve this optimal rate. However, in the overfitting regime, we prove that the minimum norm interpolant is vulnerable to adversarial perturbations.

对抗鲁棒性NTK理论分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。