对抗训练在核回归中引入噪声溢价,导致预测误差变慢
The Noise Premium in Adversarial Training for Kernel Regression
- 在再生核希尔伯特空间中分析对抗训练的噪声溢价机制
- 噪声溢价使误差收敛速度低于最优非参数基准,且扰动超阈值会退化为零函数
- 提出去噪对抗训练,逼近最优率并提升稳定性,适合关注鲁棒性与精度平衡的研究者
对抗训练可提升模型对有界扰动的鲁棒性,但常以统计效率为代价。本文研究再生核希尔伯特空间(RKHS)中核回归的这一权衡。在平方损失下,对抗训练引入一个涉及函数范数与响应噪声绝对均值乘积的项,称为‘噪声溢价’。分析表明,即使平衡了近似与估计误差,噪声溢价仍使对抗训练的预测误差收敛速度严格慢于非参数最小最大基准。对于固定扰动预算,当预算超过某一阈值时,对抗训练解会退化为零函数。为缓解此问题,提出去噪对抗训练。所提估计器可将预测误差率逼近最小最大最优率(对数因子内),提升退化阈值,并给出对抗损失增长的显式上界。合成与真实数据上的数值实验验证了理论结果及方法有效性。
原文摘要 · Abstract (English)
Adversarial training can improve the robustness of predictive models to bounded perturbations, often at the cost of statistical efficiency. We study this trade-off in kernel regression over a reproducing kernel Hilbert space (RKHS). It is shown that, under squared loss, adversarial training in RKHS introduces a term involving the product of the function norm with the mean absolute value of the response noise, which we call the \textit{noise premium}. Our analysis shows that the noise premium makes the prediction error of adversarial training converge strictly more slowly than the nonparametric minimax benchmark even after balancing approximation and estimation errors. Moreover, for a fixed perturbation budget, once the budget exceeds a certain threshold, the solution to adversarial training collapses to the zero function. To mitigate these effects of the noise premium, we propose noise-debiased adversarial training. The resulting noise-debiased estimator can attain the minimax optimal rate up to a logarithmic factor for the prediction error, raises the collapse threshold, and admits an explicit bound on the increase in adversarial loss. Numerical experiments on synthetic and real data support the theoretical findings and validate the effectiveness of the proposed noise-debiased method.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。