paper-with-me

홈 › Papers

A High Dimensional Statistical Model for Adversarial Training: Geometry and Trade-Offs

2024-02-08 · Kasimir Tanner, Matteo Vilucchio, Bruno Loureiro, Florent Krzakala

This work investigates adversarial training in the context of margin-based linear classifiers in the high-dimensional regime where the dimension $d$ and the number of data points $n$ diverge with a fixed ratio $\alpha = n / d$. We introduce a tractable mathematical model where the interplay between the data and adversarial attacker geometries can be studied, while capturing the core phenomenology observed in the adversarial robustness literature. Our main theoretical contribution is an exact asymptotic description of the sufficient statistics for the adversarial empirical risk minimiser, under generic convex and non-increasing losses for a Block Feature Model. Our result allow us to precisely characterise which directions in the data are associated with a higher generalisation/robustness trade-off, as defined by a robustness and a usefulness metric. We show that the the presence of multiple different feature types is crucial to the high sample complexity performances of adversarial training. In particular, we unveil the existence of directions which can be defended without penalising accuracy. Finally, we show the advantage of defending non-robust features during training, identifying a uniform protection as an inherently effective defence mechanism.

📄 PDF Abstract BibTeX arXiv:2402.05674

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial Robustness

Similar Papers 제목 키워드 기반

On the Geometry of Adversarial Examples

2018-11-01 · ICLR 2019 5 · Marc Khoury, Dylan Hadfield-Menell

Adversarial examples are a pervasive phenomenon of machine learning models where seemingly imperceptible perturbations to the input lead to misclassifications for otherwise statistically accurate models. We propose a geo…

Adversarial Training with Voronoi Constraints

2019-05-02 · Marc Khoury, Dylan Hadfield-Menell

Adversarial examples are a pervasive phenomenon of machine learning models where seemingly imperceptible perturbations to the input lead to misclassifications for otherwise statistically accurate models. We propose a geo…

Latent Space Non-Linear Statistics

2018-05-19 · Line Kuhnel, Tom Fletcher, Sarang Joshi, Stefan Sommer

Given data, deep generative models, such as variational autoencoders (VAE) and generative adversarial networks (GAN), train a lower dimensional latent representation of the data space. The linear Euclidean geometry of da…

On the Geometry of Regularization in Adversarial Training: High-Dimensional Asymptotics and Generalization Bounds

2024-10-21 · Matteo Vilucchio, Nikolaos Tsilivis, Bruno Loureiro, Julia Kempe

Regularization, whether explicit in terms of a penalty in the loss or implicit in the choice of algorithm, is a cornerstone of modern machine learning. Indeed, controlling the complexity of the model class is particularl…

Binary ClassificationGeneralization Bounds

The Geometry of Adversarial Subspaces

2021-09-29 · Dylan M. Paiton, David Schultheiss, Matthias Kuemmerer, Zac Cranko 외

Artificial neural networks (ANNs) are constructed using well-understood mathematical operations, and yet their high-dimensional, non-linear, and compositional nature has hindered our ability to provide an intuitive descr…