paper-with-me

홈 › Papers

Lower Bounds on Adversarial Robustness from Optimal Transport

2019-09-26 · NeurIPS 2019 12 · Arjun Nitin Bhagoji, Daniel Cullina, Prateek Mittal

While progress has been made in understanding the robustness of machine learning classifiers to test-time adversaries (evasion attacks), fundamental questions remain unresolved. In this paper, we use optimal transport to characterize the minimum possible loss in an adversarial classification scenario. In this setting, an adversary receives a random labeled example from one of two classes, perturbs the example subject to a neighborhood constraint, and presents the modified example to the classifier. We define an appropriate cost function such that the minimum transportation cost between the distributions of the two classes determines the minimum $0-1$ loss for any classifier. When the classifier comes from a restricted hypothesis class, the optimal transportation cost provides a lower bound. We apply our framework to the case of Gaussian data with norm-bounded adversaries and explicitly show matching bounds for the classification and transport problems as well as the optimality of linear classifiers. We also characterize the sample complexity of learning in this setting, deriving and extending previously known results as a special case. Finally, we use our framework to study the gap between the optimal classification performance possible and that currently achieved by state-of-the-art robustly trained neural networks for datasets of interest, namely, MNIST, Fashion MNIST and CIFAR-10.

📄 PDF Abstract BibTeX arXiv:1909.12272

Code (1)

inspire-group/robustness-via-transport 공식 구현 tf

Tasks

Adversarial RobustnessClassificationGeneral Classification

Similar Papers 제목 키워드 기반

Classifier-independent Lower-Bounds for Adversarial Robustness

2020-06-17 · Elvis Dohmatob

We theoretically analyse the limits of robustness to test-time adversarial and noisy examples in classification. Our work focuses on deriving bounds which uniformly apply to all classifiers (i.e all measurable functions …

Adversarial AttackAdversarial RobustnessGeneral Classification

An Optimal Transport Approach for Computing Adversarial Training Lower Bounds in Multiclass Classification

2024-01-17 · Nicolas Garcia Trillos, Matt Jacobs, Jakwang Kim, Matthew Werenski

Despite the success of deep learning-based algorithms, it is widely known that neural networks may fail to be robust. A popular paradigm to enforce robustness is adversarial training (AT), however, this introduces many c…

Genetic Column Generation for Computing Lower Bounds for Adversarial Classification

2024-06-12 · Maximilian Penka

Recent theoretical results on adversarial multi-class classification showed a similarity to the multi-marginal formulation of Wasserstein-barycenter in optimal transport. Unfortunately, both problems suffer from the curs…

ClassificationMulti-class Classification

Statistical Guarantees for Distributionally Robust Optimization with Optimal Transport and OT-Regularized Divergences

2026-03-29 · Jeremiah Birrell, Xiaoxi Shen arxiv

We study finite-sample statistical performance guarantees for distributionally robust optimization (DRO) with optimal transport (OT) and OT-regularized divergence model neighborhoods. Specifically, we derive concentratio…

Adversarial Robustness

Learning Probability Measures with respect to Optimal Transport Metrics

2012-12-01 · NeurIPS 2012 12 · Guillermo Canas, Lorenzo Rosasco

We study the problem of estimating, in the sense of optimal transport metrics, a measure which is assumed supported on a manifold embedded in a Hilbert space. By establishing a precise connection between optimal transpor…

Learning TheoryQuantization