paper-with-me

Papers

Classifier-independent Lower-Bounds for Adversarial Robustness

2020-06-17 · Elvis Dohmatob

We theoretically analyse the limits of robustness to test-time adversarial and noisy examples in classification. Our work focuses on deriving bounds which uniformly apply to all classifiers (i.e all measurable functions from features to labels) for a given problem. Our contributions are two-fold. (1) We use optimal transport theory to derive variational formulae for the Bayes-optimal error a classifier can make on a given classification problem, subject to adversarial attacks. The optimal adversarial attack is then an optimal transport plan for a certain binary cost-function induced by the specific attack model, and can be computed via a simple algorithm based on maximal matching on bipartite graphs. (2) We derive explicit lower-bounds on the Bayes-optimal error in the case of the popular distance-based attacks. These bounds are universal in the sense that they depend on the geometry of the class-conditional distributions of the data, but not on a particular classifier. Our results are in sharp contrast with the existing literature, wherein adversarial vulnerability of classifiers is derived as a consequence of nonzero ordinary test error.

📄 PDF Abstract BibTeX arXiv:2006.09989

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackAdversarial RobustnessGeneral Classification

Similar Papers 제목 키워드 기반

Lower Bounds on Adversarial Robustness for Multiclass Classification with General Loss Functions

2025-10-02 · Camilo Andrés García Trillos, Nicolás García Trillos arxiv

We consider adversarially robust classification in a multiclass setting under arbitrary loss functions and derive dual and barycentric reformulations of the corresponding learner-agnostic robust risk minimization problem…

Adversarial Robustness

Provable Robustness of ReLU networks via Maximization of Linear Regions

2018-10-17 · Francesco Croce, Maksym Andriushchenko, Matthias Hein

It has been shown that neural network classifiers are not robust. This raises concerns about their usage in safety-critical systems. We propose in this paper a regularization scheme for ReLU networks which provably impro…

Adversarial Learning Guarantees for Linear Hypotheses and Neural Networks

2020-04-28 · ICML 2020 1 · Pranjal Awasthi, Natalie Frank, Mehryar Mohri

Adversarial or test time robustness measures the susceptibility of a classifier to perturbations to the test input. While there has been a flurry of recent work on designing defenses against such perturbations, the theor…

Adversarial Robustness

Formal Guarantees on the Robustness of a Classifier against Adversarial Manipulation

2017-05-23 · NeurIPS 2017 12 · Matthias Hein, Maksym Andriushchenko

Recent work has shown that state-of-the-art classifiers are quite brittle, in the sense that a small adversarial change of an originally with high confidence correctly classified input leads to a wrong classification aga…

General Classification

Provably Adversarially Robust Nearest Prototype Classifiers

2022-07-14 · Václav Voráček, Matthias Hein

Nearest prototype classifiers (NPCs) assign to each input point the label of the nearest prototype with respect to a chosen distance metric. A direct advantage of NPCs is that the decisions are interpretable. Previous wo…

image-classificationImage Classification