Provable tradeoffs in adversarially robust classification

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Dobriban, Edgar, Hassani, Hamed, Hong, David, Robey, Alexander
Formato: Preprint
Publicado: 2020
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913566343299072
author Dobriban, Edgar
Hassani, Hamed
Hong, David
Robey, Alexander
author_facet Dobriban, Edgar
Hassani, Hamed
Hong, David
Robey, Alexander
contents It is well known that machine learning methods can be vulnerable to adversarially-chosen perturbations of their inputs. Despite significant progress in the area, foundational open problems remain. In this paper, we address several key questions. We derive exact and approximate Bayes-optimal robust classifiers for the important setting of two- and three-class Gaussian classification problems with arbitrary imbalance, for $\ell_2$ and $\ell_\infty$ adversaries. In contrast to classical Bayes-optimal classifiers, determining the optimal decisions here cannot be made pointwise and new theoretical approaches are needed. We develop and leverage new tools, including recent breakthroughs from probability theory on robust isoperimetry, which, to our knowledge, have not yet been used in the area. Our results reveal fundamental tradeoffs between standard and robust accuracy that grow when data is imbalanced. We also show further results, including an analysis of classification calibration for convex losses in certain models, and finite sample rates for the robust risk.
format Preprint
id arxiv_https___arxiv_org_abs_2006_05161
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle Provable tradeoffs in adversarially robust classification
Dobriban, Edgar
Hassani, Hamed
Hong, David
Robey, Alexander
Machine Learning
It is well known that machine learning methods can be vulnerable to adversarially-chosen perturbations of their inputs. Despite significant progress in the area, foundational open problems remain. In this paper, we address several key questions. We derive exact and approximate Bayes-optimal robust classifiers for the important setting of two- and three-class Gaussian classification problems with arbitrary imbalance, for $\ell_2$ and $\ell_\infty$ adversaries. In contrast to classical Bayes-optimal classifiers, determining the optimal decisions here cannot be made pointwise and new theoretical approaches are needed. We develop and leverage new tools, including recent breakthroughs from probability theory on robust isoperimetry, which, to our knowledge, have not yet been used in the area. Our results reveal fundamental tradeoffs between standard and robust accuracy that grow when data is imbalanced. We also show further results, including an analysis of classification calibration for convex losses in certain models, and finite sample rates for the robust risk.
title Provable tradeoffs in adversarially robust classification
topic Machine Learning
url https://arxiv.org/abs/2006.05161