On Achieving Optimal Adversarial Test Error

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Justin D., Telgarsky, Matus
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910425433505792
author Li, Justin D.
Telgarsky, Matus
author_facet Li, Justin D.
Telgarsky, Matus
contents We first elucidate various fundamental properties of optimal adversarial predictors: the structure of optimal adversarial convex predictors in terms of optimal adversarial zero-one predictors, bounds relating the adversarial convex loss to the adversarial zero-one loss, and the fact that continuous predictors can get arbitrarily close to the optimal adversarial error for both convex and zero-one losses. Applying these results along with new Rademacher complexity bounds for adversarial training near initialization, we prove that for general data distributions and perturbation sets, adversarial training on shallow networks with early stopping and an idealized optimal adversary is able to achieve optimal adversarial test error. By contrast, prior theoretical work either considered specialized data distributions or only provided training error guarantees.
format Preprint
id arxiv_https___arxiv_org_abs_2306_07544
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle On Achieving Optimal Adversarial Test Error
Li, Justin D.
Telgarsky, Matus
Machine Learning
We first elucidate various fundamental properties of optimal adversarial predictors: the structure of optimal adversarial convex predictors in terms of optimal adversarial zero-one predictors, bounds relating the adversarial convex loss to the adversarial zero-one loss, and the fact that continuous predictors can get arbitrarily close to the optimal adversarial error for both convex and zero-one losses. Applying these results along with new Rademacher complexity bounds for adversarial training near initialization, we prove that for general data distributions and perturbation sets, adversarial training on shallow networks with early stopping and an idealized optimal adversary is able to achieve optimal adversarial test error. By contrast, prior theoretical work either considered specialized data distributions or only provided training error guarantees.
title On Achieving Optimal Adversarial Test Error
topic Machine Learning
url https://arxiv.org/abs/2306.07544