Uniform Convergence of Adversarially Robust Classifiers
Fuente:
arXiv
Saved in:
| Main Authors: | , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866908639282855936 |
|---|---|
| author | Morris, Rachel Murray, Ryan |
| author_facet | Morris, Rachel Murray, Ryan |
| contents | In recent years there has been significant interest in the effect of different types of adversarial perturbations in data classification problems. Many of these models incorporate the adversarial power, which is an important parameter with an associated trade-off between accuracy and robustness. This work considers a general framework for adversarially-perturbed classification problems, in a large data or population-level limit. In such a regime, we demonstrate that as adversarial strength goes to zero that optimal classifiers converge to the Bayes classifier in the Hausdorff distance. This significantly strengthens previous results, which generally focus on $L^1$-type convergence. The main argument relies upon direct geometric comparisons and is inspired by techniques from geometric measure theory. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2406_14682 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Uniform Convergence of Adversarially Robust Classifiers Morris, Rachel Murray, Ryan Analysis of PDEs Machine Learning Optimization and Control 28A75, 62G35, 68Q32, 35B25 In recent years there has been significant interest in the effect of different types of adversarial perturbations in data classification problems. Many of these models incorporate the adversarial power, which is an important parameter with an associated trade-off between accuracy and robustness. This work considers a general framework for adversarially-perturbed classification problems, in a large data or population-level limit. In such a regime, we demonstrate that as adversarial strength goes to zero that optimal classifiers converge to the Bayes classifier in the Hausdorff distance. This significantly strengthens previous results, which generally focus on $L^1$-type convergence. The main argument relies upon direct geometric comparisons and is inspired by techniques from geometric measure theory. |
| title | Uniform Convergence of Adversarially Robust Classifiers |
| topic | Analysis of PDEs Machine Learning Optimization and Control 28A75, 62G35, 68Q32, 35B25 |
| url | https://arxiv.org/abs/2406.14682 |