Uniform Convergence of Adversarially Robust Classifiers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Morris, Rachel, Murray, Ryan
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908639282855936
author Morris, Rachel
Murray, Ryan
author_facet Morris, Rachel
Murray, Ryan
contents In recent years there has been significant interest in the effect of different types of adversarial perturbations in data classification problems. Many of these models incorporate the adversarial power, which is an important parameter with an associated trade-off between accuracy and robustness. This work considers a general framework for adversarially-perturbed classification problems, in a large data or population-level limit. In such a regime, we demonstrate that as adversarial strength goes to zero that optimal classifiers converge to the Bayes classifier in the Hausdorff distance. This significantly strengthens previous results, which generally focus on $L^1$-type convergence. The main argument relies upon direct geometric comparisons and is inspired by techniques from geometric measure theory.
format Preprint
id arxiv_https___arxiv_org_abs_2406_14682
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Uniform Convergence of Adversarially Robust Classifiers
Morris, Rachel
Murray, Ryan
Analysis of PDEs
Machine Learning
Optimization and Control
28A75, 62G35, 68Q32, 35B25
In recent years there has been significant interest in the effect of different types of adversarial perturbations in data classification problems. Many of these models incorporate the adversarial power, which is an important parameter with an associated trade-off between accuracy and robustness. This work considers a general framework for adversarially-perturbed classification problems, in a large data or population-level limit. In such a regime, we demonstrate that as adversarial strength goes to zero that optimal classifiers converge to the Bayes classifier in the Hausdorff distance. This significantly strengthens previous results, which generally focus on $L^1$-type convergence. The main argument relies upon direct geometric comparisons and is inspired by techniques from geometric measure theory.
title Uniform Convergence of Adversarially Robust Classifiers
topic Analysis of PDEs
Machine Learning
Optimization and Control
28A75, 62G35, 68Q32, 35B25
url https://arxiv.org/abs/2406.14682