Data-dependent stability analysis of adversarial training

被引:0
作者
Wang, Yihan [1 ]
Liu, Shuang [1 ]
Gao, Xiao-Shan [1 ]
机构
[1] Univ Chinese Acad Sci, Beijing 101408, Peoples R China
关键词
On-average stability analysis; Generalization bound; Adversarial training; Stochastic gradient descent; Data poisoning attack;
D O I
10.1016/j.neunet.2024.106983
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Stability analysis is an essential aspect of studying the generalization ability of deep learning, as it involves deriving generalization bounds for stochastic gradient descent-based training algorithms. Adversarial training is the most widely used defense against adversarial attacks. However, previous generalization bounds for adversarial training have not included information regarding data distribution. In this paper, we fill this gap by providing generalization bounds for stochastic gradient descent-based adversarial training that incorporate data distribution information. We utilize the concepts of on-average stability and high-order approximate Lipschitz conditions to examine how changes in data distribution and adversarial budget can affect robust generalization gaps. Our derived generalization bounds for both convex and non-convex losses are at least as good as the uniform stability-based counterparts which do not include data distribution information. Furthermore, our findings demonstrate how distribution shifts from data poisoning attacks can impact robust generalization.
引用
收藏
页数:14
相关论文
共 51 条
  • [21] Goodfellow IJ, 2015, Arxiv, DOI [arXiv:1412.6572, 10.48550/ARXIV.1412.6572, DOI 10.48550/ARXIV.1412.6572]
  • [22] Krizhevsky A., 2009, CITESEER
  • [23] Kuzborskij I, 2018, PR MACH LEARN RES, V80
  • [24] Le Y., 2015, Tiny ImageNet visual recognition challenge, V231N, P3
  • [25] Li Binghui, 2022, Advances in Neural Information Processing Systems
  • [26] Liu C, 2020, ADV NEUR IN, V33
  • [27] Madry A, 2019, Arxiv, DOI arXiv:1706.06083
  • [28] DeepFool: a simple and accurate method to fool deep neural networks
    Moosavi-Dezfooli, Seyed-Mohsen
    Fawzi, Alhussein
    Frossard, Pascal
    [J]. 2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, : 2574 - 2582
  • [29] ROBUST STOCHASTIC APPROXIMATION APPROACH TO STOCHASTIC PROGRAMMING
    Nemirovski, A.
    Juditsky, A.
    Lan, G.
    Shapiro, A.
    [J]. SIAM JOURNAL ON OPTIMIZATION, 2009, 19 (04) : 1574 - 1609
  • [30] Netzer Y., 2011, NIPS WORKSHOP DEEP L, P5