On the Generalization Analysis of Adversarial Learning

被引:0
|
作者
Mustafa, Waleed [1 ]
Lei, Yunwen [2 ]
Kloft, Marius [1 ]
机构
[1] Univ Kaiserslautern, Dept Comp Sci, Kaiserslautern, Germany
[2] Univ Birmingham, Sch Comp Sci, Birmingham, W Midlands, England
来源
INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162 | 2022年
关键词
BOUNDS;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many recent studies have highlighted the susceptibility of virtually all machine-learning models to adversarial attacks. Adversarial attacks are imperceptible changes to an input example of a given prediction model. Such changes are carefully designed to alter the otherwise correct prediction of the model. In this paper, we study the generalization properties of adversarial learning. In particular, we derive high-probability generalization bounds on the adversarial risk in terms of the empirical adversarial risk, the complexity of the function class, and the adversarial noise set. Our bounds are generally applicable to many models, losses, and adversaries. We showcase its applicability by deriving adversarial generalization bounds for the multi-class classification setting and various prediction models (including linear models and Deep Neural Networks). We also derive optimistic adversarial generalization bounds for the case of smooth losses. These are the first fast-rate bounds valid for adversarial deep learning to the best of our knowledge.
引用
收藏
页数:23
相关论文
共 50 条
  • [21] The Adversarial Robustness of Sampling
    Ben-Eliezer, Omri
    Yogev, Eylon
    PODS'20: PROCEEDINGS OF THE 39TH ACM SIGMOD-SIGACT-SIGAI SYMPOSIUM ON PRINCIPLES OF DATABASE SYSTEMS, 2020, : 49 - 62
  • [22] A GENERALIZATION OF A PROBLEM OF MORDELL
    He, Bo
    Pinter, Akos
    Togbe, Alain
    Varga, Nora
    GLASNIK MATEMATICKI, 2015, 50 (01) : 35 - 41
  • [23] Generalization for Estrada Index
    Gungor, A. Dilek
    Cevik, A. Sinan
    Karpuz, Eylem G.
    Ates, Firat
    Cangul, I. Naci
    NUMERICAL ANALYSIS AND APPLIED MATHEMATICS, VOLS I-III, 2010, 1281 : 1106 - +
  • [24] A GENERALIZATION OF GERSHGORIN CIRCLES
    Chien, Mao-Ting
    Fang, Ssu-Ting
    Su, Yu-Xuan
    APPLIED AND COMPUTATIONAL MATHEMATICS, 2016, 15 (01) : 106 - 111
  • [25] Generalization of GCD matrices
    Han, Haiqing
    Li, Qin
    Wen, Yi
    Wen, Shuang
    Li, Jie
    EVOLUTIONARY INTELLIGENCE, 2022, 15 (04) : 2437 - 2443
  • [26] Minimax Analysis of Active Learning
    Hanneke, Steve
    Yang, Liu
    JOURNAL OF MACHINE LEARNING RESEARCH, 2015, 16 : 3487 - 3602
  • [27] Stability of adversarial routing with feedback
    Chlebus, Bogdan S.
    Cholvi, Vicent
    Kowalski, Dariusz R.
    NETWORKS, 2015, 66 (02) : 88 - 97
  • [28] Adversarial Online Collaborative Filtering
    Pasteris, Stephen
    Vitale, Fabio
    Herbster, Mark
    Gentile, Claudio
    Panisson, Andre'
    INTERNATIONAL CONFERENCE ON ALGORITHMIC LEARNING THEORY, VOL 237, 2024, 237
  • [29] On a generalization of a problem of Erdos and Graham
    Tengely, Szabolcs
    Varga, Nora
    PUBLICATIONES MATHEMATICAE-DEBRECEN, 2014, 84 (3-4): : 475 - 482
  • [30] Algorithmic Stability and Uniform Generalization
    Alabdulmohsin, Ibrahim
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 28 (NIPS 2015), 2015, 28