Asymptotic Behavior of Adversarial Training in Binary Linear Classification

被引:1
|
作者
Taheri, Hossein [1 ]
Pedarsani, Ramtin [1 ]
Thrampoulidis, Christos [1 ,2 ]
机构
[1] Univ Calif Santa Barbara, Dept Elect & Comp Engn, Santa Barbara, CA 93106 USA
[2] Univ British Columbia, Dept Elect & Comp Engn, Vancouver, BC V6T 1Z4, Canada
基金
美国国家科学基金会;
关键词
~Adversarial learning; adversarial training; high-dimensional statistics; optimization;
D O I
10.1109/TNNLS.2023.3290592
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training using empirical risk minimization (ERM) is the state-of-the-art method for defense against adversarial attacks, that is, against small additive adversarial perturbations applied to test data leading to misclassification. Despite being successful in practice, understanding the generalization properties of adversarial training in classification remains widely open. In this article, we take the first step in this direction by precisely characterizing the robustness of adversarial training in binary linear classification. Specifically, we consider the high-dimensional regime where the model dimension grows with the size of the training set at a constant ratio. Our results provide exact asymptotics for both standard and adversarial test errors under general lq-norm bounded perturbations (q = 1) in both discriminative binary models and generative Gaussian-mixture models with correlated features. We use our sharp error formulae to explain how the adversarial and standard errors depend upon the over-parameterization ratio, the data model, and the attack budget. Finally, by comparing with the robust Bayes estimator, our sharp asymptotics allow us to study the fundamental limits of adversarial training.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [31] On the asymptotic behavior of a linear viscoelastic fluid
    Fabrizio, Mauro
    Lazzari, Barbara
    Nibbi, Roberta
    MATHEMATICAL METHODS IN THE APPLIED SCIENCES, 2012, 35 (07) : 769 - 775
  • [32] ASYMPTOTIC BEHAVIOR OF PERTURBED LINEAR SYSTEMS
    LOCKE, P
    JOURNAL OF DIFFERENTIAL EQUATIONS, 1971, 9 (02) : 380 - &
  • [33] The asymptotic behavior of linear placement statistics
    Kim, Dongjae
    Lee, Sungchul
    Wang, Wensheng
    STATISTICS & PROBABILITY LETTERS, 2011, 81 (02) : 326 - 336
  • [34] ASYMPTOTIC-BEHAVIOR IN LINEAR VISCOELASTICITY
    RIVERA, JEM
    QUARTERLY OF APPLIED MATHEMATICS, 1994, 52 (04) : 629 - 648
  • [35] ASYMPTOTIC BEHAVIOR OF LINEAR INTEGRODIFFERENTIAL SYSTEMS
    GROSSMAN, SI
    BARBU, V
    NOTICES OF THE AMERICAN MATHEMATICAL SOCIETY, 1972, 19 (01): : A155 - &
  • [36] ASYMPTOTIC-BEHAVIOR OF LINEAR RECURRENCES
    BURKE, JR
    WEBB, WA
    FIBONACCI QUARTERLY, 1981, 19 (04): : 318 - 321
  • [37] SafeAMC: Adversarial training for robust modulation classification models
    Maroto, Javier
    Bovet, Gerome
    Frossard, Pascal
    2022 30TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO 2022), 2022, : 1636 - 1640
  • [38] Adversarial training for few-shot text classification
    Croce, Danilo
    Castellucci, Giuseppe
    Basili, Roberto
    INTELLIGENZA ARTIFICIALE, 2020, 14 (02) : 201 - 214
  • [39] PRECISE STATISTICAL ANALYSIS OF CLASSIFICATION ACCURACIES FOR ADVERSARIAL TRAINING
    Javanmard, Adel
    Soltanolkotabi, Mahdi
    ANNALS OF STATISTICS, 2022, 50 (04): : 2127 - 2156
  • [40] Siamese BERT Model with Adversarial Training for Relation Classification
    Lin, Zhimin
    Lei, Dajiang
    Han, Yuting
    Wang, Guoyin
    Deng, Wei
    Huang, Yuan
    11TH IEEE INTERNATIONAL CONFERENCE ON KNOWLEDGE GRAPH (ICKG 2020), 2020, : 291 - 296