Asymptotic Behavior of Adversarial Training in Binary Linear Classification

被引:1
|
作者
Taheri, Hossein [1 ]
Pedarsani, Ramtin [1 ]
Thrampoulidis, Christos [1 ,2 ]
机构
[1] Univ Calif Santa Barbara, Dept Elect & Comp Engn, Santa Barbara, CA 93106 USA
[2] Univ British Columbia, Dept Elect & Comp Engn, Vancouver, BC V6T 1Z4, Canada
基金
美国国家科学基金会;
关键词
~Adversarial learning; adversarial training; high-dimensional statistics; optimization;
D O I
10.1109/TNNLS.2023.3290592
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training using empirical risk minimization (ERM) is the state-of-the-art method for defense against adversarial attacks, that is, against small additive adversarial perturbations applied to test data leading to misclassification. Despite being successful in practice, understanding the generalization properties of adversarial training in classification remains widely open. In this article, we take the first step in this direction by precisely characterizing the robustness of adversarial training in binary linear classification. Specifically, we consider the high-dimensional regime where the model dimension grows with the size of the training set at a constant ratio. Our results provide exact asymptotics for both standard and adversarial test errors under general lq-norm bounded perturbations (q = 1) in both discriminative binary models and generative Gaussian-mixture models with correlated features. We use our sharp error formulae to explain how the adversarial and standard errors depend upon the over-parameterization ratio, the data model, and the attack budget. Finally, by comparing with the robust Bayes estimator, our sharp asymptotics allow us to study the fundamental limits of adversarial training.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [41] Parameter Interpolation Adversarial Training for Robust Image Classification
    Liu, Xin
    Yang, Yichen
    He, Kun
    Hopcroft, John E.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 1613 - 1623
  • [42] Improved Text Classification via Contrastive Adversarial Training
    Pan, Lin
    Hang, Chung-Wei
    Sil, Avi
    Potdar, Saloni
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 11130 - 11138
  • [43] Existence and Minimax Theorems for Adversarial Surrogate Risks in Binary Classification
    Frank, Natalie S.
    Niles-Weed, Jonathan
    JOURNAL OF MACHINE LEARNING RESEARCH, 2024, 25
  • [44] Spectral classification by generative adversarial linear discriminant analysis
    Cao, Ziyi
    Zhang, Shijie
    Liu, Youlin
    Smith, Casey J.
    Sherman, Alex M.
    Hwang, Yechan
    Simpson, Garth J.
    ANALYTICA CHIMICA ACTA, 2023, 1261
  • [45] Hierarchical gated recurrent neural network with adversarial and virtual adversarial training on text classification
    Poon, Hoon-Keng
    Yap, Wun-She
    Tee, Yee-Kai
    Lee, Wai-Kong
    Goi, Bok-Min
    NEURAL NETWORKS, 2019, 119 : 299 - 312
  • [46] Multiclass and binary SVM classification: Implications for training and classification users
    Mathur, A.
    Foody, G. M.
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2008, 5 (02) : 241 - 245
  • [47] On the Classification and Asymptotic Behavior of the Symmetric Capillary Surfaces
    Bagley, Zachary
    Treinen, Ray
    EXPERIMENTAL MATHEMATICS, 2018, 27 (02) : 215 - 229
  • [48] Classification of Asymptotic Behavior in a Stochastic SIR Model
    Dieu, N. T.
    Nguyen, D. H.
    Du, N. H.
    Yin, G.
    SIAM JOURNAL ON APPLIED DYNAMICAL SYSTEMS, 2016, 15 (02): : 1062 - 1084
  • [49] Incremental and Decremental Training for Linear Classification
    Tsai, Cheng-Hao
    Lin, Chieh-Yen
    Lin, Chih-Jen
    PROCEEDINGS OF THE 20TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING (KDD'14), 2014, : 343 - 352
  • [50] Asymptotic Behavior of Linear Evolution Difference System
    Zada, Akbar
    Li, Tongxing
    Arif, Muhammad
    PUNJAB UNIVERSITY JOURNAL OF MATHEMATICS, 2015, 47 (01): : 119 - 125