On the Generalization Analysis of Adversarial Learning

被引:0
|
作者
Mustafa, Waleed [1 ]
Lei, Yunwen [2 ]
Kloft, Marius [1 ]
机构
[1] Univ Kaiserslautern, Dept Comp Sci, Kaiserslautern, Germany
[2] Univ Birmingham, Sch Comp Sci, Birmingham, W Midlands, England
来源
INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162 | 2022年
关键词
BOUNDS;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many recent studies have highlighted the susceptibility of virtually all machine-learning models to adversarial attacks. Adversarial attacks are imperceptible changes to an input example of a given prediction model. Such changes are carefully designed to alter the otherwise correct prediction of the model. In this paper, we study the generalization properties of adversarial learning. In particular, we derive high-probability generalization bounds on the adversarial risk in terms of the empirical adversarial risk, the complexity of the function class, and the adversarial noise set. Our bounds are generally applicable to many models, losses, and adversaries. We showcase its applicability by deriving adversarial generalization bounds for the multi-class classification setting and various prediction models (including linear models and Deep Neural Networks). We also derive optimistic adversarial generalization bounds for the case of smooth losses. These are the first fast-rate bounds valid for adversarial deep learning to the best of our knowledge.
引用
收藏
页数:23
相关论文
共 50 条
  • [41] Adversarial data splitting for domain generalization
    Gu, Xiang
    Sun, Jian
    Xu, Zongben
    SCIENCE CHINA-INFORMATION SCIENCES, 2024, 67 (05)
  • [42] Adversarial data splitting for domain generalization
    Xiang Gu
    Jian Sun
    Zongben Xu
    Science China Information Sciences, 2024, 67
  • [43] Adversarial data splitting for domain generalization
    Xiang GU
    Jian SUN
    Zongben XU
    Science China(Information Sciences), 2024, 67 (05) : 28 - 42
  • [44] Aliasing and adversarial robust generalization of CNNs
    Grabinski, Julia
    Keuper, Janis
    Keuper, Margret
    MACHINE LEARNING, 2022, 111 (11) : 3925 - 3951
  • [45] On Generalization of Graph Autoencoders with Adversarial Training
    Huang, Tianjin
    Pei, Yulong
    Menkovski, Vlado
    Pechenizkiy, Mykola
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2021: RESEARCH TRACK, PT II, 2021, 12976 : 367 - 382
  • [46] Feature Stylization Adversarial Domain Generalization
    Hu, Zhengzhong
    2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [47] Adversarial Reconstruction Loss for Domain Generalization
    Bekkouch, Imad Eddine Ibrahim
    Nicolae, Dragos Constantin
    Khan, Adil
    Kazmi, S. M. Ahsan
    Khattak, Asad Masood
    Ibragimov, Bulat
    IEEE ACCESS, 2021, 9 : 42424 - 42437
  • [48] Improving the Generalization of Deep Learning Classification Models in Medical Imaging Using Transfer Learning and Generative Adversarial Networks
    Venu, Sagar Kora
    AGENTS AND ARTIFICIAL INTELLIGENCE, ICAART 2021, 2022, 13251 : 218 - 235
  • [49] Adversarial Deception in Deep Learning: Analysis and Mitigation
    Wei, Wenqi
    Liu, Ling
    Loper, Margaret
    Chow, Ka-Ho
    Gursoy, Mehmet Emre
    Truex, Stacey
    Wu, Yanzhao
    2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 236 - 245
  • [50] Theoretical Analysis of Adversarial Learning: A Minimax Approach
    Tu, Zhuozhuo
    Zhang, Jingwei
    Tao, Dacheng
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32