vix.ing · top · new · best · stats · spec

Robust Attacks against Multiple Classifiers

2019/06/06 by Juan C. Perdomo, Yaron Singer, Perdomo, Juan C. +1 · 1 citation
Computer Science · #Adversarial Robustness in Machine Learning #Computer Science and Game Theory (cs.GT) #Cryptography and Security (cs.CR) #Domain Adaptation and Few-Shot Learning #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Machine Learning and Algorithms

paper · pdf · doi:10.48550/arxiv.1906.02816

openalex publication_date 2019/06/06 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

We address the challenge of designing optimal adversarial noise algorithms for settings where a learner has access to multiple classifiers. We demonstrate how this problem can be framed as finding strategies at equilibrium in a two-player, zero-sum game between a learner and an adversary. In doing so, we illustrate the need for randomization in adversarial attacks. In order to compute Nash equilibrium, our main technical focus is on the design of best response oracles that can then be implemented within a Multiplicative Weights Update framework to boost deterministic perturbations against a set of models into optimal mixed strategies. We demonstrate the practical effectiveness of our approach on a series of image classification tasks using both linear classifiers and deep neural networks.

Citations

Cited by

Related