2021/04/19 by Difan Zou, Zou, Difan, Spencer Frei +3 · 2 citations
Computer Science · Engineering · #Adversarial Robustness in Machine Learning #Fault Detection and Control Systems
paper · pdf · doi:10.48550/arxiv.2104.09437
We analyze the properties of adversarial training for learning adversarially\nrobust halfspaces in the presence of agnostic label noise. Denoting\n\OPTp,r as the best robust classification error achieved by a\nhalfspace that is robust to perturbations of \ℓp balls of radius r, we\nshow that adversarial training on the standard binary cross-entropy loss yields\nadversarially robust halfspaces up to (robust) classification error nO(\√\OPT2,r) for p=2, and O(d1/4\n\√\OPT\∞, r + d1/2 \OPT\∞,r) when\np=\∞. Our results hold for distributions satisfying anti-concentration\nproperties enjoyed by log-concave isotropic distributions among others. We\nadditionally show that if one instead uses a nonconvex sigmoidal loss,\nadversarial training yields halfspaces with an improved robust classification\nerror of O(\OPT2,r) for p=2, and O(d1/4\OPT\∞,\nr) when p=\∞. To the best of our knowledge, this is the first work to\nshow that adversarial training provably yields robust classifiers in the\npresence of noise.\n