On the Generalization Analysis of Adversarial Learning

被引:0
|
作者
Mustafa, Waleed [1 ]
Lei, Yunwen [2 ]
Kloft, Marius [1 ]
机构
[1] Univ Kaiserslautern, Dept Comp Sci, Kaiserslautern, Germany
[2] Univ Birmingham, Sch Comp Sci, Birmingham, W Midlands, England
关键词
BOUNDS;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many recent studies have highlighted the susceptibility of virtually all machine-learning models to adversarial attacks. Adversarial attacks are imperceptible changes to an input example of a given prediction model. Such changes are carefully designed to alter the otherwise correct prediction of the model. In this paper, we study the generalization properties of adversarial learning. In particular, we derive high-probability generalization bounds on the adversarial risk in terms of the empirical adversarial risk, the complexity of the function class, and the adversarial noise set. Our bounds are generally applicable to many models, losses, and adversaries. We showcase its applicability by deriving adversarial generalization bounds for the multi-class classification setting and various prediction models (including linear models and Deep Neural Networks). We also derive optimistic adversarial generalization bounds for the case of smooth losses. These are the first fast-rate bounds valid for adversarial deep learning to the best of our knowledge.
引用
收藏
页数:23
相关论文
共 50 条
  • [31] Enhancing Generalization in Few-Shot Learning for Detecting Unknown Adversarial Examples
    Liu, Wenzhao
    Zhang, Wanli
    Yang, Kuiwu
    Chen, Yue
    Guo, Kaiwei
    Wei, Jianghong
    NEURAL PROCESSING LETTERS, 2024, 56 (02)
  • [32] Generalization Analysis on Learning with a Concurrent Verifier
    Nishino, Masaaki
    Nakamura, Kengo
    Yasuda, Norihito
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35, NEURIPS 2022, 2022,
  • [33] Active learning using Generative Adversarial Networks for improving generalization and avoiding distractor points
    Lim, Heechul
    Chon, Kang-Wook
    Kim, Min-Soo
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 227
  • [34] Adversarial learning and decomposition-based domain generalization for face anti-spoofing
    Liu, Mingxin
    Mu, Jiong
    Yu, Zitong
    Ruan, Kun
    Shu, Baiyi
    Yang, Jie
    PATTERN RECOGNITION LETTERS, 2022, 155 : 171 - 177
  • [35] On the Role of Generalization in Transferability of Adversarial Examples
    Wang, Yilin
    Farnia, Farzan
    UNCERTAINTY IN ARTIFICIAL INTELLIGENCE, 2023, 216 : 2259 - 2270
  • [36] Privacy protection generalization with adversarial fusion
    Wang, Hao
    Sun, Guangmin
    Zheng, Kun
    Li, Hui
    Liu, Jie
    Bai, Yu
    MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2022, 19 (07) : 7314 - 7336
  • [37] Aliasing and adversarial robust generalization of CNNs
    Julia Grabinski
    Janis Keuper
    Margret Keuper
    Machine Learning, 2022, 111 : 3925 - 3951
  • [38] Adversarial data splitting for domain generalization
    Gu, Xiang
    Sun, Jian
    Xu, Zongben
    SCIENCE CHINA-INFORMATION SCIENCES, 2024, 67 (05)
  • [39] Adversarial data splitting for domain generalization
    Xiang Gu
    Jian Sun
    Zongben Xu
    Science China Information Sciences, 2024, 67
  • [40] Feature Stylization Adversarial Domain Generalization
    Hu, Zhengzhong
    2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,