Robustness for Non-Parametric Classification: A Generic Attack and Defense

被引:0
|
作者
Yang, Yao-Yuan [1 ]
Rashtchian, Cyrus [1 ]
Wang, Yizhen [1 ]
Chaudhuri, Kamalika [1 ]
机构
[1] Univ Calif San Diego, Comp Sci & Engn, San Diego, CA 92103 USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarially robust machine learning has received much recent attention. However, prior attacks and defenses for non-parametric classifiers have been developed in an ad-hoc or classifier-specific basis. In this work, we take a holistic look at adversarial examples for non-parametric classifiers, including nearest neighbors, decision trees, and random forests. We provide a general defense method, adversarial pruning, that works by preprocessing the dataset to become well-separated. To test our defense, we provide a novel attack that applies to a wide range of non-parametric classifiers. Theoretically, we derive an optimally robust classifier, which is analogous to the Bayes Optimal. We show that adversarial pruning can be viewed as a finite sample approximation to this optimal classifier. We empirically show that our defense and attack are either better than or competitive with prior work on non-parametric classifiers. Overall, our results provide a strong and broadly-applicable baseline for future work on robust non-parametrics.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Adversarial Attack and Defense for Non-Parametric Two-Sample Tests
    Xu, Xilie
    Zhang, Jingfeng
    Liu, Feng
    Sugiyama, Masashi
    Kankanhalli, Mohan
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [2] A NON-PARAMETRIC STATISTICS BASED METHOD FOR GENERIC CURVE PARTITION AND CLASSIFICATION
    Hu, Gang
    Gao, Qigang
    [J]. 2010 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, 2010, : 3041 - 3044
  • [3] Non-Parametric Calibration for Classification
    Wenger, Jonathan
    Kjellstroem, Hedvig
    Triebel, Rudolph
    [J]. INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 108, 2020, 108
  • [4] A non-parametric approach to extending generic binary classifiers for multi-classification
    Santhanam, Venkataraman
    Morariu, Vlad I.
    Harwood, David
    Davis, Larry S.
    [J]. PATTERN RECOGNITION, 2016, 58 : 149 - 158
  • [5] Consistent Non-Parametric Methods for Maximizing Robustness
    Bhattacharjee, Robi
    Chaudhuri, Kamalika
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [6] Robustness of the parametric MLSE algorithm against non-parametric channels
    Chen, JT
    [J]. GLOBECOM 98: IEEE GLOBECOM 1998 - CONFERENCE RECORD, VOLS 1-6: THE BRIDGE TO GLOBAL INTEGRATION, 1998, : 142 - 147
  • [7] Non-parametric time series classification
    Lenser, S
    Veloso, M
    [J]. 2005 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA), VOLS 1-4, 2005, : 3918 - 3923
  • [8] Non-parametric classification of mamographic lesions
    Bonta, DV
    Giger, ML
    Lan, L
    [J]. RADIOLOGY, 2002, 225 : 498 - 498
  • [9] Supervised parametric and non-parametric classification of chromosome images
    Sampat, MP
    Bovik, AC
    Aggarwal, JK
    Castleman, KR
    [J]. PATTERN RECOGNITION, 2005, 38 (08) : 1209 - 1223
  • [10] Experimental comparison of parametric, non-parametric, and hybrid multigroup classification
    Pai, Dinesh R.
    Lawrence, Kenneth D.
    Klimberg, Ronald K.
    Lawrence, Sheila M.
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2012, 39 (10) : 8593 - 8603