A Le Cam Type Bound for Adversarial Learning and Applications
arXiv:2007.00289
Abstract
Robustness of machine learning methods is essential for modern practical applications. Given the arms race between attack and defense methods, one may be curious regarding the fundamental limits of any defense mechanism. In this work, we focus on the problem of learning from noise-injected data, where the existing literature falls short by either assuming a specific attack method or by over-specifying the learning problem. We shed light on the information-theoretic limits of adversarial learning without assuming a particular learning process or attacker. Finally, we apply our general bounds to a canonical set of non-trivial learning problems and provide examples of common types of attacks.
10 pages
References in corpus (6)
- Certifying Some Distributional Robustness with Principled Adversarial Training
- Adversarial Attacks on Node Embeddings via Graph Poisoning
- Adversarial Examples for Semantic Image Segmentation
- VC Classes are Adversarially Robustly Learnable, but Only Improperly
- Theoretical evidence for adversarial robustness through randomization
- Robust Nonparametric Regression under Huber's -contamination Model