Asymptotic Behavior of Adversarial Training in Binary Classification
arXiv:2010.13275
Abstract
It has been consistently reported that many machine learning models are susceptible to adversarial attacks i.e., small additive adversarial perturbations applied to data points can cause misclassification. Adversarial training using empirical risk minimization is considered to be the state-of-the-art method for defense against adversarial attacks. Despite being successful in practice, several problems in understanding generalization performance of adversarial training remain open. In this paper, we derive precise theoretical predictions for the performance of adversarial training in binary classification. We consider the high-dimensional regime where the dimension of data grows with the size of the training data-set at a constant ratio. Our results provide exact asymptotics for standard and adversarial test errors of the estimators obtained by adversarial training with -norm bounded perturbations () for both discriminative binary models and generative Gaussian-mixture models with correlated features. Furthermore, we use these sharp predictions to uncover several intriguing observations on the role of various parameters including the over-parameterization ratio, the data model, and the attack budget on the adversarial and standard errors.
V3: additional theoretical results, extensions to correlated features
References in corpus (14)
- Theoretically Principled Trade-off between Robustness and Accuracy
- A framework to characterize performance of LASSO algorithms
- The generalization error of max-margin linear classifiers: Benign overfitting and high dimensional asymptotics in the overparametrized regime
- Various thresholds for -optimization in compressed sensing
- Understanding and Mitigating the Tradeoff Between Robustness and Accuracy
- The Curious Case of Adversarially Robust Models: More Data Can Help, Double Descend, or Hurt Generalization
- Opportunities and Challenges in Deep Learning Adversarial Robustness: A Survey
- Fundamental Limits of Ridge-Regularized Empirical Risk Minimization in High Dimensions
- Precise Tradeoffs in Adversarial Training for Linear Regression
- On the Generalization Properties of Adversarial Training
- Convergence and Margin of Adversarial Training on Separable Data
- Universality in Learning from Linear Measurements
- Sharp Asymptotics and Optimal Performance for Inference in Binary Models
- Sharp Statistical Guarantees for Adversarially Robust Gaussian Classification