[論文レビュー] Adversarial Learning Guarantees for Linear Hypotheses and Neural Networks
この論文は、$\ell_r$-ノルム摂動下における線形モデルおよびニューラルネットワークの敵対的ラデマッチャー複雑度について、$\ell_\infty$-ロバストネスに関する先行研究を一般化したきわめて鋭い境界を提供する。一般化における次元依存のトレードオフを確立し、線形分類器のための改善された境界を導出し、代理近似を用いない単一のReLUユニットおよび1層隠れ層ネットワークの直接的な境界を提示する。
Adversarial or test time robustness measures the susceptibility of a classifier to perturbations to the test input. While there has been a flurry of recent work on designing defenses against such perturbations, the theory of adversarial robustness is not well understood. In order to make progress on this, we focus on the problem of understanding generalization in adversarial settings, via the lens of Rademacher complexity. We give upper and lower bounds for the adversarial empirical Rademacher complexity of linear hypotheses with adversarial perturbations measured in $l_r$-norm for an arbitrary $r \geq 1$. This generalizes the recent result of [Yin et al.'19] that studies the case of $r = \infty$, and provides a finer analysis of the dependence on the input dimensionality as compared to the recent work of [Khim and Loh'19] on linear hypothesis classes. We then extend our analysis to provide Rademacher complexity lower and upper bounds for a single ReLU unit. Finally, we give adversarial Rademacher complexity bounds for feed-forward neural networks with one hidden layer. Unlike previous works we directly provide bounds on the adversarial Rademacher complexity of the given network, as opposed to a bound on a surrogate. A by-product of our analysis also leads to tighter bounds for the Rademacher complexity of linear hypotheses, for which we give a detailed analysis and present a comparison with existing bounds.
研究の動機と目的
- 敵対的摂動下での一般化を理解する理論的ギャップを埋めること、特に線形モデルおよびニューラルネットワークに焦点を当てる。
- 先行研究が特定のノルム(例:$\ell_\infty$)に限定され、または代理境界に依存するという限界を克服すること。
- 入力次元および摂動ノルムの影響を捉える、データに依存する鋭い敵対的ラデマッチャー複雑度の境界を提供すること。
- ラデマッチャー複雑度を通じて敵対的ロバストネスと一般化の直接的な関連を確立し、より鋭いマージンに基づく一般化境界を可能にすること。
- 解析の副産物として、線形分類器の非敵対的ラデマッチャー複雑度の境界を改善すること。
提案手法
- 任意の$\ell_r$-ノルム摂動($r \geq 1$)下での線形仮説の敵対的経験的ラデマッチャー複雑度の上界および下界を導出。これは、先行の$\ell_\infty$結果を一般化するものである。
- 訓練サンプルの分割と、キンチンケ・カハーヌの不等式を用いて、重みベクトルの重み付き和の$\ell_{p^*}$-ノルムを評価する。
- ラデマッチャー確率変数を用いた新たな敵対的シャッタリングの分析により、次元依存の下界を導出する。
- 双対性およびノルム不等式(例:ホルダーおよびコーシー・シュワルツ)を用いて、敵対的複雑度をデータ行列の$\ell_{p,\infty}$-ノルムに関連付ける。
- 単一のReLUユニットへの応用において、その符号活性化された重みの組み合わせの複雑度を評価する。
- 補助関数に依存しない、1層隠れ層のフィードフォワードネットワークの敵対的ラデマッチャー複雑度に対する直接的な上界を提供する。
実験結果
リサーチクエスチョン
- RQ1線形モデルの敵対的ラデマッチャー複雑度は、入力次元および摂動ノルム$\ell_r$にどのように依存するか?
- RQ2$\ell_r$-摂動下で、敵対的一般化はデータ分布および重みノルムにどのように依存するか?
- RQ3ReLUユニットおよび浅いニューラルネットワークに対して、より鋭くデータに依存する敵対的ラデマッチャー複雑度の境界を導出可能か?
- RQ4敵対的複雑度の境界と非敵対的境界の比較は?次元性はこのギャップにどのように寄与するか?
- RQ5この解析により、標準的(非敵対的)線形分類器の一般化境界が改善可能か?
主な発見
- 線形モデルの敵対的ラデマッチャー複雑度は、$\ell_r$-ノルム摂動下で、入力次元$d$に依存する追加の$\sqrt{d}$項を伴うことが判明。これは次元依存の一般化コストを確認する。
- $r \geq 1$の$\ell_r$-ノルムに対して、$\mathcal{O}(\tau \|X\|_{p,\infty} / \epsilon)$という鋭い上界を導出。ここで$\tau$は最大重みノルム、$\epsilon$は摂動半径である。
- 非敵対的ラデマッチャー複雑度のための新たな改善された境界が得られ、$\sqrt{d}$依存性が先行研究より鋭くなっている。
- 単一のReLUユニットに対しては、敵対的ラデマッチャー複雑度が$\mathcal{O}(\|W^+\|_2 \|\Delta W\|_{p^*} / \epsilon)$で抑えられ、重み構造に明示的な依存性を持つ。
- 1層隠れ層のニューラルネットワークに対しては、補助関数に依存しない直接的な上界が提供され、先行研究を改善している。
- 敵対的シャッタリングの導出された境界は、$t \leq \frac{4c_2^2(p^*)\tau^2\|X\|_{p,\infty}^2}{\epsilon^2 w_{\text{min}}^2}$を示し、次元およびノルムに依存する一般化の限界を示している。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。