Skip to main content
QUICK REVIEW

[논문 리뷰] Calibration and Consistency of Adversarial Surrogate Losses

Pranjal Awasthi, Natalie S. Frank|arXiv (Cornell University)|2021. 04. 19.
Adversarial Robustness in Machine Learning참고 문헌 34인용 수 6
한 줄 요약

이 논문은 강건한 기계학습에서 적대적 서브티튜트 손실의 校정성과 일致성에 대한 엄밀한 이론적 분석을 제공한다. 표준 볼록 서브티튜트 손실이 일반선형모델 및 일층 신경망과 같은 중요한 모델에 대해 ${\mathscr{H}}$-교정되지 않았음을 증명하며, ${\mathscr{H}}$-교정성이 ${\mathscr{H}}$-일치성에 충분하지 않음을 보여준다. 실제로, 분포 가정이 없이선 어떤 연속 서브티튜트 손실도 적대적 설정에서 일치하지 않는다. 저자들은 특정 서브티튜트 손실이 ${\mathscr{H}}$-일치성을 달성할 수 있는 조건을 규명하고, 이들의 발견을 실험적으로 검증한다.

ABSTRACT

Adversarial robustness is an increasingly critical property of classifiers in applications. The design of robust algorithms relies on surrogate losses since the optimization of the adversarial loss with most hypothesis sets is NP-hard. But which surrogate losses should be used and when do they benefit from theoretical guarantees? We present an extensive study of this question, including a detailed analysis of the H-calibration and H-consistency of adversarial surrogate losses. We show that, under some general assumptions, convex loss functions, or the supremum-based convex losses often used in applications, are not H-calibrated for important hypothesis sets such as generalized linear models or one-layer neural networks. We then give a characterization of H-calibration and prove that some surrogate losses are indeed H-calibrated for the adversarial loss, with these hypothesis sets. Next, we show that H-calibration is not sufficient to guarantee consistency and prove that, in the absence of any distributional assumption, no continuous surrogate loss is consistent in the adversarial setting. This, in particular, proves that a claim presented in a COLT 2020 publication is inaccurate. (Calibration results there are correct modulo subtle definition differences, but the consistency claim does not hold.) Next, we identify natural conditions under which some surrogate losses that we describe in detail are H-consistent for hypothesis sets such as generalized linear models and one-layer neural networks. We also report a series of empirical results with simulated data, which show that many H-calibrated surrogate losses are indeed not H-consistent, and validate our theoretical assumptions.

연구 동기 및 목표

  • 적대적 강건 학습에서 이론적 보장을 부족하게 하는 문제, 특히 일반선형모델 및 일층 신경망과 같은 가설 집합에서 강건 분류기 학습을 위한 서브티튜트 손실의 선택에 초점을 맞춘다.
  • 일반적으로 사용되는 볼록 서브티튜트 손실이 일반선형모델 및 일층 신경망과 같은 가설 집합에서 적대적 강건성에 대해 이론적으로 타당한지 조사한다.
  • 표준 일치성 이론이 적용되지 않는 적대적 설정에서 ${\mathscr{H}}$-교정성과 ${\mathscr{H}}$-일치성의 차이를 명확히 한다.
  • 이전 연구(COLT 2020)에서 잘못된 주장(적대적 설정에서 ${\mathscr{H}}$-교정성이 ${\mathscr{H}}$-일치성을 함의한다는 것)을 수정하기 위해, 적대적 설정에서 ${\mathscr{H}}$-교정성이 ${\mathscr{H}}$-일치성을 함의하지 않는다는 것을 증명한다.
  • 핵심 가설 클래스에서 특정 서브티튜트 손실이 ${\mathscr{H}}$-일치성을 달성할 수 있는 자연스러운 분포 및 구조 조건을 규명한다.

제안 방법

  • 저자들은 적대적 손실의 맥락에서 ${\mathscr{H}}$-교정성과 ${\mathscr{H}}$-일치성의 개념을 도입하고 공식화하며, 지역 이웃 행동을 고려하기 위해 표준 정의를 확장한다.
  • 그들은 손실 함수가 $f({\mathbf{x}})$ 뿐 아니라 ${\mathbf{x}}$의 이웃에서의 $f$ 값에도 의존함을 분석하여, 기존의 일치성 추론을 무효화한다.
  • 측도 이론적 도구를 사용하여, 분포 가정이 없이선 어떤 연속 서브티튜트 손실도 적대적 설정에서 ${\mathscr{H}}$-일치하지 않음을 증명하며, 근본적인 이론적 장벽을 확립한다.
  • ${\mathscr{H}}$-교정성에 대한 특성화를 도출하고, 많은 표준 볼록 손실이 핵심 가설 집합에서 이를 충족하지 못함을 보여준다.
  • 특정 데이터 분포의 구조와 손실 기하학적 특성 등의 충분조건을 규명하여, 일부 서브티튜트 손실이 ${\mathscr{H}}$-일치성에 도달할 수 있음을 밝힌다.
  • 시뮬레이션 데이터를 활용한 실험을 통해 이론을 검증하며, ${\mathscr{H}}$-교정성은 갖추고도 ${\mathscr{H}}$-일치성은 달성하지 못하는 경우가 있음을 확인한다.

실험 결과

연구 질문

  • RQ1일반적으로 사용되는 볼록 서브티튜트 손실이 일반선형모델 및 일층 신경망에서 적대적 강건성에 대해 ${\mathscr{H}}$-교정되나?
  • RQ2표준 분류와 마찬가지로, 적대적 설정에서 ${\mathscr{H}}$-교정성이 ${\mathscr{H}}$-일치성을 함의하는가?
  • RQ3분포 가정 없이도 어떤 연속 서브티튜트 손실이 적대적 학습에서 ${\mathscr{H}}$-일치성이 가능한가?
  • RQ4어떤 구조적 또는 분포 조건이 적대적 설정에서 서브티튜트 손실의 ${\mathscr{H}}$-일치성을 가능하게 하는가?
  • RQ5COLT 2020 논문에서 제시한 적대적 서브티튜트 일치성 이론적 주장은 올바른가, 아니면 추론에 결함이 있는가?

주요 결과

  • 일반적인 가정 하에 일반선형모델 또는 일층 신경망에서 볼록 서브티튜트 손실, 특히 최대값 기반 볼록 손실은 ${\mathscr{H}}$-교정되지 않는다.
  • ${\mathscr{H}}$-교정성이 적대적 설정에서 ${\mathscr{H}}$-일치성에 충분하지 않으며, 두 개념은 서로 독립적이고 별개이다.
  • 분포 가정이 없이선 어떤 연속 서브티튜트 손실도 적대적 학습에서 ${\mathscr{H}}$-일치하지 않으며, 이는 근본적인 이론적 제약를 확립한다.
  • COLT 2020 논문에서 제시한 ${\mathscr{H}}$-일치성 주장은 잘못되었으며, 다만 정의의 미세한 차이를 고려하면 교정성 결과는 유효하다.
  • 특정 데이터 분포의 구조와 손실 기하학적 특성 등의 자연스러운 조건 하에서, 일부 서브티튜트 손실은 일반선형모델 및 일층 신경망에서 ${\mathscr{H}}$-일치성을 달성할 수 있다.
  • 시뮬레이션 데이터에 대한 실험 결과는 많은 ${\mathscr{H}}$-교정 서브티튜트 손실이 ${\mathscr{H}}$-일치하지 않음을 확인하며, 이는 이론적 가정과 결과를 검증한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.