Skip to main content
QUICK REVIEW

[論文レビュー] Computational Limitations in Robust Classification and Win-Win Results

Akshay Degwekar, Preetum Nakkiran|arXiv (Cornell University)|Feb 4, 2019
Cryptography and Data Security参考文献 39被引用数 7
ひとこと要約

この論文は、標準的な暗号的仮定のもとで、ロバストな分類器を学習する際の計算的制限を確立している。具体的には、効率的なロバストな分類器が存在する場合でさえ、それが証明的に難しいことを示している。この研究は、Win-Winの状況を明らかにしている:もしあるロバストな分類器が効率的に学習可能であれば、あるいは、ロバスト学習の難易度から、ワンウェイ関数や公開鍵暗号といった新しい暗号的プリミティブを構築できる。

ABSTRACT

We continue the study of statistical/computational tradeoffs in learning robust classifiers, following the recent work of Bubeck, Lee, Price and Razenshteyn who showed examples of classification tasks where (a) an efficient robust classifier exists, in the small-perturbation regime; (b) a non-robust classifier can be learned efficiently; but (c) it is computationally hard to learn a robust classifier, assuming the hardness of factoring large numbers. The question of whether a robust classifier for their task exists in the large perturbation regime seems related to important open questions in computational number theory. In this work, we extend their work in three directions. First, we demonstrate classification tasks where computationally efficient robust classification is impossible, even when computationally unbounded robust classifiers exist. For this, we rely on the existence of average-case hard functions. Second, we show hard-to-robustly-learn classification tasks in the large-perturbation regime. Namely, we show that even though an efficient classifier that is robust to large perturbations exists, it is computationally hard to learn any non-trivial robust classifier. Our first construction relies on the existence of one-way functions, and the second on the hardness of the learning parity with noise problem. In the latter setting, not only does a non-robust classifier exist, but also an efficient algorithm that generates fresh new labeled samples given access to polynomially many training examples (termed as generation by Kearns et. al. (1994)). Third, we show that any such counterexample implies the existence of cryptographic primitives such as one-way functions. This leads us to a win-win scenario: either we can learn an efficient robust classifier, or we can construct new instances of cryptographic primitives.

研究の動機と目的

  • 敵対的摂動が存在する状況下でのロバストな分類器を学習する際の計算複雑性を調査すること。
  • ロバストな分類器が存在するが、計算的に効率的な学習が不可能である条件を特定すること、すなわち、それらが計算的に効率的である場合でさえも。
  • ロバスト学習の難易度と基本的な暗号的プリミティブの存在との間の関係を確立すること。
  • 最小限の仮定のもとで、先行研究の統計的・計算的トレードオフの枠組みを拡張し、新たな構成を提供すること。

提案手法

  • 平均的困難な関数を用い、暗号的仮定を一切用いずに、ロバストな分類器が存在するが、それを学習することが計算的に困難な分類タスクを構築する。
  • 学習パリティノイズ(LPN)問題と学習誤差(LWE)を用いて、効率的なロバストな分類器が存在するが、それを効率的に学習できないタスクを構築する。
  • 効率的なロバストな分類器が学習できない場合、差分の識別可能性を用いた還元により、ワンウェイ関数が存在することを示す。
  • 偽乱関数とエラー訂正符号を用いて、学習が困難なロバストな分類タスクを構築する。
  • 全変動距離と統計的区別不能性を用いて、摂動によって誘発される分布の間の分離を形式化する。
  • ミニマックス論法を用いて、時間制限付きの普遍的摂動敵を構築し、敵対的ロバスト性と暗号的セキュリティを結びつける。

実験結果

リサーチクエスチョン

  • RQ1ロバストな分類器が存在し、計算的に効率的である場合でも、それらを効率的に学習することは可能か?
  • RQ2ロバストな分類器の学習が証明的に困難になる最小限の計算的仮定は何か?
  • RQ3ロバスト学習の難易度と暗号的プリミティブの存在との間に、関係があるか?
  • RQ4ロバストな分類器が計算的に効率的であるにもかかわらず、効率的に学習できない分類タスクを構築できるか?
  • RQ5平均的困難さと擬似乱数性は、ロバスト分類の計算的制限において、果たす役割は何か?

主な発見

  • この論文は、暗号的仮定を一切用いずに、平均的困難な関数の存在を仮定するだけで、ロバストな分類器が存在するが、計算的に学習が困難な分類タスクを構築している。
  • 学習パリティノイズ(LPN)仮定のもとで、効率的なロバストな分類器が存在するが、非ロバストな分類器が学習可能であっても、それを効率的に学習することはできないことが示されている。
  • 学習が困難なロバストな分類器が存在するならば、ワンウェイ関数が存在することを示しており、Win-Winの結果を確立している:もしあるロバスト学習が効率的であるか、あるいは、新しい暗号的プリミティブを構築できる。
  • 摂動された分布 $D'_0$ と $D'_1$ 間の全変動距離は 0.8 以上であり、統計的に区別可能であるが、どの効率的アルゴリズムでもそれらを区別できないため、計算的に区別不能である。
  • ロバストな分類器は摂動された分布の間の識別器として機能し、得られる統計的分離と計算的区別不能性の両方が、ワンウェイ関数の存在を示唆している。
  • 摂動敵が少なくとも 0.4 の確率で敵対的例を発見できる場合、ワンウェイ関数が存在することを示しており、敵対的ロバスト性と基本的な暗号理論を結びつけている。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。