Skip to main content
QUICK REVIEW

[论文解读] Computational Limitations in Robust Classification and Win-Win Results

Akshay Degwekar, Preetum Nakkiran|arXiv (Cornell University)|Feb 4, 2019
Cryptography and Data Security参考文献 39被引用 7
一句话总结

本文通过证明在标准密码学假设下,学习鲁棒分类器在计算上可能是难以解决的,即使存在高效的鲁棒分类器,从而确立了学习鲁棒分类器的计算局限性。它揭示了一个双赢局面:要么可以高效学习鲁棒分类器,要么可从鲁棒学习的困难性出发构造出新的密码学原原子,如单向函数或公钥加密。

ABSTRACT

We continue the study of statistical/computational tradeoffs in learning robust classifiers, following the recent work of Bubeck, Lee, Price and Razenshteyn who showed examples of classification tasks where (a) an efficient robust classifier exists, in the small-perturbation regime; (b) a non-robust classifier can be learned efficiently; but (c) it is computationally hard to learn a robust classifier, assuming the hardness of factoring large numbers. The question of whether a robust classifier for their task exists in the large perturbation regime seems related to important open questions in computational number theory. In this work, we extend their work in three directions. First, we demonstrate classification tasks where computationally efficient robust classification is impossible, even when computationally unbounded robust classifiers exist. For this, we rely on the existence of average-case hard functions. Second, we show hard-to-robustly-learn classification tasks in the large-perturbation regime. Namely, we show that even though an efficient classifier that is robust to large perturbations exists, it is computationally hard to learn any non-trivial robust classifier. Our first construction relies on the existence of one-way functions, and the second on the hardness of the learning parity with noise problem. In the latter setting, not only does a non-robust classifier exist, but also an efficient algorithm that generates fresh new labeled samples given access to polynomially many training examples (termed as generation by Kearns et. al. (1994)). Third, we show that any such counterexample implies the existence of cryptographic primitives such as one-way functions. This leads us to a win-win scenario: either we can learn an efficient robust classifier, or we can construct new instances of cryptographic primitives.

研究动机与目标

  • 研究在存在对抗性扰动的情况下,学习鲁棒分类器的计算复杂性。
  • 识别出即使鲁棒分类器存在且计算高效,也无法被高效学习的条件。
  • 建立鲁棒学习困难性与基本密码学原原子存在性之间的联系。
  • 通过在最小假设下提供新构造,扩展先前关于鲁棒分类中统计-计算权衡的研究。

提出的方法

  • 构建了鲁棒分类器存在但计算上难以学习的分类任务,依赖于平均情况困难函数,且无需密码学假设。
  • 利用学习带噪声的奇偶性(LPN)问题和学习误差(LWE)问题,构建了存在高效鲁棒分类器但难以学习的任务。
  • 证明了若无法高效学习鲁棒分类器,则必须存在单向函数,通过从扰动分布可区分性出发的归约实现。
  • 应用伪随机函数和纠错码,构造难以学习的鲁棒分类任务。
  • 使用总变差距离和统计不可区分性,形式化了由扰动诱导的分布之间的分离。
  • 采用极小-极大论证,构建时间有界的通用扰动对抗者,将对抗鲁棒性与密码学安全性联系起来。

实验结果

研究问题

  • RQ1即使鲁棒分类器存在且计算高效,是否仍可高效学习鲁棒分类器?
  • RQ2在何种最小计算假设下,学习鲁棒分类器将被证明是计算困难的?
  • RQ3鲁棒学习的困难性与密码学原原子的存在性之间是否存在联系?
  • RQ4能否构造出即使访问到高效鲁棒分类器,其鲁棒性仍计算上不可学习的分类任务?
  • RQ5平均情况困难性和伪随机性在鲁棒分类计算限制中起什么作用?

主要发现

  • 本文在仅假设存在平均情况困难函数的前提下,构建了鲁棒分类器存在但计算上难以学习的分类任务,且无需密码学假设。
  • 在学习带噪声的奇偶性(LPN)假设下,即使存在高效鲁棒分类器,也无法被高效学习,尽管非鲁棒分类器可以被学习。
  • 难以学习的鲁棒分类器的存在意味着单向函数的存在,从而建立了双赢结果:要么鲁棒学习是高效的,要么可构造出新的密码学原原子。
  • 扰动分布 $D'_0$ 和 $D'_1$ 之间的总变差距离至少为 0.8,表明具有统计可区分性,而没有任何高效算法能区分它们,意味着计算不可区分性。
  • 鲁棒分类器充当了对扰动分布的区分器,而由此产生的统计分离与计算不可区分性相结合,意味着单向函数的存在。
  • 本文表明,若扰动对抗者能以至少 0.4 的概率找到对抗样本,则单向函数存在,从而将对抗鲁棒性与基础密码学联系起来。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。