A PAC-Bayes Analysis of Adversarial Robustness

02/19/2021
by   Guillaume Vidot, et al.
0

We propose the first general PAC-Bayesian generalization bounds for adversarial robustness, that estimate, at test time, how much a model will be invariant to imperceptible perturbations in the input. Instead of deriving a worst-case analysis of the risk of a hypothesis over all the possible perturbations, we leverage the PAC-Bayesian framework to bound the averaged risk on the perturbations for majority votes (over the whole class of hypotheses). Our theoretically founded analysis has the advantage to provide general bounds (i) independent from the type of perturbations (i.e., the adversarial attacks), (ii) that are tight thanks to the PAC-Bayesian framework, (iii) that can be directly minimized during the learning phase to obtain a robust model on different attacks at test time.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/13/2019

Lower Bounds for Adversarially Robust PAC Learning

In this work, we initiate a formal study of probably approximately corre...
research
11/22/2022

Improving Robust Generalization by Direct PAC-Bayesian Bound Minimization

Recent research in robust optimization has shown an overfitting-like phe...
research
02/17/2021

A General Framework for the Derandomization of PAC-Bayesian Bounds

PAC-Bayesian bounds are known to be tight and informative when studying ...
research
03/28/2015

Risk Bounds for the Majority Vote: From a PAC-Bayesian Analysis to a Learning Algorithm

We propose an extensive analysis of the behavior of majority votes in bi...
research
04/28/2020

Adversarial Learning Guarantees for Linear Hypotheses and Neural Networks

Adversarial or test time robustness measures the susceptibility of a cla...
research
12/06/2020

PAC-Learning for Strategic Classification

Machine learning (ML) algorithms may be susceptible to being gamed by in...
research
06/17/2020

Universal Lower-Bounds on Classification Error under Adversarial Attacks and Random Corruption

We theoretically analyse the limits of robustness to test-time adversari...

Please sign up or login with your details

Forgot password? Click here to reset