Current browse context:
cs
Change to browse by:
References & Citations
Statistics > Machine Learning
Title: Black-box Certification and Learning under Adversarial Perturbations
(Submitted on 30 Jun 2020 (v1), last revised 22 Feb 2022 (this version, v2))
Abstract: We formally study the problem of classification under adversarial perturbations from a learner's perspective as well as a third-party who aims at certifying the robustness of a given black-box classifier. We analyze a PAC-type framework of semi-supervised learning and identify possibility and impossibility results for proper learning of VC-classes in this setting. We further introduce a new setting of black-box certification under limited query budget, and analyze this for various classes of predictors and perturbation. We also consider the viewpoint of a black-box adversary that aims at finding adversarial examples, showing that the existence of an adversary with polynomial query complexity can imply the existence of a sample efficient robust learner.
Submission history
From: Vinayak Pathak [view email][v1] Tue, 30 Jun 2020 04:12:59 GMT (60kb)
[v2] Tue, 22 Feb 2022 15:38:06 GMT (57kb)
Link back to: arXiv, form interface, contact.