We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

stat

Change to browse by:

References & Citations

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo ScienceWISE logo

Computer Science > Machine Learning

Title: The Geometry of Adversarial Training in Binary Classification

Abstract: We establish an equivalence between a family of adversarial training problems for non-parametric binary classification and a family of regularized risk minimization problems where the regularizer is a nonlocal perimeter functional. The resulting regularized risk minimization problems admit exact convex relaxations of the type $L^1+$ (nonlocal) $\operatorname{TV}$, a form frequently studied in image analysis and graph-based learning. A rich geometric structure is revealed by this reformulation which in turn allows us to establish a series of properties of optimal solutions of the original problem, including the existence of minimal and maximal solutions (interpreted in a suitable sense), and the existence of regular solutions (also interpreted in a suitable sense). In addition, we highlight how the connection between adversarial training and perimeter minimization problems provides a novel, directly interpretable, statistical motivation for a family of regularized risk minimization problems involving perimeter/total variation. The majority of our theoretical results are independent of the distance used to define adversarial attacks.
Subjects: Machine Learning (cs.LG); Analysis of PDEs (math.AP); Metric Geometry (math.MG); Optimization and Control (math.OC); Machine Learning (stat.ML)
MSC classes: 62G35, 49Q20, 68Q32, 65J20
Cite as: arXiv:2111.13613 [cs.LG]
  (or arXiv:2111.13613v1 [cs.LG] for this version)

Submission history

From: Leon Bungert [view email]
[v1] Fri, 26 Nov 2021 17:19:50 GMT (492kb,D)

Link back to: arXiv, form interface, contact.