English

Adversarial Robustness: What fools you makes you stronger

Machine Learning 2021-02-19 v2 Cryptography and Security

Abstract

We prove an exponential separation for the sample complexity between the standard PAC-learning model and a version of the Equivalence-Query-learning model. We then show that this separation has interesting implications for adversarial robustness. We explore a vision of designing an adaptive defense that in the presence of an attacker computes a model that is provably robust. In particular, we show how to realize this vision in a simplified setting. In order to do so, we introduce a notion of a strong adversary: he is not limited by the type of perturbations he can apply but when presented with a classifier can repetitively generate different adversarial examples. We explain why this notion is interesting to study and use it to prove the following. There exists an efficient adversarial-learning-like scheme such that for every strong adversary A\mathbf{A} it outputs a classifier that (a) cannot be strongly attacked by A\mathbf{A}, or (b) has error at most ϵ\epsilon. In both cases our scheme uses exponentially (in ϵ\epsilon) fewer samples than what the PAC bound requires.

Keywords

Cite

@article{arxiv.2102.05475,
  title  = {Adversarial Robustness: What fools you makes you stronger},
  author = {Grzegorz Głuch and Rüdiger Urbanke},
  journal= {arXiv preprint arXiv:2102.05475},
  year   = {2021}
}

Comments

15 pages, 1 figure [V2 - fixed typos]

R2 v1 2026-06-23T23:01:58.954Z