English

Is nasty noise actually harder than malicious noise?

Machine Learning 2026-02-18 v2 Computational Complexity Data Structures and Algorithms

Abstract

We consider the relative abilities and limitations of computationally efficient algorithms for learning in the presence of noise, under two well-studied and challenging adversarial noise models for learning Boolean functions: malicious noise, in which an adversary can arbitrarily corrupt a random subset of examples given to the learner; and nasty noise, in which an adversary can arbitrarily corrupt an adversarially chosen subset of examples given to the learner. We consider both the distribution-independent and fixed-distribution settings. Our main results highlight a dramatic difference between these two settings: For distribution-independent learning, we prove a strong equivalence between the two noise models: If a class C{\cal C} of functions is efficiently learnable in the presence of η\eta-rate malicious noise, then it is also efficiently learnable in the presence of η\eta-rate nasty noise. In sharp contrast, for the fixed-distribution setting we show an arbitrarily large separation: Under a standard cryptographic assumption, for any arbitrarily large value rr there exists a concept class for which there is a ratio of rr between the rate ηmalicious\eta_{malicious} of malicious noise that polynomial-time learning algorithms can tolerate, versus the rate ηnasty\eta_{nasty} of nasty noise that such learning algorithms can tolerate. To offset the negative result for the fixed-distribution setting, we define a broad and natural class of algorithms, namely those that ignore contradictory examples (ICE). We show that for these algorithms, malicious noise and nasty noise are equivalent up to a factor of two in the noise rate: Any efficient ICE learner that succeeds with η\eta-rate malicious noise can be converted to an efficient learner that succeeds with η/2\eta/2-rate nasty noise. We further show that the above factor of two is necessary, again under a standard cryptographic assumption.

Keywords

Cite

@article{arxiv.2511.09763,
  title  = {Is nasty noise actually harder than malicious noise?},
  author = {Guy Blanc and Yizhi Huang and Tal Malkin and Rocco A. Servedio},
  journal= {arXiv preprint arXiv:2511.09763},
  year   = {2026}
}

Comments

SODA 2026