English

Adversarially Robust PAC Learnability of Real-Valued Functions

Machine Learning 2024-05-07 v3 Machine Learning

Abstract

We study robustness to test-time adversarial attacks in the regression setting with p\ell_p losses and arbitrary perturbation sets. We address the question of which function classes are PAC learnable in this setting. We show that classes of finite fat-shattering dimension are learnable in both realizable and agnostic settings. Moreover, for convex function classes, they are even properly learnable. In contrast, some non-convex function classes provably require improper learning algorithms. Our main technique is based on a construction of an adversarially robust sample compression scheme of a size determined by the fat-shattering dimension. Along the way, we introduce a novel agnostic sample compression scheme for real-valued functions, which may be of independent interest.

Keywords

Cite

@article{arxiv.2206.12977,
  title  = {Adversarially Robust PAC Learnability of Real-Valued Functions},
  author = {Idan Attias and Steve Hanneke},
  journal= {arXiv preprint arXiv:2206.12977},
  year   = {2024}
}

Comments

accepted to ICML2023

R2 v1 2026-06-24T12:04:35.458Z