← Search

Daniel Cullina

5 accepted papers

2023

Characterizing the Optimal $0-1$ Loss for Multi-class Classification with a Test-time Attacker

NeurIPS 2023spotlight

Finding classifiers robust to adversarial examples is critical for their safe deployment. Determining the robustness of the best possible classifier under a given threat model for a fixed data distribution and comparing it to that achieved by state-of-the-art training methods is thus an important di…

Cited by 4SourcePDFScholar
2021

Lower Bounds on Cross-Entropy Loss in the Presence of Test-time Adversaries

ICML 2021spotlight

Understanding the fundamental limits of robust supervised learning has emerged as a problem of immense interest, from both practical and theoretical standpoints. In particular, it is critical to determine classifier-agnostic bounds on the training loss to establish when learning is possible. In this…

2019

Lower Bounds on Adversarial Robustness from Optimal Transport

NeurIPS 2019poster

While progress has been made in understanding the robustness of machine learning classifiers to test-time adversaries (evasion attacks), fundamental questions remain unresolved. In this paper, we use optimal transport to characterize the maximum achievable accuracy in an adversarial classification s…