ICML 2020poster40 citations

When are Non-Parametric Methods Robust?

Robi Bhattacharjee, Kamalika Chaudhuri

Abstract

A growing body of research has shown that many classifiers are susceptible to adversarial examples – small strategic modifications to test inputs that lead to misclassification. In this work, we study general non-parametric methods, with a view towards understanding when they are robust to these modifications. We establish general conditions under which non-parametric methods are r-consistent – in the sense that they converge to optimally robust and accurate classifiers in the large sample limit. Concretely, our results show that when data is well-separated, nearest neighbors and kernel classifiers are r-consistent, while histograms are not. For general data distributions, we prove that preprocessing by Adversarial Pruning (Yang et. al., 2019)– that makes data well-separated – followed by nearest neighbors or kernel classifiers also leads to r-consistency.

BibTeX
@InProceedings{pmlr-v119-bhattacharjee20a,
  title = 	 {When are Non-Parametric Methods Robust?},
  author =       {Bhattacharjee, Robi and Chaudhuri, Kamalika},
  booktitle = 	 {Proceedings of the 37th International Conference on Machine Learning},
  pages = 	 {832--841},
  year = 	 {2020},
  editor = 	 {III, Hal Daumé and Singh, Aarti},
  volume = 	 {119},
  series = 	 {Proceedings of Machine Learning Research},
  month = 	 {13--18 Jul},
  publisher =    {PMLR},
  pdf = 	 {http://proceedings.mlr.press/v119/bhattacharjee20a/bhattacharjee20a.pdf},
  url = 	 {https://proceedings.mlr.press/v119/bhattacharjee20a.html},
  abstract = 	 {A growing body of research has shown that many classifiers are susceptible to adversarial examples – small strategic modifications to test inputs that lead to misclassification. In this work, we study general non-parametric methods, with a view towards understanding when they are robust to these modifications. We establish general conditions under which non-parametric methods are r-consistent – in the sense that they converge to optimally robust and accurate classifiers in the large sample limit. Concretely, our results show that when data is well-separated, nearest neighbors and kernel classifiers are r-consistent, while histograms are not. For general data distributions, we prove that preprocessing by Adversarial Pruning (Yang et. al., 2019)– that makes data well-separated – followed by nearest neighbors or kernel classifiers also leads to r-consistency.}
}
When are Non-Parametric Methods Robust? · ICML 2020