ICML 2022spotlight19 citations

Provably Adversarially Robust Nearest Prototype Classifiers

Václav Voráček, Matthias Hein

Abstract

Nearest prototype classifiers (NPCs) assign to each input point the label of the nearest prototype with respect to a chosen distance metric. A direct advantage of NPCs is that the decisions are interpretable. Previous work could provide lower bounds on the minimal adversarial perturbation in the $\ell_p$-threat model when using the same $\ell_p$-distance for the NPCs. In this paper we provide a complete discussion on the complexity when using $\ell_p$-distances for decision and $\ell_q$-threat models for certification for $p,q \in \{1,2,\infty\}$. In particular we provide scalable algorithms for the

BibTeX
@InProceedings{pmlr-v162-voracek22a,
  title = 	 {Provably Adversarially Robust Nearest Prototype Classifiers},
  author =       {Vor{\'a}{\v{c}}ek, V{\'a}clav and Hein, Matthias},
  booktitle = 	 {Proceedings of the 39th International Conference on Machine Learning},
  pages = 	 {22361--22383},
  year = 	 {2022},
  editor = 	 {Chaudhuri, Kamalika and Jegelka, Stefanie and Song, Le and Szepesvari, Csaba and Niu, Gang and Sabato, Sivan},
  volume = 	 {162},
  series = 	 {Proceedings of Machine Learning Research},
  month = 	 {17--23 Jul},
  publisher =    {PMLR},
  pdf = 	 {https://proceedings.mlr.press/v162/voracek22a/voracek22a.pdf},
  url = 	 {https://proceedings.mlr.press/v162/voracek22a.html},
  abstract = 	 {Nearest prototype classifiers (NPCs) assign to each input point the label of the nearest prototype with respect to a chosen distance metric. A direct advantage of NPCs is that the decisions are interpretable. Previous work could provide lower bounds on the minimal adversarial perturbation in the $\ell_p$-threat model when using the same $\ell_p$-distance for the NPCs. In this paper we provide a complete discussion on the complexity when using $\ell_p$-distances for decision and $\ell_q$-threat models for certification for $p,q \in \{1,2,\infty\}$. In particular we provide scalable algorithms for the
Provably Adversarially Robust Nearest Prototype Classifiers · ICML 2022