NeurIPS 2020poster42 citations
Reducing Adversarially Robust Learning to Non-Robust PAC Learning
Omar Montasser, Steve Hanneke, Nati Srebro
Abstract
We study the problem of reducing adversarially robust learning to standard PAC learning, i.e. the complexity of learning adversarially robust predictors using access to only a black-box non-robust learner. We give a reduction that can robustly learn any hypothesis class C using any non-robust learner A for C. The number of calls to A depends logarithmically on the number of allowed adversarial perturbations per example, and we give a lower bound showing this is unavoidable.
BibTeX
@inproceedings{NEURIPS2020_a822554e,
author = {Montasser, Omar and Hanneke, Steve and Srebro, Nati},
booktitle = {Advances in Neural Information Processing Systems},
editor = {H. Larochelle and M. Ranzato and R. Hadsell and M.F. Balcan and H. Lin},
pages = {14626--14637},
publisher = {Curran Associates, Inc.},
title = {Reducing Adversarially Robust Learning to Non-Robust PAC Learning},
url = {https://proceedings.neurips.cc/paper_files/paper/2020/file/a822554e5403b1d370db84cfbc530503-Paper.pdf},
volume = {33},
year = {2020}
}