When are Non-Parametric Methods Robust?
Bhattacharjee, Robi, Chaudhuri, Kamalika
A growing body of research has shown that many classifiers are susceptible to {\em{adversarial examples}} -- small strategic modifications to test inputs that lead to misclassification. In this work, we study general non-parametric methods, with a view towards understanding when they are robust to these modifications. We establish general conditions under which non-parametric methods are r-consistent -- in the sense that they converge to optimally robust and accurate classifiers in the large sample limit. Concretely, our results show that when data is well-separated, nearest neighbors and kernel classifiers are r-consistent, while histograms are not. For general data distributions, we prove that preprocessing by Adversarial Pruning (Yang et. al., 2019) -- that makes data well-separated -- followed by nearest neighbors or kernel classifiers also leads to r-consistency.
Mar-13-2020
- Country:
- North America
- United States
- Illinois > Cook County
- Chicago (0.04)
- California
- San Francisco County > San Francisco (0.14)
- Santa Clara County > San Jose (0.04)
- San Diego County > San Diego (0.04)
- Arizona > Maricopa County
- Phoenix (0.04)
- Alaska > Anchorage Municipality
- Anchorage (0.04)
- Illinois > Cook County
- Canada
- Quebec > Montreal (0.04)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.04)
- Alberta > Census Division No. 15
- Improvement District No. 9 > Banff (0.04)
- United States
- Europe
- North America
- Genre:
- Research Report > New Finding (0.68)
- Technology: