db6461eaf0eaeaad1d9c4a70e4818cbd-Supplemental-Conference.pdf
–Neural Information Processing Systems
Weshowaseparation result: on one hand, if the query radiusλis strictly smaller than the adversary's perturbation budgetρ, then distribution-free robust learning is impossible for a widevarietyofconcept classes; ontheotherhand,thesettingλ=ρallowsusto develop robust ERM algorithms.
Neural Information Processing Systems
Feb-12-2026, 07:17:22 GMT