In this paper, we investigate the impact of test-time adversarial attacks on linear regression models and determine the optimal level of robustness that any model can reach while maintaining a given level of standard predictive performance (accuracy). Through quantitative estimates, we uncover fundamental tradeoffs between adversarial robustness and accuracy in different regimes. We obtain a precise characterization which distinguishes between regimes where robustness is achievable without hurting standard accuracy and regimes where a tradeoff might be unavoidable. Our findings are empirically confirmed with simple experiments that represent a variety of settings. This work applies to feature covariance matrices and attack norms of any nature, and extends beyond previous works in this area.
翻译:本文研究了测试时对抗攻击对线性回归模型的影响,并确定了任何模型在保持给定标准预测性能(精度)水平下所能达到的最优鲁棒性。通过定量估计,我们揭示了不同场景中对抗鲁棒性与精度之间的基本权衡。我们获得了精确的特征描述,区分了鲁棒性可在不损害标准精度的情况下实现的场景与可能需要权衡的场景。我们的发现通过代表多种设置的简单实验得到了实证确认。本工作适用于任何性质的特征协方差矩阵与攻击范数,并超越了该领域先前的研究。