A fundamental problem in robust learning is asymmetry: a learner needs to correctly classify every one of exponentially-many perturbations that an adversary might make to a test-time natural example. In contrast, the attacker only needs to find one successful perturbation. Xiang et al.[2022] proposed an algorithm that in the context of patch attacks for image classification, reduces the effective number of perturbations from an exponential to a polynomial number of perturbations and learns using an ERM oracle. However, to achieve its guarantee, their algorithm requires the natural examples to be robustly realizable. This prompts the natural question; can we extend their approach to the non-robustly-realizable case where there is no classifier with zero robust error? Our first contribution is to answer this question affirmatively by reducing this problem to a setting in which an algorithm proposed by Feige et al.[2015] can be applied, and in the process extend their guarantees. Next, we extend our results to a multi-group setting and introduce a novel agnostic multi-robust learning problem where the goal is to learn a predictor that achieves low robust loss on a (potentially) rich collection of subgroups.
翻译:鲁棒学习中的一个基本问题是不对称性:学习者需要正确分类对手在测试时可能对自然样本进行的指数级数量的扰动中的每一个。相反,攻击者只需要找到一个成功的扰动。Xiang等人[2022]提出了一种算法,该算法在图像分类的补丁攻击场景中,将有效扰动数量从指数级减少到多项式级,并通过ERM预言机进行学习。然而,为了实现其保证,该算法要求自然样本是鲁棒可实现的。这自然引发了一个问题:我们能否将他们的方法扩展到非鲁棒可实现的情况,即不存在具有零鲁棒误差的分类器的情况?我们的第一个贡献是通过将该问题简化为Feige等人[2015]提出的算法可应用的设置,并在该过程中扩展其保证,从而肯定地回答了这个问题。接下来,我们将结果扩展到多组设置,并引入一个新的非不可知多鲁棒学习问题,其目标是在(可能)丰富的子组集合上学习一个具有低鲁棒损失的预测器。