Adversarial robustness is a critical property in a variety of modern machine learning applications. While it has been the subject of several recent theoretical studies, many important questions related to adversarial robustness are still open. In this work, we study a fundamental question regarding Bayes optimality for adversarial robustness. We provide general sufficient conditions under which the existence of a Bayes optimal classifier can be guaranteed for adversarial robustness. Our results can provide a useful tool for a subsequent study of surrogate losses in adversarial robustness and their consistency properties. This manuscript is the extended and corrected version of the paper \emph{On the Existence of the Adversarial Bayes Classifier} published in NeurIPS 2021. There were two errors in theorem statements in the original paper -- one in the definition of pseudo-certifiable robustness and the other in the measurability of $A^\e$ for arbitrary metric spaces. In this version we correct the errors. Furthermore, the results of the original paper did not apply to some non-strictly convex norms and here we extend our results to all possible norms.
翻译:对抗鲁棒性是现代机器学习应用中一项关键特性。尽管近期已有若干理论研究涉足此领域,但关于对抗鲁棒性的许多重要问题仍未解决。本文针对对抗鲁棒性的贝叶斯最优性这一基础性问题展开研究,给出了保证对抗鲁棒性情境下贝叶斯最优分类器存在性的普适充分条件。我们的结论可为后续研究对抗鲁棒性中的替代损失函数及其一致性性质提供有效工具。本稿件为发表于NeurIPS 2021的论文《On the Existence of the Adversarial Bayes Classifier》的扩展与修正版本。原论文定理陈述中存在两处错误:其一涉及伪可证鲁棒性定义,其二涉及任意度量空间下$A^\e$的可测性问题。本版本已修正上述错误。此外,原论文结论不适用于部分非严格凸范数,本文已将研究结论推广至所有可能的范数。