We study robustness to test-time adversarial attacks in the regression setting with $\ell_p$ losses and arbitrary perturbation sets. We address the question of which function classes are PAC learnable in this setting. We show that classes of finite fat-shattering dimension are learnable in both realizable and agnostic settings. Moreover, for convex function classes, they are even properly learnable. In contrast, some non-convex function classes provably require improper learning algorithms. Our main technique is based on a construction of an adversarially robust sample compression scheme of a size determined by the fat-shattering dimension. Along the way, we introduce a novel agnostic sample compression scheme for real-valued functions, which may be of independent interest.
翻译:我们研究回归设置中针对测试时对抗攻击的鲁棒性,考虑ℓ_p损失函数和任意扰动集合。我们探讨在此设置下哪些函数类具有PAC可学习性。结果表明,有限胖分裂维数的函数类在可实现设定和不可知设定下均可学习。此外,对于凸函数类,它们甚至能够适当学习。相比之下,某些非凸函数类被证明需要非适当学习算法。我们的主要技术基于构造一个由胖分裂维数决定大小的鲁棒对抗性样本压缩方案。在此过程中,我们提出了一种新的用于实值函数的不可知样本压缩方案,该方案可能具有独立的研究价值。