In supervised learning, it has been shown that label noise in the data can be interpolated without penalties on test accuracy. We show that interpolating label noise induces adversarial vulnerability, and prove the first theorem showing the relationship between label noise and adversarial risk for any data distribution. Our results are almost tight if we do not make any assumptions on the inductive bias of the learning algorithm. We then investigate how different components of this problem affect this result, including properties of the distribution. We also discuss non-uniform label noise distributions; and prove a new theorem showing uniform label noise induces nearly as large an adversarial risk as the worst poisoning with the same noise rate. Then, we provide theoretical and empirical evidence that uniform label noise is more harmful than typical real-world label noise. Finally, we show how inductive biases amplify the effect of label noise and argue the need for future work in this direction.
翻译:在监督学习中,已有研究表明数据中的标签噪声可以在不影响测试准确率的情况下被插值。我们证明,对标签噪声进行插值会引发对抗脆弱性,并首次提出定理,揭示标签噪声与任意数据分布下对抗风险之间的关系。若不假设学习算法的归纳偏置,我们的结果几乎是紧致的。我们进一步研究该问题的不同组成部分(包括分布性质)对这一结果的影响,并讨论非均匀标签噪声分布;同时证明新定理:相同噪声率下,均匀标签噪声引发的对抗风险几乎与最恶劣的投毒攻击相当。接着,我们从理论与实证两方面证明,均匀标签噪声比典型的真实世界标签噪声更具危害性。最后,我们展示归纳偏置如何放大标签噪声的影响,并指出该方向亟需未来研究。