对抗训练估计量在无穷范数扰动下的渐近行为

Asymptotic Behavior of Adversarial Training Estimator under l ∞ -Perturbation

Journal of the American Statistical Association · 2025
被引 1
ABS 4

中文导读

研究了广义线性模型中对抗训练估计量在无穷范数扰动下的渐近分布,发现其能在参数为零时赋予正概率质量,从而具备稀疏恢复能力,并提出了改进的自适应对抗训练方法。

Abstract

Adversarial training has been proposed to protect machine learning models against adversarial attacks. This paper focuses on adversarial training under 𝓁∞-perturbation, which has recently attracted much research attention. The asymptotic behavior of the adversarial training estimator is investigated in the generalized linear model. The results imply that the asymptotic distribution of the adversarial training estimator under 𝓁∞-perturbation could put a positive probability mass at 0 when the true parameter is 0, providing a theoretical guarantee of the associated sparsity-recovery ability. Alternatively, a two-step procedure is proposed—adaptive adversarial training, which could further improve the performance of adversarial training under 𝓁∞-perturbation. Specifically, the proposed procedure could achieve asymptotic variable-selection consistency and unbiasedness. Numerical experiments are conducted to show the sparsity-recovery ability of adversarial training under 𝓁∞-perturbation and to compare the empirical performance between classic adversarial training and adaptive adversarial training.

机器学习统计学习计量经济学人工智能