arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

当干净数据造成伤害:超越二元分类的单调损坏下的学习

When Clean Data Hurts: Learning with Monotone Corruptions Beyond Binary Classification

Julian Asilis, Shaddin Dughmi, Chirag Pabbaraju

arXiv 2608.20480首次发表:更新:

AI 中文总结

该研究针对单调对抗性损坏下的学习问题,证明多类分类等场景中部分问题不可学习,给出自适应添加数量为o(n)时仍可学习的紧界,还明确了不同对抗者下的错误率可达情况。

AI 中文摘要

最优学习者是为利用经典PAC模型背后的独立同分布(i.i.d.)数据假设而量身定制的。如果一个独立同分布的训练样本被来自不相关甚至对抗性源的正确标记示例损坏,会发生什么?这种带单调对抗性损坏的学习模型是Larsen等人(2026)最近提出的,他们证明在该设置下,所有已知的最优二元学习者的错误率都会上升:从PAC模型下的O(d/n)上升到单调损坏下的Ω(d log(n/d)/n)。Mehrotra(2026)证明了该对数因子对于二元分类是必要的,但留下了损坏对更通用学习设置(如多类分类和部分二元概念类)的影响这一开放问题。作为我们的主要结果,我们证明单调对抗者在每种此类设置中都强大得多。我们展示了一个DS维度仅为2的可学习多类问题,在单调对抗者下变得完全不可学习,并对部分二元概念类展示了类似结果。这些结果由一个自适应对抗者实现,该对抗者被允许查看原始独立同分布训练集S并向S中插入b < ∞个损坏数据点。在多类示例中,对抗者仅需插入线性数量b = |S| = n个数据点。我们通过证明当自适应添加数量为o(n)时,每个类仍然可学习来补充这些不可能性结果,而我们之前的多类下界证明了这是紧的。我们进一步观察到,对于受限于已知常数预算b = O(1)的自适应对抗者、仅查看S的p分之一(p ∈ (0,1))的半自适应对抗者以及无法查看S的非自适应对抗者,经典多类错误率O(d_DS/n)仍然可实现。

英文摘要

Optimal learners are tailored to exploit the i.i.d.\ data assumption underlying the classic PAC model. What if an i.i.d.\ training sample were corrupted with correctly labeled examples drawn from an otherwise unrelated, even adversarial source? This model of learning with monotone adversarial corruptions was recently introduced by Larsen et al. (2026), who demonstrated that all known optimal binary learners suffer increased error rates in this setting, from $O(d / n)$ in the PAC model to $Ω(d \log(n / d) / n)$ under monotone corruption. Mehrotra (2026) proved this logarithmic factor to be necessary for binary classification, but left open the consequences of corruption for more general learning settings, such as multiclass classification and partial binary concept classes. As our primary result, we demonstrate that monotone adversaries are frighteningly more powerful in each of these settings. We exhibit a learnable multiclass problem, of DS dimension only 2, that becomes altogether unlearnable under a monotone adversary, and show an analogous result for partial binary concept classes. These results are achieved by an adaptive adversary permitted to view the original i.i.d.\ training set $S$ and to insert $b < \infty$ corrupted datapoints into $S$. In the multiclass example, the adversary need only insert a linear number $b = |S| = n$ of datapoints. We complement these impossibility results by proving that every class remains learnable when the number of adaptive additions is $o(n)$, which our previous multiclass lower bound proves to be tight. We further observe that the classic multiclass error rate of $O(d_{\mathrm{DS}} / n)$ remains achievable against adaptive adversaries restricted to a known constant budget $b = O(1)$, against semi-adaptive adversaries viewing only a $p$-fraction of $S$ for $p \in (0, 1)$, and against oblivious adversaries that cannot view $S$.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑