近低秩对抗分类中的尾部权重控制与局部泛化
Tail-Weight Control and Localized Generalization in Nearly Low-Rank Adversarial Classification
浏览论文内容
中文总结 AI 辅助
本研究针对近低秩对抗分类,提出边界归一化与路径特定密度界,实现尾部权重控制及局部泛化保证,并通过实验验证其有效性。
中文摘要 AI 辅助
我们在一个具有低维信息子空间和独立噪声尾部的高斯模型中,研究欧几里得对抗扰动下的范数约束线性分类。对于有界斜坡损失,我们证明了一个风险低于二分之一的子空间见证者迫使每个近最优预测器具有较小的尾部权重。一个路径特定的密度界在不要求正尾部方差的情况下提供了常数。在各向同性主协方差下,我们建立了唯一的总体最小化器和联合局部增长。边界归一化随后从居中边际中移除了常见的攻击惩罚,从而给出了由主维度和总尾部能量控制的局部有限样本保证。全局化增长在较弱的常数下移除了入口条件;一种模型感知的比较保留了局部保证。二十次配对重复的实验显示,随着样本量的增加,超额风险和尾部使用减少,并且在固定总能量下尾部维度增长时行为几乎不变。纯噪声控制和优化器诊断阐明了这些结论的范围和局限性。
英文摘要
Empirical ramp fitting can assign weight to pure-noise features even when the population optimum ignores them. We quantify this gap for norm-constrained adversarial classification with Gaussian signal and noise. The variance cost relative to normalized signed mean separates into two factors: selecting observations inside the active margin window and the curvature induced by the norm constraint. Changing the tail variance leaves the activewindow probability unchanged but changes the second factor. With positive attack budget and a signal-only predictor of risk below one half, we prove a uniform quadratic tail-deletion bound, including at zero tail variance. Sufficiently accurate approximate global empirical minimizers admit exact fixeddimensional asymptotic covariances in the low-risk regime with isotropic principal covariance. For positive tail variance at most principal variance, the product exceeds one; an additional moment condition transfers it to expected excess ramp and robust classification risks. A wide window analysis characterizes when this ordering reverses. Controlled experiments test the decomposition, and a separate contamination study examines its scope outside the Gaussian training model.
发表机构
- The Chinese University of Hong Kong(香港中文大学)
- Columbia University(哥伦比亚大学)
机构由 AI 辅助整理,请以论文原文为准。