发表机构
EPFL; Apple(瑞士洛桑联邦理工学院; 苹果公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出基于最优传输几何的对抗训练改进方法,通过多起点粒子上升和输入凸神经网络参数化对抗映射,确保循环单调性,从而在鲁棒回归、图像分类和控制任务中提升鲁棒性与泛化性能。
AI 中文摘要
分布鲁棒优化(DRO)为分布偏移下的学习提供了原则性框架,但其实际应用因非凸损失函数下最坏情况风险评估的困难而受阻。我们研究了一种带惩罚的DRO公式,其中对手可以选择任何分布,但偏离经验分布时会 incur 一个 Wasserstein 惩罚。我们证明,对手的问题可以重新表述为关于传输映射的优化问题,这些映射将经验样本推送到对抗样本,并证明最优映射是循环单调的。我们还表明,标准的对抗训练——基于逐样本局部优化——违反了循环单调性,并且浪费了传输成本,除非对手受到严格限制。我们提出两种补救措施。首先,我们引入多起点粒子上升法,该方法交替进行并行梯度上升与重新分配,以在样本间强制执行循环单调性。其次,我们将对抗映射参数化为输入凸神经网络的梯度,这通过构造保证了循环单调性。在鲁棒回归、图像分类和鲁棒控制上的实验表明,我们的方法始终优于标准对抗训练和最先进的基线,在分布偏移下实现了改进的鲁棒性和更好的泛化能力。
英文摘要
Distributionally robust optimization (DRO) provides a principled framework for learning under distribution shift, but its practical use is hindered by the difficulty of evaluating worst-case risks for nonconvex loss functions. We study a penalized DRO formulation in which the adversary may choose any distribution but incurs a Wasserstein penalty for deviating from the empirical distribution. We show that the adversary's problem can be reformulated as an optimization problem over transport maps that push empirical samples to adversarial ones, and we prove that optimal maps are cyclically monotone. We also show that standard adversarial training---based on per-sample local optimization---violates cyclical monotonicity and wastes transport costs unless the adversary is severely restricted. We propose two remedies. First, we introduce multi-start particle ascent, which alternates parallel gradient ascent with reassignment to enforce cyclical monotonicity across samples. Second, we parameterize adversarial maps as gradients of input-convex neural networks, which guarantees cyclical monotonicity by construction. Experiments on robust regression, image classification, and robust control show that our methods consistently outperform standard adversarial training and state-of-the-art baselines, achieving improved robustness and better generalization under distribution shift.