arXiv Machine Learning

Convex training of Lipschitz-regularized shallow neural networks

arXiv:2606. 19652v1 Announce Type: new Abstract: In this work, we introduce a training procedure for shallow neural networks that promotes robustness against adversarial attacks.

arXiv Machine Learning
Sep 14

A Unified and Constrained View of Regularization-Based Robust Reinforcement Learning

The paper presents a unified framework for regularization-based robust reinforcement learning by deriving upper bounds on the performance gap between nominal and worst-case policies. These bounds are expressed as a regularization objective plus a KL-divergence penalty, explaining why KL penalties enhance robustness. The authors reformulate robust training as a constrained optimization problem, updating the Lagrange multiplier jointly with the policy to automatically tune regularization, and validate the approach with extensive adversarial evaluations on continuous control tasks.

By Amine Andam, Jamal Bentahar, Mustapha Hedabou
arXiv AI
Sep 18

Exploring Sparsity and Smoothness of Arbitrary Lp Norms in Adversarial Attacks

The paper investigates how the choice of the π parameter in λπ norm-constrained adversarial attacks influences the sparsity and smoothness of the perturbations. By applying two established sparsity metrics and introducing three new smoothness measures—including one based on first-order Taylor approximations—the authors perform extensive experiments on real-world image datasets and various neural network architectures. Their results indicate that λρ norms with π values between 1.3 and 1.5 consistently provide the best balance between sparsity and smoothness, challenging the common use of λ1 or λ2 norms.

By Christof Duhme, Florian Eilers, Xiaoyi Jiang
arXiv Statistics ML
6d ago

Brenier Meets Adversarial Training: Optimal Transport Geometry for Robust Learning

The paper introduces a penalized distributionally robust optimization framework that allows an adversary to choose any distribution while incurring a Wasserstein penalty for deviating from the empirical distribution. It shows that the adversary’s problem can be reformulated as optimizing transport maps that push empirical samples to adversarial ones, proving that optimal maps are cyclically monotone. The authors argue that standard per-sample adversarial training violates this property and propose two remedies—multi-start particle ascent and input-convex neural network parameterization—to enforce cyclical monotonicity, demonstrating improved robustness and generalization in experiments on regression, image classification, and control tasks.

By Alireza Abdollahpoorrostam, Ehsan Sharifian, Buse \c{S}en, Marco Cuturi, Daniel Kuhn