OpenAI Blog

Trading inference-time compute for adversarial robustness

Trading Inference-Time Compute for Adversarial Robustness

arXiv Statistics ML
6d ago

Brenier Meets Adversarial Training: Optimal Transport Geometry for Robust Learning

The paper introduces a penalized distributionally robust optimization framework that allows an adversary to choose any distribution while incurring a Wasserstein penalty for deviating from the empirical distribution. It shows that the adversary’s problem can be reformulated as optimizing transport maps that push empirical samples to adversarial ones, proving that optimal maps are cyclically monotone. The authors argue that standard per-sample adversarial training violates this property and propose two remedies—multi-start particle ascent and input-convex neural network parameterization—to enforce cyclical monotonicity, demonstrating improved robustness and generalization in experiments on regression, image classification, and control tasks.

By Alireza Abdollahpoorrostam, Ehsan Sharifian, Buse \c{S}en, Marco Cuturi, Daniel Kuhn
arXiv Machine Learning
Sep 22

Statistical Inference for Adversarial Training: Central Limit Theorems via Optimal Transport

The paper rigorously analyzes the statistical and learning-theoretic properties of adversarial training models for classification, focusing on empirical optimal partial transport. It establishes two central limit theorems—one centered at the expected empirical value and another at the population value with smoothing—by leveraging the uniqueness of optimal potentials across various optimal transport formulations and empirical process theory. In the binary setting, the authors prove uniqueness of the optimal potential via a connection to multi-marginal optimal transport, and as additional results they derive stability of the saddle point, sample complexity, and concentration bounds for generalization error.

By Kim Jakwang, Kwon Dohyun
arXiv Machine Learning
Jun 26

Over-parameterization and Adversarial Robustness in Neural Networks: An Overview and Empirical Analysis

arXiv:2406. 10090v3 Announce Type: replace Abstract: Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization.

By Srishti Gupta, Zhang Chen, Luca Demetrio, Fabio Brau, Xiaoyi Feng, Zhaoqiang Xia, Antonio Emanuele Cin\`a, Maura Pintor, Luca Oneto, Ambra Demontis, Battista Biggio, Fabio Roli