arXiv論文メモ
新着一覧
stat.ML / cs.LG / math.ST / stat.TH · 査読状況未確認

敵対的摂動に強い学習の最適な標本数を証明

Adversarially Robust PAC Learning with Optimal VC Rates

Steve Hanneke and Amirreza Shaeiri

この論文をやさしく読む

ひとことで言うと

入力が許された範囲で改変されても正しく分類する学習に、理論上どれだけの訓練例が必要かを調べています。最適な必要標本数は通常のPAC学習と同じ次数になると証明しています。

何に役立つ?

頑健な学習の難しさのうち、データ数に由来する部分を見極める基礎になります。εは誤差水準、δは保証が失敗する確率を制御する量です。

この研究の面白いところ

摂動写像がどのようなものでも一様に成り立つ標本数の上界を示し、古典的な下界と一致させています。新しい二項バギングが証明の中心です。

どこまで分かった?

独立標本、同じ分布からの将来例、学習者に既知の摂動写像という理論設定です。統計的コストが増えないという結論であり、計算時間が増えないことや実際の画像モデルでの達成を示す結果ではありません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

本研究では、敵対的摂動に対して頑健なPAC学習の問題を扱う。この枠組みでは、古典的PAC学習と同様に、学習者は𝒳×{0,1}上の未知の分布から得られた独立な標本を観測する。ただし、学習者に既知の摂動写像𝒰:𝒳→2^𝒳が与えられ、同じ基礎分布から将来得られる例(x,y)の大部分について、そのあらゆる摂動z∈𝒰(x)を正しく分類する予測器を、高い確率で出力することが目標となる。 この問題について、実現可能な設定と不可知な設定の両方で、𝒰に依存しない最適な標本複雑度を決定する。具体的には、VC次元がdの任意の概念クラスℋについて、実現可能な設定ではO(d/ε + log(1/δ)/ε)、不可知な設定ではO(d/ε² + log(1/δ)/ε²)という上界を証明し、後者については最適な一次の精密化も与える。これらの上界は古典的PAC学習に対応する下界と一致する。したがって、意外にも、敵対的頑健性のために、分布に依存しない統計的コストが追加されることはなく、この結論はすべての摂動写像にわたって一様に成り立つ。得られた上界は、Montasser、Hanneke、SrebroによるCOLT 2019の結果を指数関数的に改善する。技術面では、二項バギングと呼ぶ新しいアルゴリズム原理に基づく、短く初等的な証明を提示する。著者らは、二項バギングとその解析自体にも独立した関心が寄せられ得ると考えている。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-21(UTC)
最新改訂
2026-09-21 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

We study the problem of \emph{adversarially robust} PAC learning. In this framework, the learner observes independent samples from an unknown distribution over $\mathcal{X} \times \{0,1\}$, as in classical PAC learning. However, given a perturbation map $\mathcal{U} : \mathcal{X} \to 2^{\mathcal{X}}$ known to the learner, the goal is to output, with high probability, a predictor that correctly classifies \emph{every} perturbation $z \in \mathcal{U}(x)$ of most future examples $(x,y)$ drawn from the same underlying distribution. We determine the \emph{optimal} $\mathcal{U}$-independent sample complexity of this problem in both the realizable and agnostic settings. More specifically, for every concept class $\mathcal{H}$ of $\operatorname{VC}$ dimension $d$, we prove upper bounds of $\mathcal{O} \big( d/\epsilon + \log(1/\delta)/\epsilon \big)$ in the realizable setting and $\mathcal{O} \big( d/\epsilon^2 + \log(1/\delta)/\epsilon^2 \big)$ in the agnostic setting, together with an optimal first-order refinement of the latter. These bounds match the corresponding lower bounds for classical PAC learning. Consequently, and perhaps surprisingly, adversarial robustness incurs \emph{no additional} distribution-free statistical cost, uniformly over all perturbation maps. Our bounds improve exponentially on those of [Montasser, Hanneke, and Srebro; COLT '19]. On the technical side, we present short and elementary proofs based on a new algorithmic principle that we call \emph{binomial-bagging}. We believe that binomial-bagging and its analysis may be of independent interest.

著者のコメント

35 pages, 2 figures

arXiv ID: 2609.24260 / 要約の誤りについて