Pith. sign in

REVIEW 2 cited by

Adversarial Training Should Be Cast as a Non-Zero-Sum Game

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.11035 v2 pith:3CGHAKRO submitted 2023-06-19 cs.LG math.OCstat.ML

classification cs.LGmath.OCstat.ML
keywords adversarialtrainingalgorithmsrobustnessapproachformulationlevelsnon-zero-sum
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

One prominent approach toward resolving the adversarial vulnerability of deep neural networks is the two-player zero-sum paradigm of adversarial training, in which predictors are trained against adversarially chosen perturbations of data. Despite the promise of this approach, algorithms based on this paradigm have not engendered sufficient levels of robustness and suffer from pathological behavior like robust overfitting. To understand this shortcoming, we first show that the commonly used surrogate-based relaxation used in adversarial training algorithms voids all guarantees on the robustness of trained classifiers. The identification of this pitfall informs a novel non-zero-sum bilevel formulation of adversarial training, wherein each player optimizes a different objective function. Our formulation yields a simple algorithmic framework that matches and in some cases outperforms state-of-the-art attacks, attains comparable levels of robustness to standard adversarial training algorithms, and does not suffer from robust overfitting.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Decoupled SGDA for Games with Intermittent Strategy Communication

    cs.LG 2025-01 conditional novelty 6.0 of 10

    Decoupled SGDA achieves O(1/(1-4κ_c) log(1/ϵ)) communication rounds in weakly coupled SCSC games, independent of the players' condition numbers.

  2. Linear Convergence Analysis of Single-loop Algorithm for Bilevel Optimization via Small-gain Theorem

    math.OC 2024-12 conditional novelty 6.0 of 10

    Using a small-gain argument from control theory, the authors prove the standard single-loop bilevel optimization algorithm converges linearly in the strongly convex setting.

Pith tools