arrow
Return

Simultaneous Robustness and Generalization Using Nearest Neighbor Classifiers

delete2026-01-01
delete0
PRE
AI
Ó
Óscar Déniz *
G
Gloria Bueno
A
Aníbal Pedraza
H
Harbinder Singh
DOI:10.1007/978-3-032-05060-1_8delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
While most attention in modern machine learning is devoted to accuracy gains, there is ample scope for research into fail cases. The phenomenon of adversarial examples shows in the most striking fashion how brittle the behavior of our models is. Adversarial examples are not exclusive of deep learning, they can equally appear with other machine learning methods too. Since they became popular, a multitude of attack and defense methods have been proposed in the literature to both generate adversarials and protect models from them. In this context, it has been shown that there is a general trade-off between robustness to adversarial examples and generalization: making a model more robust to adversarials causes it to lose generalization in the standard test set. This has been observed in so many ways (both theoretical and empirical) that several authors have argued that the trade-off is inescapable. In this work we use nearest neighbors to show that an algorithm can have optimal generalization and robustness, suggesting that the trade-off is not inescapable in that case.
Keywords:
Adversarial examples
Nearest Neighbors

Journal

C
COMPUTER ANALYSIS OF IMAGES AND PATTERNS, CAIP 2025, PT II
IF:
0
Papers:
32
Citations:
0

Organization

U
Universidad de Castilla-La Mancha
Scholars:
9.9K
Papers: 9.1K
Citations: 7