Adversarial examples from computational constraints
Sébastien Bubeck, Eric Price, Ilya Razenshteyn
Introduction
Such an input in the above event is colloquially referred to as an adversarial exampleIn the literature one sometimes uses a more stringent definition of adversarial examples, where and are in addition required to satisfy . We ignore this requirement here..
Following Szegedy et al. there is a rapidly expanding literature exploring the vulnerability of neural networks to adversarially chosen perturbations. The surprising observation is that, say in vision applications, for most images the perturbation can be chosen in a way that is imperceptible to a human yet dramatically changes the output of state-of-the-art neural networks. This is a particularly important issue as these neural networks are currently being deployed in real-world situations. Naturally there is by now a large literature (in fact going back at least to ) on attacks (finding adversarial perturbations) and defenses (making classifiers robust against certain type of attacks).
While we have a sophisticated theory for the classical goal of minimizing the non-robust probability of error, our understanding of the robust scenario is still very rudimentary. At the moment, the “attackers” seem to be winning the arms race against the “defenders”, see e.g., . We identify four mutually exclusive possibilities for why all known classification algorithms are vulnerable to adversarial examples:
Identifying a robust classifier requires too much training data.
Identifying a robust classifier from limited training data is information theoretically possible but computationally intractable.
We just have not found the right algorithm yet.
The goal of this paper is to provide two pieces of evidence, one in favor of hypothesis 3 and one against hypothesis 2. Our primary result is that hypothesis 3 is indeed possible: there exist robust classification tasks that are information theoretically easy but computationally intractable under a powerful model of computation (namely the statistical query model, see below). Our secondary result is evidence against hypothesis 2, showing that if a robust classifier exists then it can be found with relatively few training examples under a standard assumption on the data distribution (for example, that the distribution within each label is close to a Lipschitz generative model, or is drawn from a finite set of exponential size).
In Section 1.1 we discuss related work on adversarial examples in light of those four hypotheses. In Section 1.2 we introduce the model of computation under which we will prove intractability. We conclude the introduction with Section 1.3 where we give a brief proof overview for our primary and secondary result. These results are discussed in greater depth respectively in Section 4 and Section 3.
To the best of our knowledge, previous works have not linked computational constraints to adversarial examples, but instead have focused on the other three hypotheses.
Another work arguing the inevitability of adversarial examples is Gilmer et al. . There the authors propose a simple classification task, namely distinguishing between samples on the unit sphere in high dimension and samples on a sphere of radius bounded away from . They show experimentally that even in such a simple setup, state-of-the-art neural networks have adversarial examples at most points. We note however that this example only applies to specific classifiers, since it is easy to construct an efficient robust classifier for the given example (e.g., just use a linear model on the norm of the features); thus the “hardness” here only appears for a given network structure.
2 The SQ model
Proving computational hardness is a notoriously difficult problem. To circumvent this difficulty one usually either (i) reduces the problem at hand to a well-established computational hardness conjecture (e.g., proving NP-hardness), or (ii) proves an unconditional hardness within a limited computational framework (such as the oracle lower bounds in convex optimization, ). Our task here is further complicated by the average-case nature of the problem (the datasets are i.i.d. from some fixed distribution). Fortunately there is a growing set of results on computational hardness in learning theory that we can leverage. The statistical query (SQ) model of computation from Kearns is a particularly successful instance of approach (ii) for learning theory: (a) most known learning algorithms fall in the framework, including in particular logistic regression, SVM, stochastic gradient descent, etc; and (b) SQ-hardness has been proved for many interesting problems that are believed to be computationally hard, such as learning parity with noise , learning intersection of halfspaces , the planted clique problem , robust estimation of high-dimensional Gaussians , or learning a function computable by a small neural network . Thus we naturally use this model to prove our main result on the computational hardness of robust learning. We now recall the definition of the SQ model and state informally our main result.
not efficiently and robustly learnable in the statistical query model, in the sense that even with an exponential (in ) precision statistical query oracle one needs an exponential (in ) number of queries in order to robustly learn with robustness parameter .
Of course, a number of natural machine learning algorithms such as nearest neighbor are not based on statistical queries. Although we cannot prove it, we believe that our input distributions are computationally hard in general. For the case of nearest neighbor, the distance to points of each class have very similar distributions—indeed, the two distributions match on polynomially many moments. This suggests that exponentially many samples are necessary for nearest neighbor. For more information about nearest neighbor classifiers in the context of adversarial examples, see .
Moreover, there are very few problems in any domain with exponential SQ hardness for which polynomial time algorithms are known; in fact, the only such problems involve solving systems of linear equations over finite fields . Since Theorem 1.1 involves a real-valued problem, finding a polynomial time algorithm that avoids the SQ lower bound would be a remarkable breakthrough in SQ theory.
3 Overview of proofs
Our secondary result, on the information theoretic achievability of robustness, is proved via simple arguments reminiscent of PAC-learning theory. Namely, if a classifier is not good enough for a given pair of distributions, we can rule it out with high confidence by looking at not too many samples. Then, we use a union bound to claim the result for a family of pairs that is either at most exponentially large, or is at least covered by a net of at most exponential size (the only subtlety is in the proper definition of a net in this robust context).
Our primarily result, on the hardness of robustness, is technically much more challenging. The central object in the proof is a natural high-dimensional generalization of a construction from Diakonikolas et al. . Roughly speaking, a hard pair of distributions is obtained by taking a standard multivariate Gaussian, choosing a random -dimensional subspace and planting there two well-separated distributions that match many moments of a Gaussian (in only the case is considered). To show an SQ lower bound, we use – as in – the framework of to reduce the question to computing a certain non-standard notion of correlation between the distributions. To bound said correlation, we deviate from significantly, since their argument is tailored crucially to the case . Our argument is less precise, but allows which is necessary to obtain a large separation between the distributions (which in turn controls the parameter in Theorem 1.1).
Definitions
We say that is -robustly learnable with samples if there is a classification algorithm such that, for every , with probability at least over and , the algorithm produces a classifier that is -robust for .
The success probability is an arbitrary constant larger than . It is easy to see that, for any , by using samples one can obtain a success probability of .
We say that is -robustly feasible if every admits an -robust classifier. When it exists we denote for such a classifier (chosen arbitrarily among all robust classifiers for ), and .
Robust learning with few samples
Obviously robust feasibility is a necessary condition for robust learnability. We show that it is in fact sufficient, even for sample efficient robust learnability. We first do so when a finite set of classifiers suffices for robust feasibility.
Assume that is -robustly feasible. Then it is -robustly learnable with .
Let be the empirical measure corresponding to the dataset . We will show that ERM on the -robust loss gives the claimed sample complexity. More precisely we consider the classification algorithm that outputs:
Now observe that for one can has , and thus we obtain with ,
It now suffices to observe that implies . ∎
2 Robust covering number
With the above definitions one can obtain the following result as a straightforward corollary of Theorem 3.1 and the definition of total variation distance.
It is now easy to prove the following strengthening of Theorem 3.3:
3 Covering number bound from generative models
We now show that distributions approximated by generative models have bounded covering numbers (in terms of Definition 3.4), so Theorem 3.5 gives a good sample complexity for such distributions. The proof is deferred to Appendix C in the supplementary material.
Lower bound for the SQ model
The distributions and admits a -robust classifier; moreover, a -robust classifier can be learned from samples from and ;
For and , there exists a linear (non-robust) classifier, which can be learned in polynomial time;
For every , in order to learn a -robust classifier for and , one needs at least statistical queries with accuracy as good as .
For instance, if is a small constant we get the existence of a -robust classifier, where is a large constant. One could push as high as at a cost of the lower bound being against SQ queries with somewhat worse accuracy ( instead of ).
We first show a family of pairs that admit a robust classifier, yet it is hard (in the SQ model) to learn any (non-robust) classifier. Later, in Section 4.3, we show a simple modification of this family to obtain the main result.
Here we define a hard family of pairs of distributions as discussed above. This section contains the definition and key properties of the family; proofs of those properties appear in Appendix A. This family can be seen to be a high-dimensional generalization and modification of a family considered in . The family depends on three parameters: integers , and a positive real .
and match in the first moments;
, and for every and , one has: .
For every , there exists such a family with and .
where and are densities of distributions and from Lemma 4.2, and is the p.d.f. of the standard Gaussian distribution . Now we simply take to be and to be .
The heart of the matter is to show that it requires statistical queries with precision to learn a classifier for and provided that all the parameters are set correctly. The argument is fairly involved and uses the framework of to reduce the question to that of upper bounding -correlation between the distributions. Due to space limitations, we show the argument in Appendix B of the supplementary material.
3 Making the distribution easy to learn non-robustly
Conclusion and future directions
In this paper we put forward the thesis that adversarial examples might be an unavoidable consequence of computational constraints for learning algorithms. Our main piece of evidence is a classification task, for which there essentially exists a classifier robust to Euclidean perturbations of size (while with high probability any sample has norm ), yet finding any non-trivial robust classifier (even for arbitrarily small perturbations, and with probability of correctness only slightly better than chance) is hard in the statistical query model (in the sense that one needs an exponential number of queries, even with a very high precision statistical query oracle). We identify several directions in which this result could be strengthened to give stronger evidence for our thesis.
The most important question for the validity of our thesis is whether one could prove a similar hardness result for natural distributions. This is a particularly challenging open problem as the concept of a natural distribution is fuzzy (for instance there is no consensus on what a natural distribution for images should look like).
We believe that our proposed classification task is really computationally hard in any sense, not only in the statistical query model. As we discussed SQ is natural for learning theory hardness, but there have been lots of works leveraging other types of hardness assumption (e.g., cryptographic). It would be interesting to explore further the position of robust learning in the hardness landscape.
Finally one might wonder whether the perturbation size is optimal (for distributions essentially supported in a ball of size ). A concrete open question could be phrased as follows: consider a classification task that is -robustly feasible, how fast does need to grow in order to ensure that one can find in polynomial time a -robust classifier?
References
Appendix A Proofs of properties of the SQ hard distribution
We start with the following lemma on Hermite polynomials:
For every , the distance between any roots of and is at least .
It is known that extrema of are exactly zeros of , which follows from and a lack of double roots. Thus, it is enough to show that extrema and zeros of are -separated.
Consider the case where are such that , is positive between and , and . Let us show how to lower bound . Denote . Clearly, and is positive between and with a unique local maximum on , which we denote by . It is not hard to check that . Thus, it is enough to lower bound . It is known (see, e.g., [19, Section 5.5] that satisfies the ODE . By comparing with , we can get that lower bound .
Now let us lower bound . It is known [19, Section 5.5] that satisfies the ODE . By comparing this ODE with , we get that . The latter step is due to and that the lower bound on is nonincreasing in .
and match in the first moments;
, and for every and , one has: .
Let and be two consecutive (physicist’s) Hermite’s polynomials. It is a classic result in Gaussian quadrature (see, e.g., ) that for every , there exists a discrete distribution supported on the zeros of , which matches in the first moments. Let denote such a distribution for and the same for . By Lemma A.1, the distance between the supports of and is at least and they both match in the first moments.
Now, we obtain the desired distributions and as follows. Fix a small . The distribution is defined as , where , , and and are independent. The distribution is defined similarly, but instead of we use . It is easy to check that and match the first moments of . Now suppose that . The second property follows from the supports of and being separated and the standard concentration inequalities; specifically, we take to be the Minkowski sum of the support of scaled down and the ball of radius , and to be similar with instead of . Then the chance is not in is at most the chance has , which is .
Now let us prove the bounds on , for the similar bounds follows exactly the same way.
Denote the roots of .
We have for every the bound . Therefore, if denotes the p.d.f. of we have
For every , there exists such a family with and .
Thus, we can set , and for a sufficiently small positive , which yields . ∎
The points and are well-separated, since in at least a -fraction of , both and . Since and are -separated, we obtain the result.
The bounds on the probabilities follow from the respective bounds in Lemma 4.2 and standard Chernoff bounds. ∎
Appendix B SQ lower bound
Now let us show that if we set all the parameters appropriately, it is hard in the SQ model to learn a good classifier (robust or otherwise) for distributions and defined above, where is an unknown subspace. The main idea is to show that if the subspace is chosen uniformly at random, unless we perform more than queries, we can not tell apart or from the standard Gaussian (and as a result, from each other). Intuitively, any since query can only reliably distinguish from for a tiny fraction of subspaces . The result then follows by a simple counting argument. To formalize the above intuition, we use an argument similar at a high-level to the one used in .
In Section B.2, we show that for an appropriate setting of parameters (namely, when ), for every , one has:
Then by repeating the proof of Lemma 3.3 from , we get that if the number of queries is significantly smaller than:
then with high probability over a random subspace , all the queries asked can be answered as if both and were . As a result, we cannot distinguish them from and, as a result, between each other.
Suppose that for a sufficiently large constant , so that the term is less than . Then we can set the precision to and still be unable to distinguish from from queries. If for a sufficiently small positive , this gives the desired lower bound of on the number of SQ queries the algorithm must ask.
B.2 Upper bounding pairwise correlations
We assume that for a sufficiently large constant to be determined later. Since by Lemma 4.3 we can take , the required inequality holds as long as and are at most small powers of .
where the fourth step is due to the independence of (which is implied by orthogonality of ), and the fifth step follows from Lemma 4.2.
for some that lies between and .
Suppose . For every , one has:
Since , we can write . One has:
Now let us fix partitions and show that:
Since , there exists such that: . Since is independent from the remaining dot products, we can factor from (3) the expression
with . But since is distributed as , one has that (4) is equal to zero due to Lemma 4.2. ∎
Let us continue upper bounding (B.2). For and , denote:
Plugging (B.2) into (B.2), we get the result.
B.3 Setting parameters
We obtain a -robust classifier, and the precision of statistical queries can be as high as . Thus, for , we can set and . As a result we get robustness , and the precision of statistical queries can be as good as .
Appendix C Bound on covering number of generative models
by Lemma C.1 and our chosen . Since with probability much higher than , this implies . The triangle inequality then gives as desired. ∎