Can overfitted deep neural networks in adversarial training generalize? – An approximation viewpoint
March. 01,2024In this talk, I will discuss whether overfitted DNNs in adversarial training can generalize from an approximation viewpoint. We prove by construction the existence of infinitely many adversarial training classifiers on over-parameterized DNNs that obtain arbitrarily small adversarial training error (overfitting), whereas achieving good robust generalization error under certain conditions concerning the data quality, well separated, and perturbation level. This construction is optimal and thus points out the fundamental limits of DNNs under adversarial training with statistical guarantees. Part of this talk comes from our recent work.
Reviews
Wow! Such a good movie.
It's funny watching the elements come together in this complicated scam. On one hand, the set-up isn't quite as complex as it seems, but there's an easy sense of fun in every exchange.
The storyline feels a little thin and moth-eaten in parts but this sequel is plenty of fun.
Exactly the movie you think it is, but not the movie you want it to be.