arXiv · 2210.12606
Nash Equilibria and Pitfalls of Adversarial Training in Adversarial Robustness Games
Abstract
Adversarial training is a standard technique for training adversarially robust models. In this paper, we study adversarial training as an alternating best-response strategy in a 2-player zero-sum game. We prove that even in a simple scenario of a linear classifier and a statistical model that abstracts robust vs. non-robust features, the alternating best response strategy of such game may not converge. On the other hand, a unique pure Nash equilibrium of the game exists and is provably robust. We support our theoretical results with experiments, showing the non-convergence of adversarial training and the robustness of Nash equilibrium.
Explore related subjects
Keep this discovery
Maria-Florina Balcan, Rattana Pukdee, Pradeep Ravikumar, Hongyang Zhang. 2022-10-23. Nash Equilibria and Pitfalls of Adversarial Training in Adversarial Robustness Games. https://arxiv.org/abs/2210.12606
Cite the original work for its findings. Save a collection to share your selection of sources.