Maximizing the robust margin provably overfits on noiseless data

Konstantin Donhauser*, Alexandru Țifrea*, Michael Aerni, Reinhard Heckel, Fanny Yang

* Equal contribution

ICML Workshop on Adversarial Machine Learning 2021

Abstract

Numerous recent works show that overparameterization implicitly reduces variance, suggesting vanishing benefits for explicit regularization in high dimensions. However, this narrative has been challenged by empirical observations indicating that adversarially trained deep neural networks suffer from robust overfitting. While existing explanations attribute this phenomenon to noise or problematic samples in the training data set, we prove that even on entirely noiseless data, achieving a vanishing adversarial logistic training loss is suboptimal compared to regularized counterparts.

BibTeX

@inproceedings{donhauser2021robustmargin,
    title={Maximizing the robust margin provably overfits on noiseless data},
    author={Donhauser, Konstantin and Ţifrea, Alexandru and Aerni, Michael and Heckel, Reinhard and Yang, Fanny},
    booktitle={{ICML 2021 Workshop on Adversarial Machine Learning}},
    year={2021},
    url={https://openreview.net/forum?id=ujQKWaxFkrL}
}