用最优传输几何改进对抗训练:arXiv 新研究提出两种提升鲁棒性的方法
Brenier Meets Adversarial Training: Optimal Transport Geometry for Robust Learning
把最优传输的数学搬到对抗训练里,还给出了两种可实现的改进算法,做鲁棒性研究的可以看看推导和实验设置。
arXiv 论文《Brenier Meets Adversarial Training》研究带 Wasserstein 惩罚的分布式鲁棒优化(DRO) formulation。作者证明对抗问题可重构为对传输映射的优化,且最优映射满足循环单调性,而基于逐样本局部优化的标准对抗训练违反该性质并浪费传输成本。论文提出多起点粒子上升和用 input-convex 神经网络参数化对抗映射两种方法,后者从构造上保证循环单调性。在鲁棒回归、图像分类和鲁棒控制实验中,两种方法在鲁棒性和分布偏移下的泛化上均超过标准对抗训练与 SOTA 基线。
Brenier Meets Adversarial Training: Optimal Transport Geometry for Robust Learning
Distributionally robust optimization (DRO) provides a principled framework for learning under distribution shift, but its practical use is hindered by the difficulty of evaluating worst-case risks for nonconvex loss functions. We study a penalized DRO formulation in which the adversary may choose any distribution but incurs a Wasserstein penalty for deviating from the empirical distribution. We show that the adversary's problem can be reformulated as an optimization problem over transport maps that push empirical samples to adversarial ones, and we prove that optimal maps are cyclically monotone. We also show that standard adversarial training---based on per-sample local optimization---violates cyclical monotonicity and wastes transport costs unless the adversary is severely restricted. We propose two remedies. First, we introduce multi-start particle ascent, which alternates parallel gradient ascent with reassignment to enforce cyclical monotonicity across samples. Second, we parameterize adversarial maps as gradients of input-convex neural networks, which guarantees cyclical monotonicity by construction. Experiments on robust regression, image classification, and robust control show that our methods consistently outperform standard adversarial training and state-of-the-art baselines, achieving improved robustness and better generalization under distribution shift.