ArXiv

Generalization and Trade-off in Adversarial Training: An RKHS Perspective via Kernel Integral Operators

Authors
Yiling Xie, Xiaoming Huo
Categories
stat.ML, cs.LG
arXiv
https://arxiv.org/abs/2607.27995v1
PDF
https://arxiv.org/pdf/2607.27995v1

Brief

Adversarial training in RKHS via kernel integral operators is analyzed by Xie and Huo (2026), who derive source-uniform generalization bounds depending on robustness level, sample size, source smoothness, and kernel spectrum. They show a matching lower bound on polynomial-spectrum models where noise–robustness interaction yields slower-than-minimax rates, and propose a two-stage noise-debiased estimator that restores the minimax polynomial rate up to logarithmic factors. Full text not available; summary based on abstract.

Why it matters

Xie and Huo (2026) derive source-uniform generalization error bounds for RKHS adversarial training estimators that depend explicitly on robustness level, sample size, source smoothness, and the kernel spectrum.

Key details

  • On a fixed polynomial-spectrum model they prove a matching lower bound: the optimally balanced generalization rate can be strictly slower than the minimax prediction benchmark, revealing a loss of statistical accuracy due to adversarial robustness interacting with observation noise.
  • They propose a two-stage noise-debiased procedure that estimates and removes the noise contribution from the mixed robustness term; this estimator improves the generalization rate and attains the minimax polynomial rate up to a logarithmic factor when the robustness level is chosen at the stated sample-dependent order, with numerical experiments supporting the theory.
Source evidence

Abstract

Adversarial training has emerged as a powerful approach for protecting models against adversarial attacks in a broad range of real-world applications. In this paper, we study adversarial training in the reproducing kernel Hilbert space (RKHS) framework through the associated kernel integral operator. We first derive source-uniform generalization error bounds for the RKHS adversarial training estimator in terms of the robustness level, sample size, source smoothness, and kernel spectrum. On a fixed polynomial-spectrum model, we further establish a matching lower bound showing that the optimally balanced generalization rate can be slower than the minimax prediction benchmark. This result reveals a loss of statistical accuracy in adversarial training. Our analysis shows that this loss arises from the interaction between adversarial robustness and observation noise: the noise contribution in the mixed robustness term slows the approximation rate, although the same term reduces the estimation complexity. To address this limitation, we propose a two-stage noise-debiased procedure that estimates and removes the noise contribution from the mixed term. The resulting estimator improves the generalization rate and attains the minimax polynomial rate, up to a logarithmic factor, when the robustness level is selected at the stated sample-dependent order. Our results characterize the generalization behavior of adversarial training in a nonparametric framework and provide a new interpretation and a principled solution for the trade-off between adversarial robustness and generalization. Numerical experiments support the theoretical findings and demonstrate the effectiveness of the proposed method.