Part of Advances in Neural Information Processing Systems 36 (NeurIPS 2023) Main Conference Track
Jingyuan Xu, Weiwei Liu
This paper considers the following question: Given the number of classes m, the number of robust accuracy queries k, and the number of test examples in the dataset n, how much can adaptive algorithms robustly overfit the test dataset? We solve this problem by equivalently giving near-matching upper and lower bounds of the robust overfitting bias in multiclass classification problems.