Learning Halfspaces with Malicious Noise
Adam R. Klivans, Philip M. Long, Rocco A. Servedio · 2009
Abstract. We give new algorithms for learning halfspaces in the challenging malicious noise model, where an adversary may corrupt both the labels and the underlying distribution of examples. Our algorithms can tolerate malicious noise rates exponentially larger than previous work in terms of the dependence on the dimension n, and succeed for the fairly broad class of all isotropic log-concave distributions. We give poly(n, 1/ǫ)-time algorithms for solving the following problems to ac-curacy ǫ: – Learning origin-centered halfspaces in Rn with respect to the uniform dis-tribution on the unit ball with malicious noise rate η = Ω(ǫ2 / log(n/ǫ)). (The best previous result was Ω(ǫ/(n log(n/ǫ))1/4).) – Learning origin-centered halfspaces with respect to any isotropic log-concave distribution on Rn with malicious noise rate η = Ω(ǫ3 / log(n/ǫ)). This is the first efficient algorithm for learning under isotropic log-concave distribu-tions in the presence of malicious noise. We also give a poly(n, 1/ǫ)-time algorithm for learning origin-centered half-spaces under any isotropic log-concave distribution on Rn in the presence of adversarial label noise at rate η = Ω(ǫ3 / log(1/ǫ)). In the adversarial label noise setting (or agnostic model), labels can be noisy, but not example points themselves. Previous results could handle η = Ω(ǫ) but had running time expo-nential in an unspecified function of 1/ǫ. Our analysis crucially exploits both concentration and anti-concentration prop-erties of isotropic log-concave distributions. Our algorithms combine an itera-tive outlier removal procedure using Principal Component Analysis together with “smooth ” boosting. 1