Convex Basins in Single-Index Model Loss Landscapes: Applications to Robust Recovery under Strong Adversarial Corruption
Abstract
Lay Summary
Imagine trying to learn the nonlinear rule that relates property features to house prices by aggregating thousands of listings. Two kinds of corruption make this hard. - First, every homeowner has personal idiosyncrasies (one prizes a bay view, another a large kitchen) that add random, occasionally extreme noise to their asking price; a single eccentric seller might list at ten times the market rate, skewing any naive estimate. - Second, a coordinated price-fixing cartel can strategically falsify both the property details and the asking prices of a fraction of listings, no matter how the learning algorithm works. We give the first provably efficient algorithm for nonlinear regression that handles both corruptions simultaneously, recovering the nonlinear pricing rule and the relevant combination of property features even when the relationship between features and price is non-monotone (for example, an extra bedroom may help in a small flat but barely matter in a mansion), the idiosyncratic noise is occasionally extreme, and the cartel corrupts a constant fraction of both features and prices. Computational guarantees for nonlinear regression under both corruptions were previously known only for monotone and/or highly structured pricing rules. Our framework applies directly to a large class of activation functions that include GeLU and Swish which are the scalar primitives in Transformers. Therefore, we provide the first theoretical guarantee that these building blocks can be learned reliably under adversarial data poisoning. This is particularly relevant for large language models, which are trained on vast web-scraped datasets that inevitably contain strategically corrupted or manipulated content.