Abstract
We connect adversarial training for binary classification to a geometricevolution equation for the decision boundary. Relying on a perspective thatrecasts adversarial training as a regularization problem, we introduce amodified training scheme that constitutes a minimizing movements scheme for anonlocal perimeter functional. We prove that the scheme is monotone andconsistent as the adversarial budget vanishes and the perimeter localizes, andas a consequence we rigorously show that the scheme approximates a weightedmean curvature flow. This highlights that the efficacy of adversarial trainingmay be due to locally minimizing the length of the decision boundary. In ouranalysis, we introduce a variety of tools for working with the subdifferentialof a supremal-type nonlocal total variation and its regularity properties.