增强的隐蔽性类别歧视性的普遍对抗性扰乱.
Haoran Gao1, Hua Zhang1, Xin Zhang1
1State key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, 100876, China.
概括
这项研究引入了一种新的方法,用于产生更隐蔽的类歧视性通用对抗性扰动 (CD-UAPs). 增强的CD-UAP可以降低检测风险,同时保持攻击的有效性,对安全敏感的应用程序构成重大威胁.
科学领域:
- 计算机视觉 计算机视觉
- 机器学习安全 机器学习安全
- 敌对的机器学习
背景情况:
- 现有的类歧视性普遍对抗性扰动 (CD-UAPs) 对非目标类具有很高的愚蠢比率,并且很容易被检测出来.
- 目前的CD-UAP策略可能会因为它们对非目标源类的影响而被发现.
研究的目的:
- 开发一个培训框架,以生成增强的CD-UAP,以提高隐蔽性.
- 扩大CD-UAP从单个目标攻击到多个目标攻击,以获得更高的对抗精度和更低的可检测性.
主要方法:
- 目标和非目标源类集的交替训练以更新干扰.
- 引入logit配对来最大限度地减少对非目标类的影响.
- 将CD-UAP扩展到多目标攻击,将一个源类干扰到多个下沉类.
主要成果:
- 拟议的方法产生了更多的欺骗性扰动,增强了CD-UAP的隐蔽性.
- 与CIFAR-10,CIFAR-100和ImageNet数据集的基线方法相比,欺骗比率差距显著改善.
- 在GTSRB数据集上成功展示了具有高欺骗率的多目标攻击.
结论:
- 新的培训框架有效地提高了CD-UAP的隐蔽性.
- 扩展到多目标攻击提供了精确的对抗控制,降低了检测风险.
- 这项研究对安全敏感的人工智能应用构成重大威胁.
相关概念视频
Generalization, Discrimination, and Extinction
649
Generalization, discrimination, and extinction are key concepts in operant conditioning that influence how behaviors are learned and maintained.
Generalization occurs when a behavior reinforced in one context is performed in similar situations. For instance, a student who studies diligently for calculus and receives excellent grades might apply the same study habits to psychology and history, expecting similar results. Generalization shows how learning in one setting can influence behavior in...
Generalization occurs when a behavior reinforced in one context is performed in similar situations. For instance, a student who studies diligently for calculus and receives excellent grades might apply the same study habits to psychology and history, expecting similar results. Generalization shows how learning in one setting can influence behavior in...
649
Difference from Background: Limit of Detection
6.7K
The limit of detection (LOD) is the smallest amount of analyte that can be distinguished from the background noise. The LOD value corresponds to the concentration at which the analyte signal is three times larger than the standard deviation of the blank signal. Below this value, the analyte signal cannot be differentiated from the background noise. It is calculated by dividing the calibration slope by 3 times the standard deviation of the blank signals.
The LOD indicates the presence or absence...
The LOD indicates the presence or absence...
6.7K
Masking and Demasking Agents
2.5K
EDTA titrations may necessitate masking and demasking agents to temporarily protect a particular metal ion in a mixture from the EDTA reaction. These agents facilitate the sequential analysis of the metal ions by forming stable complexes with some—but not all—metal ions during certain steps.
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
2.5K
Nonconscious Mimicry
4.6K
Nonconscious mimicry occurs when individuals alter their mannerisms to match the behaviors and expressions of those nearby, without intention.
4.6K
Stereotype Content Model
14.8K
The Stereotype Content Model (SCM) was first proposed by Susan Fiske and her colleagues (Fiske, Cuddy, Glick & Xu, 2002; see also Fiske, 2012 and Fiske, 2017). The SCM specifies that when someone encounters a new group, they will stereotype them based on two metrics: warmth—or that group’s perceived intent, and how likely they are to provide help or inflict harm—and competence—or their ability to carry out that objective. Depending on the warmth-competence...
14.8K


