通过适应性边际进化改善深度神经网络的对抗性强度
1Department of Computer Science, University of Miami, 1365 Memorial Drive, Coral Gables, 33146, FL, USA.
概括
适应边际进化 (AME) 是一种新的,无超参数的方法,可以增强深度神经网络 (DNN) 对抗敌对攻击的稳定性. AME在基准数据集上取得了卓越的表现,使对抗性培训更容易获得.
科学领域:
- 计算机科学 计算机科学
- 人工智能的人工智能
- 机器学习 机器学习
背景情况:
- 深度神经网络 (DNN) 容易受到敌对攻击.
- 敌对训练提高了DNN的稳定性,但往往需要广泛的超参数调整.
- 现有的方法对训练噪声上限等超参数敏感,限制了实际应用.
研究的目的:
- 引入适应性边际进化 (AME),一种新的,无超参数的对抗性训练方法.
- 提高对抗性培训技术的可访问性和适用性.
- 为了增强深度神经网络 (DNN) 对抗对抗噪音的稳定性.
主要方法:
- 开发了自适应边际进化 (AME),一种优化对抗训练样本配置的方法.
- AME使用自适应和渐变感知的步骤大小来扩大勘探范围.
- 使用AutoAttack对CIFAR10,SVHN和Tiny ImageNet数据集的其他七种对抗性训练方法进行了评估.
主要成果:
- 在所有三个基准数据集中,AME表现出优异的整体表现.
- 在具有挑战性的Tiny ImageNet数据集上,AME在所有噪声水平上取得了最佳表现.
- 拟议的方法显著提高了DNN的稳定性,而不需要用户定义的超参数.
结论:
- 适应性边际进化 (AME) 提供了一个强大的和用户友好的对抗训练方法.
- 由于AME无超参数的性质,因此在各种应用领域中更容易采用对抗性稳定性技术.
- 这项研究为在现实世界中更广泛地使用对抗训练铺平了道路.
相关概念视频
Improving Translational Accuracy
11.6K
Base complementarity between the three base pairs of mRNA codon and the tRNA anticodon is not a failsafe mechanism. Inaccuracies can range from a single mismatch to no correct base pairing at all. The free energy difference between the correct and nearly correct base pairs can be as small as 3 kcal/ mol. With complementarity being the only proofreading step, the estimated error frequency would be one wrong amino acid in every 100 amino acids incorporated. However, error frequencies observed in...
11.6K
Margin of Error
4.3K
The margin of error is also called the maximum error of an estimate. The margin of error is the maximum possible or expected difference between the observed sample parameter value and the actual population parameter value. For proportion, it is the maximum difference between the value of sample proportion obtained from the data and the true value of population proportion. As the true value of the population parameter is not known, the margin of error is calculated using the sample statistic.
4.3K
Survival Tree
109
Survival trees are a non-parametric method used in survival analysis to model the relationship between a set of covariates and the time until an event of interest occurs, often referred to as the "time-to-event" or "survival time." This method is particularly useful when dealing with censored data, where the event has not occurred for some individuals by the end of the study period, or when the exact time of the event is unknown.
Building a Survival Tree
Constructing a...
Building a Survival Tree
Constructing a...
109
Neural Regulation
39.5K
Digestion begins with a cephalic phase that prepares the digestive system to receive food. When our brain processes visual or olfactory information about food, it triggers impulses in the cranial nerves innervating the salivary glands and stomach to prepare for food.
39.5K
Reducing Line Loss
173
In a three-phase circuit, line loss is an indicator of energy dissipated as heat due to the resistance of transmission lines. To address this, incorporating transformers into the system—a step-up transformer at the source and a step-down transformer at the load—is a strategic solution. Two three-phase transformers are introduced to improve this.
With a step-up transformer at the source, the voltage is increased, thereby reducing the current in the transmission lines since power loss...
With a step-up transformer at the source, the voltage is increased, thereby reducing the current in the transmission lines since power loss...
173
Mean Absolute Deviation
2.7K
The mean absolute deviation is also a measure of the variability of data in a sample. It is the absolute value of the average difference between the data values and the mean.
Let us consider a dataset containing the number of unsold cupcakes in five shops: 10, 15, 8, 7, and 10. Initially, calculate the sample mean. Then calculate the deviation, or the difference, between each data value and the mean. Next, the absolute values of these deviations are added and divided by the sample size to...
Let us consider a dataset containing the number of unsold cupcakes in five shops: 10, 15, 8, 7, and 10. Initially, calculate the sample mean. Then calculate the deviation, or the difference, between each data value and the mean. Next, the absolute values of these deviations are added and divided by the sample size to...
2.7K


