拉菲特:有效和可靠的对抗防御的评估与潜在的特征
IEEE transactions on pattern analysis and machine intelligence
|October 13, 2023
概括
深层卷积神经网络 (CNN) 容易受到对抗性攻击. 一个新的白盒攻击,LAFIT,通过使用防御者的潜在特征和一种新的损失函数,有效地评估CNN的强度.
科学领域:
- 人工智能的人工智能
- 机器学习 机器学习
- 计算机视觉 计算机视觉
背景情况:
- 深层卷积神经网络 (CNN) 容易受到对抗性攻击,构成安全风险.
- 目前用于评估CNN对攻击的强度的现有方法通常是低效或不准确的.
研究的目的:
- 提出一种新的白盒攻击策略,LAFIT,以更有效地评估CNN的稳定性.
- 解决当前对抗性攻击方法的局限性,以评估深度学习模型防御.
主要方法:
- 开发了一个统一的白盒攻击策略,命名为LAFIT.
- 拉菲特利用防御者的潜伏特征在其梯度下降步骤中.
- 引入了一个新的损失函数来规范逻辑,减轻基于浮点的梯度掩盖.
主要成果:
- 与最先进的方法相比,LAFIT显示出更高的效率和对抗力.
- 攻击的有效性是通过各种防御机制验证的.
- 拉菲特强调了利用模型的内部组件进行稳定性评估的重要性.
结论:
- 竞争力的强度受到模型隐藏特征的利用的影响.
- 稳定性评估应考虑内部模型组件,而不是整体方法.
- 拉菲特为对抗防御研究提供了一个更准确,更有效的基准.
相关概念视频
Confidence Coefficient
7.6K
The confidence coefficient is also known as the confidence level or degree of confidence. It is the percent expression for the probability, 1-α, that the confidence interval contains the true population parameter assuming that the confidence interval is obtained after sufficient unbiased sampling; for example, if the CL = 90%, then in 90 out of 100 samples the interval estimate will enclose the true population parameter. Here α is the area under the curve, distributed equally under...
7.6K
Masking and Demasking Agents
2.5K
EDTA titrations may necessitate masking and demasking agents to temporarily protect a particular metal ion in a mixture from the EDTA reaction. These agents facilitate the sequential analysis of the metal ions by forming stable complexes with some—but not all—metal ions during certain steps.
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
2.5K
Wald-Wolfowitz Runs Test II
251
The Wald-Wolfowitz runs test, commonly referred to as the runs test, is a nonparametric test used to assess the randomness of ordered data. The test evaluates the number of runs, which are consecutive sequences of similar elements within the data. If the number of runs is significantly higher or lower than expected, the data is considered non-random, indicating a detectable pattern or structure.
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
251
Force Classification
1.2K
Forces play a crucial role in the study of physics and engineering. They are essential in describing the motion, behavior, and equilibrium of objects in the physical world. Forces can be classified based on their origin, type, and direction of action.
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...
1.2K
Hypothesis: Accept or Fail to Reject?
27.9K
The outcome of any hypothesis testing leads to rejecting or not rejecting the null hypothesis. This decision is taken based on the analysis of the data, an appropriate test statistic, an appropriate confidence level, the critical values, and P-values. However, when the evidence suggests that the null hypothesis cannot be rejected, is it right to say, 'Accept' the null hypothesis?
There are two ways to indicate that the null hypothesis is not rejected. 'Accept' the null...
There are two ways to indicate that the null hypothesis is not rejected. 'Accept' the null...
27.9K
Accuracy and Errors in Hypothesis Testing
204
Hypothesis testing is a fundamental statistical tool that begins with the assumption that the null hypothesis H0 is true. During this process, two types of errors can occur: Type I and Type II. A Type I error refers to the incorrect rejection of a true null hypothesis, while a Type II error involves the failure to reject a false null hypothesis.
In hypothesis testing, the probability of making a Type I error, denoted as α, is commonly set at 0.05. This significance level indicates a 5%...
In hypothesis testing, the probability of making a Type I error, denoted as α, is commonly set at 0.05. This significance level indicates a 5%...
204


