GraphGuard:一种适应性方法,用于恢复被后门破坏的GNN的准确性
Adil Ahmad1, Anwar Shah2, Waleed Alnumay3
1National University of Computer and Emerging Science, Faisalabad, Pakistan.
概括
这项研究引入了一种新的方法,用于在后门攻击后恢复图形神经网络 (GNN) 的准确性. 这种方法使用过和增强来防御隐藏的触发器,实现高精度的恢复.
科学领域:
- 人工智能
- 机器学习安全性
背景情况:
- 后门攻击威胁到机器学习模型,特别是图形神经网络 (GNN).
- 现有的防御通常集中在检测上,而不是准确地恢复模型性能.
- 图形数据的复杂结构使GNN防御策略变得复杂.
研究的目的:
- 开发一种方法来恢复被后门攻击破坏的GNN的原始准确性.
- 增强GNN对隐藏的触发器和有毒输入的抵抗力.
- 提高攻击后GNN决策的可解释性.
主要方法:
- 结合先进的过来删除可疑的数据点和增强来加强GNN的触发.
- 实施适应性框架以平衡基于攻击严重程度和模型灵敏度的过和增强.
- 整合可解释的人工智能 (XAI) 技术,以透明地检测和理解后门触发器.
主要成果:
- 在各种后门攻击场景中实现了97-99%的平均准确性恢复.
- 在后门检测中有效减少虚假阳性和负性.
- 在复杂的攻击中增强GNN完整性和性能.
结论:
- 提出的方法提供了一种有效的解决方案,用于在后门攻击后恢复GNN的准确性.
- 适应性过和增强策略显著提高了模型的弹性.
- XAI的整合提高了GNN安全性的透明度和信任.
相关概念视频
Improving Translational Accuracy
2.7K
2.7K
Propagation of Uncertainty from Systematic Error
882
The atomic mass of an element varies due to the relative ratio of its isotopes. A sample's relative proportion of oxygen isotopes influences its average atomic mass. For instance, if we were to measure the atomic mass of oxygen from a sample, the mass would be a weighted average of the isotopic masses of oxygen in that sample. Since a single sample is not likely to perfectly reflect the true atomic mass of oxygen for all the molecules of oxygen on Earth, the mass we obtain from this...
882
Propagation of Uncertainty from Random Error
1.1K
An experiment often consists of more than a single step. In this case, measurements at each step give rise to uncertainty. Because the measurements occur in successive steps, the uncertainty in one step necessarily contributes to that in the subsequent step. As we perform statistical analysis on these types of experiments, we must learn to account for the propagation of uncertainty from one step to the next. The propagation of uncertainty depends on the type of arithmetic operation performed on...
1.1K

