论文标题

仔细观察对l-内在和空间扰动的鲁棒性及其组成

A Closer Look at Robustness to L-infinity and Spatial Perturbations and their Composition

论文作者

Rowe, Luke, Thérien, Benjamin, Czarnecki, Krzysztof, Zhang, Hongyang

论文摘要

在对抗机器学习中,流行的$ \ ell_ \ infty $ thrat模型一直是以前工作的重点。虽然这种对无智能的数学定义成功地捕获了一组无限的添加图像转换,该模型应该是可靠的,但这只是所有转换的子集,这些转换使图像不变的语义标签保持不变。确实,以前的工作还考虑了空间攻击以及其他语义转换的鲁棒性。但是,针对空间和$ \ ell _ {\ infty} $扰动设计防御方法仍然相对不受欢迎。在下文中,我们很少提高对这一研究的组成设置的理解。从理论上讲,我们在简单的统计环境中,没有线性分类器对复合对手的琐碎精度超过了,这说明了其难度。然后,我们研究了最新的$ \ ell _ {\ infty} $防御能力如何适应这种新颖的威胁模型,并研究其针对构图攻击的绩效。我们发现,我们新提出的交易$ _ {\ text {ash as ast {all}} $策略在所有方面都表现最强。分析其Logit的Lipschitz常数以用于不同尺寸的RT转换,我们发现交易$ _ {\ text {ash as all}} $在带有和没有$ \ ell_ \ ell_ \ infty $ intturtations的宽RT转换中保持稳定。

In adversarial machine learning, the popular $\ell_\infty$ threat model has been the focus of much previous work. While this mathematical definition of imperceptibility successfully captures an infinite set of additive image transformations that a model should be robust to, this is only a subset of all transformations which leave the semantic label of an image unchanged. Indeed, previous work also considered robustness to spatial attacks as well as other semantic transformations; however, designing defense methods against the composition of spatial and $\ell_{\infty}$ perturbations remains relatively underexplored. In the following, we improve the understanding of this seldom investigated compositional setting. We prove theoretically that no linear classifier can achieve more than trivial accuracy against a composite adversary in a simple statistical setting, illustrating its difficulty. We then investigate how state-of-the-art $\ell_{\infty}$ defenses can be adapted to this novel threat model and study their performance against compositional attacks. We find that our newly proposed TRADES$_{\text{All}}$ strategy performs the strongest of all. Analyzing its logit's Lipschitz constant for RT transformations of different sizes, we find that TRADES$_{\text{All}}$ remains stable over a wide range of RT transformations with and without $\ell_\infty$ perturbations.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源