Understanding and Quantifying Adversarial Examples Existence in Linear Classification

Understanding and Quantifying Adversarial Examples Existence in Linear Classification
复制标题

DOI:
10.1109/icmlc56445.2022.9941315
复制
发表时间:
2019-10
期刊:
2022 International Conference on Machine Learning and Cybernetics (ICMLC)
影响因子:
--
通讯作者:
Xupeng Shi;A. Ding
Xupeng Shi;A. Ding
中科院分区:
其他
文献类型:
--
作者:
Xupeng Shi;A. Ding

文献摘要

被引文献

相似文献

最新的深度神经网络(DNN)容易受到敌意例子的攻击:精心设计的对输入的微小扰动,对人类来说是不可感知的,可能会误导DNN。为了理解对抗性实例的根本原因,我们对线性分类器的对抗性实例存在的概率进行了量化。以前的对抗性例子的数学定义只涉及整体的扰动量,我们提出了一个更实用的强对抗性例子的相关定义,该定义也分别限制了沿信号方向的扰动。我们证明了在先前定义下不存在对抗性稳健线性分类器的情况下,线性分类器可以对强对抗性例子攻击具有健壮性。结果表明,设计一般的强对抗性-健壮性学习系统是可行的,但必须结合人类对潜在分类问题的知识。
State-of-art deep neural networks (DNN) are vulnerable to attacks by adversarial examples: a carefully designed small perturbation to the input, that is imperceptible to human, can mislead DNN. To understand the root cause of adversarial examples, we quantify the probability of adversarial example existence for linear classifiers. Previous mathematical definition of adversarial examples only involves the overall perturbation amount, and we propose a more practical relevant definition of strong adversarial examples that separately limits the perturbation along the signal direction also. We show that linear classifiers can be made robust to strong adversarial examples attack in cases where no adversarial robust linear classifiers exist under the previous definition. The results suggest that designing general strong-adversarial-robust learning systems is feasible but only through incorporating human knowledge of the underlying classification problem.