Robust deep neural network surrogate models with uncertainty quantification via adversarial training

Robust deep neural network surrogate models with uncertainty quantification via adversarial training
复制标题

DOI:
10.1002/sam.11610
复制
发表时间:
2023-01
期刊:
Statistical Analysis and Data Mining: The ASA Data Science Journal
影响因子:
--
通讯作者:
Lixiang Zhang;Jia Li
Lixiang Zhang;Jia Li
中科院分区:
其他
文献类型:
--
作者:
Lixiang Zhang;Jia Li

文献摘要

相似文献

替代模型已用于模拟物理或生物过程的数学模拟器,以提高计算效率。当模拟必须在许多随机采样的输入点(又称蒙特卡罗方法)上重复时,高速模拟对于进行不确定性量化(UQ)至关重要。模拟器的计算量可能非常大,以至于 UQ 只能通过代理模型来实现。最近,深度神经网络 (DNN) 代理模型因其最先进的仿真精度而广受欢迎。然而,众所周知,当输入数据以特定方式受到扰动时,DNN 很容易出现严重错误,这种现象引起了人们对对抗性训练的极大兴趣。就代理模型而言,人们所担心的不是利用 DNN 漏洞的蓄意攻击,而是其准确性对输入方向的高度敏感性,而使用仿真模型的研究人员在很大程度上忽视了这一问题。在本文中,我们通过实证研究和假设检验展示了这个问题的严重性。此外,我们采用对抗训练方法来增强 DNN 代理模型的鲁棒性。实验表明,我们的方法显着提高了替代模型的鲁棒性,同时又不影响仿真精度。
Surrogate models have been used to emulate mathematical simulators of physical or biological processes for computational efficiency. High‐speed simulation is crucial for conducting uncertainty quantification (UQ) when the simulation must repeat over many randomly sampled input points (aka the Monte Carlo method). A simulator can be so computationally intensive that UQ is only feasible with a surrogate model. Recently, deep neural network (DNN) surrogate models have gained popularity for their state‐of‐the‐art emulation accuracy. However, it is well‐known that DNN is prone to severe errors when input data are perturbed in particular ways, the very phenomenon which has inspired great interest in adversarial training. In the case of surrogate models, the concern is less about a deliberate attack exploiting the vulnerability of a DNN but more of the high sensitivity of its accuracy to input directions, an issue largely ignored by researchers using emulation models. In this paper, we show the severity of this issue through empirical studies and hypothesis testing. Furthermore, we adopt methods in adversarial training to enhance the robustness of DNN surrogate models. Experiments demonstrate that our approaches significantly improve the robustness of the surrogate models without compromising emulation accuracy.