On the Limitations of Stochastic Pre-processing Defenses

On the Limitations of Stochastic Pre-processing Defenses
复制标题

DOI:
10.48550/arxiv.2206.09491
复制
发表时间:
2022-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Yue Gao;Ilia Shumailov;Kassem Fawaz;Nicolas Papernot
Yue Gao;Ilia Shumailov;Kassem Fawaz;Nicolas Papernot
中科院分区:
其他
文献类型:
--
作者:
Yue Gao;Ilia Shumailov;Kassem Fawaz;Nicolas Papernot

文献摘要

相似文献

抵御敌意的例子仍然是一个悬而未决的问题。一种普遍的看法是,推理的随机性增加了寻找敌对输入的成本。这种防御的一个例子是在将输入提供给模型之前对它们应用随机转换。在本文中,我们从经验和理论上研究了这种随机预处理防御机制,并证明了它们是有缺陷的。首先,我们证明了大多数随机防御比之前认为的要弱;它们缺乏足够的随机性,即使是像投影梯度下降这样的标准攻击也是如此。这让人对一个长期持有的假设产生了怀疑,即随机防御使旨在逃避确定性防御的攻击无效,并迫使攻击者整合期望过转换(EOT)概念。其次,我们证明了随机防御面临着对抗稳健性和模型不变性之间的权衡;随着被防御模型对其随机化获得更多的不变性,它们变得不那么有效。未来的工作将需要将这两种影响脱钩。我们还讨论了对未来研究的启示和指导。
Defending against adversarial examples remains an open problem. A common belief is that randomness at inference increases the cost of finding adversarial inputs. An example of such a defense is to apply a random transformation to inputs prior to feeding them to the model. In this paper, we empirically and theoretically investigate such stochastic pre-processing defenses and demonstrate that they are flawed. First, we show that most stochastic defenses are weaker than previously thought; they lack sufficient randomness to withstand even standard attacks like projected gradient descent. This casts doubt on a long-held assumption that stochastic defenses invalidate attacks designed to evade deterministic defenses and force attackers to integrate the Expectation over Transformation (EOT) concept. Second, we show that stochastic defenses confront a trade-off between adversarial robustness and model invariance; they become less effective as the defended model acquires more invariance to their randomization. Future work will need to decouple these two effects. We also discuss implications and guidance for future research.