Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples

Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
复制标题

DOI:
--
复制
发表时间:
2018-02
期刊:
--
影响因子:
--
通讯作者:
Anish Athalye;Nicholas Carlini;D. Wagner
Anish Athalye;Nicholas Carlini;D. Wagner
中科院分区:
其他
文献类型:
--
作者:
Anish Athalye;Nicholas Carlini;D. Wagner

文献摘要

被引文献

相似文献

我们将模糊梯度(一种梯度掩蔽)识别为一种现象,这种现象会导致对抗性示例的防御中出现错误的安全感。虽然导致模糊梯度的防御似乎击败了基于迭代优化的攻击,但我们发现依赖于这种效果的防御可以被规避。我们描述了表现出这种效果的防御的特征行为,并针对我们发现的三种混淆梯度中的每一种,开发了攻击技术来克服它。在一个案例研究中,在ICLR 2018上检查了未经认证的白盒安全防御,我们发现混淆梯度是常见的,9种防御中有7种依赖于混淆梯度。我们的新攻击成功地规避6完全,1部分,在原始的威胁模型,每个文件考虑。
We identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples. While defenses that cause obfuscated gradients appear to defeat iterative optimization-based attacks, we find defenses relying on this effect can be circumvented. We describe characteristic behaviors of defenses exhibiting the effect, and for each of the three types of obfuscated gradients we discover, we develop attack techniques to overcome it. In a case study, examining non-certified white-box-secure defenses at ICLR 2018, we find obfuscated gradients are a common occurrence, with 7 of 9 defenses relying on obfuscated gradients. Our new attacks successfully circumvent 6 completely, and 1 partially, in the original threat model each paper considers.