Towards Understanding the Dynamics of Adversarial Attacks

Towards Understanding the Dynamics of Adversarial Attacks
复制标题

DOI:
10.1145/3243734.3278528
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Yujie Ji;Ting Wang
Yujie Ji;Ting Wang
中科院分区:
其他
文献类型:
--
作者:
Yujie Ji;Ting Wang

文献摘要

相似文献

深度神经网络 (DNN) 的一个有趣特性是它们对对抗性输入的固有脆弱性,这极大地阻碍了 DNN 在安全关键领域的应用。尽管关于对抗性攻击和防御的工作很多,但有关对抗性输入的推理行为的许多重要问题仍然是神秘的。这项工作通过调查各种 DNN 模型中正常输入和对抗性输入的信息流并对它们的判别模式进行深入的比较分析,为回答这些问题迈出了坚实的一步。我们的工作为设计更有效的防御机制指出了几个有希望的方向。
An intriguing property of deep neural networks (DNNs) is their inherent vulnerability to adversarial inputs, which significantly hinder the application of DNNs in security-critical domains. Despite the plethora of work on adversarial attacks and defenses, many important questions regarding the inference behaviors of adversarial inputs remain mysterious. This work represents a solid step towards answering those questions by investigating the information flows of normal and adversarial inputs within various DNN models and conducting in-depth comparative analysis of their discriminative patterns. Our work points to several promising directions for designing more effective defense mechanisms.