Assessing Optimizer Impact on DNN Model Sensitivity to Adversarial Examples

Assessing Optimizer Impact on DNN Model Sensitivity to Adversarial Examples
复制标题

DOI:
10.1109/access.2019.2948658
复制
发表时间:
2019-10
期刊:
影响因子:
3.9
通讯作者:
Yixiang Wang;Jiqiang Liu;J. Misic;V. Mišić;Shaohua Lv;Xiaolin Chang
Yixiang Wang;Jiqiang Liu;J. Misic;V. Mišić;Shaohua Lv;Xiaolin Chang
中科院分区:
计算机科学3区
文献类型:
--
作者:
Yixiang Wang;Jiqiang Liu;J. Misic;V. Mišić;Shaohua Lv;Xiaolin Chang

文献摘要

被引文献

相似文献

与许多传统的机器学习(ML)模型相比,深度神经网络(DNN)在各个领域都取得了最新的成就。然而,敌意的例子对DNN的进一步部署和应用提出了挑战。对DNN易受敌意干扰的原因进行了分析,并重点研究了模型体系结构。目前还没有关于DNN模型训练中使用的优化算法(即DNN中的优化器)对模型对敌意例子敏感性的影响的研究。本文旨在从实验的角度研究这一影响。我们不仅从白盒和黑盒攻击设置的角度分析了模型的敏感性,还从不同类型的数据集的角度分析了模型的敏感度。在结构化和非结构化数据集上对四种常见的优化器SGD、RMSprop、Adadelta和Adam进行了研究。大量的实验结果表明,优化算法确实会影响DNN模型对敌意例子的敏感度。也就是说,在训练模型和生成对抗性实例时,Adam优化器可以为结构化数据集生成质量更好的对抗性实例,Adadelta优化器可以为非结构化数据集生成更好质量的对抗性实例。此外,优化器的选择不影响对抗性例子的可转移性。
Deep Neural Networks (DNNs) have been gaining state-of-the-art achievement compared with many traditional Machine Learning (ML) models in diverse fields. However, adversarial examples challenge the further deployment and application of DNNs. Analysis has been carried out for studying the reasons of DNNs’ vulnerability to adversarial perturbation and focused on model architecture. No research has been done on investigating the impact of optimization algorithms (namely, optimizers in DNNs) employed in training DNN models on models’ sensitivity to adversarial examples. This paper aims to study this impact from an experimental perspective. We analyze the sensitivity of a model not only from the aspect of white-box and black-box attack setups, but also from the aspect of different types of datasets. Four common optimizers, SGD, RMSprop, Adadelta, and Adam, are investigated on structured and unstructured datasets. Extensive experiment results indicate that an optimization algorithm does pose effects on the DNN model sensitivity to adversarial examples. That is, when training models and generating adversarial examples, Adam optimizer can generate better quality adversarial examples for structured datasets, and Adadelta optimizer can generate better quality adversarial examples for unstructured datasets. In addition, the choice of optimizers does not affect the transferability of adversarial examples.