On the Need for Topology-Aware Generative Models for Manifold-Based Defenses

On the Need for Topology-Aware Generative Models for Manifold-Based Defenses
复制标题

DOI:
--
复制
发表时间:
2019-09
期刊:
arXiv: Learning
影响因子:
--
通讯作者:
Uyeong Jang;Susmit Jha;S. Jha
Uyeong Jang;Susmit Jha;S. Jha
中科院分区:
其他
文献类型:
--
作者:
Uyeong Jang;Susmit Jha;S. Jha

文献摘要

被引文献

相似文献

机器学习(ML)算法或模型,特别是深度神经网络(DNN),在多个领域显示出了巨大的前景。然而,研究人员最近证明,ML算法,特别是DNN,容易受到对抗性样本(导致错误分类的轻微扰动样本)的影响。对抗性示例的存在阻碍了ML算法在安全关键领域(如安全)的部署。在文献中有几种对抗性例子的辩护。其中一类重要的防御是基于流形的防御,其中样本在分类之前被“拉回”到数据流形中。这些防御依赖于数据位于比输入空间更低维度的流形中的假设。这些防御使用生成模型来近似输入分布。在本文中,我们调查了以下问题:在流形为基础的防御中使用的生成模型需要拓扑感知?我们认为答案是肯定的,并且我们提供了理论和经验证据来支持我们的主张。
Machine-learning (ML) algorithms or models, especially deep neural networks (DNNs), have shown significant promise in several areas. However, researchers have recently demonstrated that ML algorithms, especially DNNs, are vulnerable to adversarial examples (slightly perturbed samples that cause misclassification). The existence of adversarial examples has hindered the deployment of ML algorithms in safety-critical sectors, such as security. Several defenses for adversarial examples exist in the literature. One of the important classes of defenses are manifold-based defenses, where a sample is ``pulled back" into the data manifold before classifying. These defenses rely on the assumption that data lie in a manifold of a lower dimension than the input space. These defenses use a generative model to approximate the input distribution. In this paper, we investigate the following question: do the generative models used in manifold-based defenses need to be topology-aware? We suggest the answer is yes, and we provide theoretical and empirical evidence to support our claim.