A Robust Likelihood Model for Novelty Detection

A Robust Likelihood Model for Novelty Detection
复制标题

DOI:
10.48550/arxiv.2306.03331
复制
发表时间:
2023-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Ranya Almohsen;Shivang Patel;Don Adjeroh;Gianfranco Doretto
Ranya Almohsen;Shivang Patel;Don Adjeroh;Gianfranco Doretto
中科院分区:
其他
文献类型:
--
作者:
Ranya Almohsen;Shivang Patel;Don Adjeroh;Gianfranco Doretto

文献摘要

相似文献

目前的新奇或异常检测方法是基于深度神经网络的。尽管它们的有效性,神经网络也容易受到输入数据的不可察觉的变形。这在关键应用程序中是一个严重的问题,或者当数据更改由对抗性攻击产生时。虽然这是近年来在监督学习的情况下研究的已知问题,但新奇检测的情况受到的关注非常有限。事实上,在后一种情况下,学习通常是无监督的,因为在训练过程中没有离群数据,需要研究这种情况下的新方法。我们提出了一个新的先验,旨在学习一个强大的可能性的新奇测试,作为防御攻击。我们还将相同的先验知识与最先进的新奇检测方法相结合。由于该方法的几何特性,所得到的鲁棒训练在计算上非常有效。该方法的初步评估表明,它是有效的,在没有和存在的攻击的情况下,相对于标准模型的性能提高。
Current approaches to novelty or anomaly detection are based on deep neural networks. Despite their effectiveness, neural networks are also vulnerable to imperceptible deformations of the input data. This is a serious issue in critical applications, or when data alterations are generated by an adversarial attack. While this is a known problem that has been studied in recent years for the case of supervised learning, the case of novelty detection has received very limited attention. Indeed, in this latter setting the learning is typically unsupervised because outlier data is not available during training, and new approaches for this case need to be investigated. We propose a new prior that aims at learning a robust likelihood for the novelty test, as a defense against attacks. We also integrate the same prior with a state-of-the-art novelty detection approach. Because of the geometric properties of that approach, the resulting robust training is computationally very efficient. An initial evaluation of the method indicates that it is effective at improving performance with respect to the standard models in the absence and presence of attacks.