On the Adversarial Robustness of Subspace Learning

On the Adversarial Robustness of Subspace Learning
复制标题

DOI:
10.1109/icassp.2019.8683270
复制
发表时间:
2019-05
期刊:
ICASSP 2019 - 2019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
影响因子:
--
通讯作者:
Fuwei Li;L. Lai;Shuguang Cui
Fuwei Li;L. Lai;Shuguang Cui
中科院分区:
其他
文献类型:
--
作者:
Fuwei Li;L. Lai;Shuguang Cui

文献摘要

被引文献

相似文献

在本文中,我们研究了子空间学习问题的对抗鲁棒性。与假设部分数据已损坏的经典稳健算法所解决的场景不同,我们认为有一个更强大的对手,可以观察整个数据并修改所有数据。对手的目标是最大化从原始数据集学习的子空间与从修改后的数据学习的子空间之间的距离。我们描述了最优的一阶攻击策略,并表明最优策略取决于原始数据矩阵的最小奇异值和对手的能量预算。
In this paper, we investigate the adversarial robustness of subspace learning problems. Different from the scenario addressed by classic robust algorithms that assume fractions of data are corrupted, we consider a more powerful adversary who can observe the whole data and modify all of them. The goal of the adversary is to maximize the distance between the subspace learned from the original data set and that learned from the modified data. We characterize the optimal rank-one attack strategy and show that the optimal strategy depends on the smallest singular value of the original data matrix and the adversary’s energy budget.