Using Non-invertible Data Transformations to Build Adversarial-Robust Neural Networks

Using Non-invertible Data Transformations to Build Adversarial-Robust Neural Networks
复制标题

使用不可逆数据转换构建对抗性鲁棒神经网络

DOI:
--
复制
发表时间:
2016
期刊:
arXiv: Learning
影响因子:
--
通讯作者:
Gang Xiong
Gang Xiong
中科院分区:
--
文献类型:
--
作者:
Qinglong Wang;Wenbo Guo;Alexander Ororbia;Xinyu Xing;Lin Lin;C. Lee Giles;Xue Liu;Peng Liu;Gang Xiong

文献摘要

被引文献

相似文献

深度神经网络已被证明在各种机器学习任务中非常有效,从改进语音识别系统到推进自动驾驶汽车的开发。然而,尽管这些模型在许多应用中具有上级性能,但最近已被证明容易受到特定类型的攻击,这些攻击可能通过生成称为对抗样本的特定合成示例来实现。这些样本是通过从训练数据分布中操纵真实的样本来构建的,以便“愚弄”原始神经模型,从而导致先前正确分类的样本的错误分类(具有高置信度)。如果要将深度神经架构应用于关键应用(例如网络安全领域的应用),解决这一弱点至关重要。在本文中,我们对潜伏在所有神经架构中的这一基本缺陷进行了分析,以揭示先前提出的防御机制的局限性。更重要的是,我们提出了一个使用不可逆数据转换来保护深度神经模型的统一框架--开发了两个利用线性和非线性降维的对抗弹性架构。实证结果表明,我们的框架提供了更好的鲁棒性相比,国家的最先进的解决方案,同时具有可忽略不计的精度下降。
Deep neural networks have proven to be quite effective in a wide variety of machine learning tasks, ranging from improved speech recognition systems to advancing the development of autonomous vehicles. However, despite their superior performance in many applications, these models have been recently shown to be susceptible to a particular type of attack possible through the generation of particular synthetic examples referred to as adversarial samples. These samples are constructed by manipulating real examples from the training data distribution in order to "fool" the original neural model, resulting in misclassification (with high confidence) of previously correctly classified samples. Addressing this weakness is of utmost importance if deep neural architectures are to be applied to critical applications, such as those in the domain of cybersecurity. In this paper, we present an analysis of this fundamental flaw lurking in all neural architectures to uncover limitations of previously proposed defense mechanisms. More importantly, we present a unifying framework for protecting deep neural models using a non-invertible data transformation--developing two adversary-resilient architectures utilizing both linear and nonlinear dimensionality reduction. Empirical results indicate that our framework provides better robustness compared to state-of-art solutions while having negligible degradation in accuracy.