Generalized Likelihood Ratio Test for Adversarially Robust Hypothesis Testing

Generalized Likelihood Ratio Test for Adversarially Robust Hypothesis Testing
复制标题

DOI:
10.1109/tsp.2022.3198169
复制
发表时间:
2021-12
影响因子:
5.4
通讯作者:
Bhagyashree Puranik;Upamanyu Madhow;Ramtin Pedarsani
Bhagyashree Puranik;Upamanyu Madhow;Ramtin Pedarsani
中科院分区:
工程技术1区
文献类型:
--
作者:
Bhagyashree Puranik;Upamanyu Madhow;Ramtin Pedarsani

文献摘要

被引文献

相似文献

已知机器学习模型容易受到对抗攻击的影响,这可能会通过引入小但设计精良的扰动而导致错误分类。在本文中,我们考虑了一个经典的假设检验问题,以便开发出针对这种对抗性扰动的基本见解。我们将对抗性扰动解释为滋扰参数,并提出了基于将广义似然比测试(GLRT)应用于所得的复合假设检验问题的防御,共同估计了兴趣类别和对抗性扰动。虽然GLRT方法适用于一般多级假设测试,但我们首先将其评估用于在$ \ ell _ {\ ell _ {\ elfty} $ norm-norm-nord-nord-nord-nord-nord-nound-nound ofders-corseversarial扰动下进行二进制假设测试,为此,已知的最小值防御优化最糟糕的攻击提供了基准。我们为GLRT防御提供了最糟糕的案例攻击,并表明其渐近性能(随着数据的增加而增加)接近了最小值防御。对于非反应政权,我们通过模拟表明,GLRT防御在最严重的攻击下与Minimax方法具有竞争力,同时在较弱的攻击下产生了更好的稳健性 - 千里化权衡。我们还说明了多级假设测试问题的GLRT方法,为此尚不清楚minimax策略,通过提供一种方法来找到一种最佳的噪声攻击,评估其在噪声和噪声吸引的对抗环境下的性能以及在高SNR制度中找到接近最佳噪声攻击的想法。我们通过实验显示了GLRT防御在有色高斯噪声中的应用。我们还通过考虑Laplacian噪声并说明了我们的规则如何简化,我们还证明了GLRT防御超出高斯环境的使用。
Machine learning models are known to be susceptible to adversarial attacks, which can cause misclassification by introducing small but well designed perturbations. In this paper, we consider a classical hypothesis testing problem in order to develop fundamental insight into defending against such adversarial perturbations. We interpret an adversarial perturbation as a nuisance parameter, and propose a defense based on applying the generalized likelihood ratio test (GLRT) to the resulting composite hypothesis testing problem, jointly estimating the class of interest and the adversarial perturbation. While the GLRT approach is applicable to general multi-class hypothesis testing, we first evaluate it for binary hypothesis testing in white Gaussian noise under $\ell _{\infty }$ norm-bounded adversarial perturbations, for which a known minimax defense optimizing for the worst-case attack provides a benchmark. We derive the worst-case attack for the GLRT defense, and show that its asymptotic performance (as the dimension of the data increases) approaches that of the minimax defense. For non-asymptotic regimes, we show via simulations that the GLRT defense is competitive with the minimax approach under the worst-case attack, while yielding a better robustness-accuracy trade-off under weaker attacks. We also illustrate the GLRT approach for a multi-class hypothesis testing problem, for which a minimax strategy is not known, evaluating its performance under both noise-agnostic and noise-aware adversarial settings, by providing a method to find optimal noise-aware attacks, and ideas to find noise-agnostic attacks that are close to optimal in the high SNR regime. We show through experiments the application of the GLRT defense in colored Gaussian noise. We also demonstrate the use of GLRT defense beyond Gaussian settings by considering Laplacian noise and illustrating how our rule simplifies.