Interpreting vulnerabilities of multi-instance learning to adversarial perturbations

Interpreting vulnerabilities of multi-instance learning to adversarial perturbations
复制标题

DOI:
10.1016/j.patcog.2023.109725
复制
发表时间:
2022-11
期刊:
Pattern Recognit.
影响因子:
--
通讯作者:
Yu-Xuan Zhang;Hua Meng;Xueyang Cao;Zhengchun Zhou;Mei Yang;A. R. Adhikary
Yu-Xuan Zhang;Hua Meng;Xueyang Cao;Zhengchun Zhou;Mei Yang;A. R. Adhikary
中科院分区:
其他
文献类型:
--
作者:
Yu-Xuan Zhang;Hua Meng;Xueyang Cao;Zhengchun Zhou;Mei Yang;A. R. Adhikary

文献摘要

相似文献

多实例学习(MIL)是一种最新的机器学习范式,在各种现实应用中非常有用,例如图像分析、视频异常检测、文本分类等。众所周知,大多数现有的机器学习分类器非常容易受到对抗性扰动的影响。由于 MIL 是一种弱监督学习,其中信息可用于一组实例(称为包),而不是每个实例,因此对抗性扰动可能是致命的。在本文中,我们提出了两种对抗性扰动方法来分析对抗性扰动的效果,以解释 MIL 方法的漏洞。这两种算法中,一种可以针对每个包进行定制,另一种是通用算法,可以影响给定数据集中的所有包,因此具有一定的通用性。此外,通过模拟,我们已经证明了所提出的算法在欺骗最先进的 MIL 方法方面的有效性,使得这些模型对分配给袋子的标签做出错误的预测。最后,我们通过实验讨论了如何通过简单的策略处理此类对抗性扰动。源代码可在 https://github.com/InkiInki/MI-UAP 获取。
Multi-instance learning (MIL) is a recent machine learning paradigm which is immensely useful in various real-life applications, like image analysis, video anomaly detection, text classification, etc. It is well known that most of the existing machine learning classifiers are highly vulnerable to adversarial perturbations. Since MIL is a weakly supervised learning, where information is available for a set of instances, called bag and not for every instance, adversarial perturbations can be fatal. In this paper, we have proposed two adversarial perturbation methods to analyze the effect of adversarial perturbations to interpret the vulnerabilities of MIL methods. Out of the two algorithms, one can be customized for every bag, and the other is a universal one, which can affect all bags in a given data set and thus has some generalizability. Furthermore, through simulations, we have demonstrated the efficacy of the proposed algorithms in fooling state-of-the-art MIL approaches, such that these models make incorrect predictions regarding the label assigned to the bag. Finally, we have discussed, through experiments, about taking care of these kind of adversarial perturbations through a simple strategy.Source codesare available athttps://github.com/InkiInki/MI-UAP.