Adversarial ink: componentwise backward error attacks on deep learning

Adversarial ink: componentwise backward error attacks on deep learning
复制标题

对抗性墨水:深度学习的组件式后向错误攻击

DOI:
10.1093/imamat/hxad017
复制
发表时间:
2023
影响因子:
1.2
通讯作者:
Beerens L
Beerens L
中科院分区:
数学4区
文献类型:
--
作者:
Beerens L

文献摘要

相似文献

深度神经网络在许多分类任务中具有最先进的性能。然而,众所周知,它们很容易受到对抗性攻击——输入的微小扰动会导致分类的变化。我们从逆向误差和条件数的角度来解决这个问题,这些概念在数值分析中被证明是有用的。为此,我们以Beuzeville, T., Boudier, P., Buttari, A., Gratton, S., Mary, T.和Pralet S.(2021)的工作为基础,通过向后错误分析进行对抗性攻击。Hal-03296180,版本3。特别是,我们开发了一类新的攻击算法,使用组件相对摄动。这种攻击与手写文件或印刷文本高度相关,例如,签名的分类、邮政编码、日期或数字数量可以通过改变墨水的一致性而不是背景来改变。这使得被干扰的图像在肉眼看来很自然。因此,这种“对抗性墨水”攻击暴露了一个可能对安全和安保产生严重影响的弱点。我们举例说明了针对真实数据的新攻击,并将它们与现有算法进行了对比。我们还研究了使用组件条件数来量化脆弱性。
Deep neural networks are capable of state-of-the-art performance in many classification tasks. However, they are known to be vulnerable to adversarial attacks—small perturbations to the input that lead to a change in classification. We address this issue from the perspective of backward error and condition number, concepts that have proved useful in numerical analysis. To do this, we build on the work of Beuzeville, T., Boudier, P., Buttari, A., Gratton, S., Mary, T. and Pralet S. (2021) Adversarial attacks via backward error analysis. hal-03296180, version 3. In particular, we develop a new class of attack algorithms that use componentwise relative perturbations. Such attacks are highly relevant in the case of handwritten documents or printed texts where, for example, the classification of signatures, postcodes, dates or numerical quantities may be altered by changing only the ink consistency and not the background. This makes the perturbed images look natural to the naked eye. Such ‘adversarial ink’ attacks therefore reveal a weakness that can have a serious impact on safety and security. We illustrate the new attacks on real data and contrast them with existing algorithms. We also study the use of a componentwise condition number to quantify vulnerability.