Evolving Architectures with Gradient Misalignment toward Low Adversarial Transferability

Evolving Architectures with Gradient Misalignment toward Low Adversarial Transferability
复制标题

DOI:
10.1109/access.2021.3134840
复制
发表时间:
2021-09
期刊:
影响因子:
3.9
通讯作者:
K. Operiano;W. Pora;H. Iba;Hiroshi Kera
K. Operiano;W. Pora;H. Iba;Hiroshi Kera
中科院分区:
计算机科学3区
文献类型:
--
作者:
K. Operiano;W. Pora;H. Iba;Hiroshi Kera

文献摘要

相似文献

众所周知,深度神经网络图像分类器不仅容易受到为它们创建的对抗性示例的影响,也容易受到为其他人创建的对抗性示例的影响。这种现象对各种依赖图像分类器的黑箱系统构成了潜在的安全风险。对具有对抗性示例之间可转移性的网络的观察之一是它们的架构的相似性。具有高架构相似性的网络往往也具有高可移植性。因此,在本研究中,我们通过研究网络架构对可转移性的贡献,从一个新颖的角度来解决这个问题。具体来说,我们提出了一个架构搜索框架,该框架采用神经进化来进化网络架构和梯度偏差损失,以鼓励网络在训练后收敛为不同的功能。我们的研究结果表明,所提出的框架成功地发现了降低四种标准网络(包括ResNet和VGG)可转移性的架构,同时在无扰动图像上保持良好的准确性。此外,使用梯度偏差训练的进化网络的可转移性明显低于使用梯度偏差训练的标准网络,这表明网络结构在降低可转移性方面起着重要作用。我们证明,设计或探索适当的网络架构是解决可转移性问题和训练对抗鲁棒图像分类器的有前途的方法。
Deep neural network image classifiers are known to be susceptible, not only to adversarial examples created for them, but also to those created for others. This phenomenon poses a potential security risk in various black-box systems that rely on image classifiers. One of the observations on networks that have transferability of adversarial examples between them is the similarity of their architectures. Networks with high architectural similarity tend to share high transferability as well. Thus, in this study, we address this problem from a novel perspective by investigating the contribution of network architecture to transferability. Specifically, we propose an architecture searching framework that employs neuroevolution to evolve network architectures and gradient misalignment loss to encourage networks to converge into dissimilar functions after training. Our findings indicate that the proposed framework successfully discovers architectures that reduce transferability from four standard networks, including ResNet and VGG, while maintaining good accuracy on unperturbed images. In addition, the evolved networks trained with gradient misalignment exhibit significantly lower transferability than a standard network trained with gradient misalignment, which indicates that network architecture plays an important role in reducing transferability. We demonstrate that designing or exploring proper network architectures is a promising approach to tackle the transferability issue and train adversarially robust image classifiers.