PeerNets: Exploiting Peer Wisdom Against Adversarial Attacks

PeerNets: Exploiting Peer Wisdom Against Adversarial Attacks
复制标题

DOI:
--
复制
发表时间:
2018-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Jan Svoboda;Jonathan Masci;Federico Monti;M. Bronstein;L. Guibas
Jan Svoboda;Jonathan Masci;Federico Monti;M. Bronstein;L. Guibas
中科院分区:
其他
文献类型:
--
作者:
Jan Svoboda;Jonathan Masci;Federico Monti;M. Bronstein;L. Guibas

文献摘要

相似文献

深度学习系统已经在我们生活的许多方面变得无处不在。不幸的是,事实表明,这种系统容易受到敌意攻击,从而容易被潜在的非法使用。设计对对手攻击稳健的深度神经网络是使此类系统更安全、可在更广泛的应用(例如自动驾驶)中部署的基本步骤,但更重要的是设计基于新的计算范例而不是边缘建立在现有计算范例上的新颖和更先进的架构的必要步骤。在本文中,我们介绍了PeerNets,这是一类新的卷积网络,它交替使用经典的欧几里德卷积和图卷积来利用来自对等样本图的信息。这导致了模型中的一种非局部前向传播形式,其中潜在特征以图所诱导的全局结构为条件,与传统体系结构相比,在几乎不降低精度的情况下,对各种白盒和黑盒对手攻击的健壮性最高可达3倍。
Deep learning systems have become ubiquitous in many aspects of our lives. Unfortunately, it has been shown that such systems are vulnerable to adversarial attacks, making them prone to potential unlawful uses. Designing deep neural networks that are robust to adversarial attacks is a fundamental step in making such systems safer and deployable in a broader variety of applications (e.g. autonomous driving), but more importantly is a necessary step to design novel and more advanced architectures built on new computational paradigms rather than marginally building on the existing ones. In this paper we introduce PeerNets, a novel family of convolutional networks alternating classical Euclidean convolutions with graph convolutions to harness information from a graph of peer samples. This results in a form of non-local forward propagation in the model, where latent features are conditioned on the global structure induced by the graph, that is up to 3 times more robust to a variety of white- and black-box adversarial attacks compared to conventional architectures with almost no drop in accuracy.