Modeling Biological Immunity to Adversarial Examples

Modeling Biological Immunity to Adversarial Examples
复制标题

DOI:
10.1109/cvpr42600.2020.00472
复制
发表时间:
2020-06
期刊:
2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Edward J. Kim;Jocelyn Rego;Y. Watkins;Garrett T. Kenyon
Edward J. Kim;Jocelyn Rego;Y. Watkins;Garrett T. Kenyon
中科院分区:
其他
文献类型:
--
作者:
Edward J. Kim;Jocelyn Rego;Y. Watkins;Garrett T. Kenyon

文献摘要

被引文献

相似文献

虽然深度学习继续渗透到信号处理和机器学习的所有领域,但这些框架中存在一个关键漏洞,并且尚未解决。这些漏洞,或对抗性的例子,是一种信号攻击,可以改变分类器的输出类通过扰动刺激信号的一个不可感知的量。该攻击利用了训练数据中的统计不规则性,其中添加的扰动可以使图像跨越深度学习决策边界。更令人担忧的是,这些攻击可以转移到不同的深度学习模型和架构中。这意味着对一个模型的成功攻击会对其他不相关的模型产生对抗性影响。一般来说,通过扰动进行的对抗性攻击不是机器学习漏洞。人类和生物视觉也可以通过各种方法来欺骗,即将高频和低频图像混合在一起,通过改变语义相关的信号,或者通过充分扭曲输入信号。然而,改变生物感知所需的这种扭曲的数量和幅度要大得多。在这项工作中,我们通过生物学和神经科学的透镜探索了这一差距,以了解人类感知中表现出的鲁棒性。我们的实验表明,通过利用稀疏性并在细胞水平上对生物机制进行建模,我们能够减轻对抗性改变对没有可感知意义的信号的影响。此外,我们提出并说明了自上而下的功能过程,有助于利用这些属性,使一个更强大的机器视觉系统的背景下,在人类感知的固有免疫力的影响。
While deep learning continues to permeate through all fields of signal processing and machine learning, a critical exploit in these frameworks exists and remains unsolved. These exploits, or adversarial examples, are a type of signal attack that can change the output class of a classifier by perturbing the stimulus signal by an imperceptible amount. The attack takes advantage of statistical irregularities within the training data, where the added perturbations can move the image across deep learning decision boundaries. What is even more alarming is the transferability of these attacks to different deep learning models and architectures. This means a successful attack on one model has adversarial effects on other, unrelated models. In a general sense, adversarial attack through perturbations is not a machine learning vulnerability. Human and biological vision can also be fooled by various methods, i.e. mixing high and low frequency images together, by altering semantically related signals, or by sufficiently distorting the input signal. However, the amount and magnitude of such a distortion required to alter biological perception is at a much larger scale. In this work, we explored this gap through the lens of biology and neuroscience in order to understand the robustness exhibited in human perception. Our experiments show that by leveraging sparsity and modeling the biological mechanisms at a cellular level, we are able to mitigate the effect of adversarial alterations to the signal that have no perceptible meaning. Furthermore, we present and illustrate the effects of top-down functional processes that contribute to the inherent immunity in human perception in the context of exploiting these properties to make a more robust machine vision system.