• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

通过 Langevin 动力学使模型免受对抗性攻击。

Robustifying models against adversarial attacks by Langevin dynamics.

机构信息

Department of Artificial Intelligence, Fraunhofer Heinrich Hertz Institute, 10587 Berlin, Germany.

Department of Artificial Intelligence, Fraunhofer Heinrich Hertz Institute, 10587 Berlin, Germany; Machine Learning Group, Technische Universität Berlin, 10587 Berlin, Germany; BIFOLD - Berlin Institute for the Foundations of Learning and Data, Germany.

出版信息

Neural Netw. 2021 May;137:1-17. doi: 10.1016/j.neunet.2020.12.024. Epub 2021 Jan 9.

DOI:10.1016/j.neunet.2020.12.024
PMID:33515855
Abstract

Adversarial attacks on deep learning models have compromised their performance considerably. As remedies, a number of defense methods were proposed, which however, have been circumvented by newer and more sophisticated attacking strategies. In the midst of this ensuing arms race, the problem of robustness against adversarial attacks still remains a challenging task. This paper proposes a novel, simple yet effective defense strategy where off-manifold adversarial samples are driven towards high density regions of the data generating distribution of the (unknown) target class by the Metropolis-adjusted Langevin algorithm (MALA) with perceptual boundary taken into account. To achieve this task, we introduce a generative model of the conditional distribution of the inputs given labels that can be learned through a supervised Denoising Autoencoder (sDAE) in alignment with a discriminative classifier. Our algorithm, called MALA for DEfense (MALADE), is equipped with significant dispersion-projection is distributed broadly. This prevents white box attacks from accurately aligning the input to create an adversarial sample effectively. MALADE is applicable to any existing classifier, providing robust defense as well as off-manifold sample detection. In our experiments, MALADE exhibited state-of-the-art performance against various elaborate attacking strategies.

摘要

深度学习模型的对抗攻击已经严重影响了它们的性能。作为补救措施,已经提出了许多防御方法,但这些方法已经被更新和更复杂的攻击策略所规避。在这场持续的军备竞赛中,对抗攻击的鲁棒性问题仍然是一项具有挑战性的任务。本文提出了一种新颖的、简单而有效的防御策略,该策略通过考虑感知边界的 Metropolis 调整 Langevin 算法(MALA)将离群的对抗样本推向未知目标类数据生成分布的高密度区域。为了实现这一任务,我们引入了一种基于条件分布的生成模型,该模型可以通过监督去噪自动编码器(sDAE)在与判别分类器对齐的情况下进行学习。我们的算法称为防御的 MALA(MALADE),它配备了重要的分散-投影机制,分布广泛。这可以防止白盒攻击准确地将输入对齐,从而有效地创建对抗样本。MALADE 可以应用于任何现有的分类器,提供强大的防御和离群样本检测。在我们的实验中,MALADE 表现出了针对各种精心设计的攻击策略的最先进的性能。

相似文献

1
Robustifying models against adversarial attacks by Langevin dynamics.通过 Langevin 动力学使模型免受对抗性攻击。
Neural Netw. 2021 May;137:1-17. doi: 10.1016/j.neunet.2020.12.024. Epub 2021 Jan 9.
2
Robust image classification against adversarial attacks using elastic similarity measures between edge count sequences.使用边缘计数序列之间的弹性相似性度量来进行对抗攻击的鲁棒图像分类。
Neural Netw. 2020 Aug;128:61-72. doi: 10.1016/j.neunet.2020.04.030. Epub 2020 Apr 30.
3
Between-Class Adversarial Training for Improving Adversarial Robustness of Image Classification.基于类间对抗训练提高图像分类对抗鲁棒性。
Sensors (Basel). 2023 Mar 20;23(6):3252. doi: 10.3390/s23063252.
4
Image Super-Resolution as a Defense Against Adversarial Attacks.图像超分辨率作为对抗对抗攻击的一种防御手段。
IEEE Trans Image Process. 2019 Sep 19. doi: 10.1109/TIP.2019.2940533.
5
On the robustness of skeleton detection against adversarial attacks.对抗攻击下骨架检测的稳健性研究。
Neural Netw. 2020 Dec;132:416-427. doi: 10.1016/j.neunet.2020.09.018. Epub 2020 Sep 28.
6
Towards evaluating the robustness of deep diagnostic models by adversarial attack.通过对抗攻击评估深度诊断模型的稳健性。
Med Image Anal. 2021 Apr;69:101977. doi: 10.1016/j.media.2021.101977. Epub 2021 Jan 22.
7
Implicit adversarial data augmentation and robustness with Noise-based Learning.基于噪声学习的隐式对抗数据增强与鲁棒性
Neural Netw. 2021 Sep;141:120-132. doi: 10.1016/j.neunet.2021.04.008. Epub 2021 Apr 20.
8
Defending the Defender: Adversarial Learning Based Defending Strategy for Learning Based Security Methods in Cyber-Physical Systems (CPS).捍卫防御者:基于对抗学习的防御策略,用于网络物理系统 (CPS) 中的基于学习的安全方法。
Sensors (Basel). 2023 Jun 9;23(12):5459. doi: 10.3390/s23125459.
9
RobEns: Robust Ensemble Adversarial Machine Learning Framework for Securing IoT Traffic.RobEns:用于保护物联网流量的鲁棒集成对抗机器学习框架。
Sensors (Basel). 2024 Apr 19;24(8):2626. doi: 10.3390/s24082626.
10
Deeply Supervised Discriminative Learning for Adversarial Defense.用于对抗防御的深度监督判别学习
IEEE Trans Pattern Anal Mach Intell. 2021 Sep;43(9):3154-3166. doi: 10.1109/TPAMI.2020.2978474. Epub 2021 Aug 4.