• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

基于特征空间随机性的对抗攻击与防御。

Adversarial attacks and defenses using feature-space stochasticity.

机构信息

Department of Physiology, The University of Tokyo School of Medicine, 7-3-1, Hongo, Bunkyo-ku, 113-0033, Tokyo, Japan.

Department of Physiology, The University of Tokyo School of Medicine, 7-3-1, Hongo, Bunkyo-ku, 113-0033, Tokyo, Japan; International Research Center for Neurointelligence (WPI-IRCN), 7-3-1, Hongo, Bunkyo-ku, 113-0033, Tokyo, Japan; Institute for AI and Beyond, 7-3-1, Hongo, Bunkyo-ku, 113-0033, Tokyo, Japan.

出版信息

Neural Netw. 2023 Oct;167:875-889. doi: 10.1016/j.neunet.2023.08.022. Epub 2023 Aug 21.

DOI:10.1016/j.neunet.2023.08.022
PMID:37722983
Abstract

Recent studies in deep neural networks have shown that injecting random noise in the input layer of the networks contributes towards ℓ-norm-bounded adversarial perturbations. However, to defend against unrestricted adversarial examples, most of which are not ℓ-norm-bounded in the input layer, such input-layer random noise may not be sufficient. In the first part of this study, we generated a novel class of unrestricted adversarial examples termed feature-space adversarial examples. These examples are far from the original data in the input space but adjacent to the original data in a hidden-layer feature space and far again in the output layer. In the second part of this study, we empirically showed that while injecting random noise in the input layer was unable to defend these feature-space adversarial examples, they were defended by injecting random noise in the hidden layer. These results highlight the novel benefit of stochasticity in higher layers, in that it is useful for defending against these feature-space adversarial examples, a class of unrestricted adversarial examples.

摘要

最近的深度神经网络研究表明,在网络的输入层中注入随机噪声有助于 ℓ-norm 有界对抗性扰动。然而,为了防御不受限制的对抗性示例,其中大多数在输入层中不是 ℓ-norm 有界的,这种输入层随机噪声可能是不够的。在本研究的第一部分,我们生成了一类新的称为特征空间对抗性示例的不受限制的对抗性示例。这些示例在输入空间中与原始数据相去甚远,但在隐藏层特征空间中与原始数据相邻,而在输出层中则更远。在本研究的第二部分,我们通过实验表明,尽管在输入层注入随机噪声无法防御这些特征空间对抗性示例,但在隐藏层注入随机噪声可以防御这些示例。这些结果突出了高层随机性的新优势,即它对于防御这些特征空间对抗性示例,即一类不受限制的对抗性示例是有用的。

相似文献

1
Adversarial attacks and defenses using feature-space stochasticity.基于特征空间随机性的对抗攻击与防御。
Neural Netw. 2023 Oct;167:875-889. doi: 10.1016/j.neunet.2023.08.022. Epub 2023 Aug 21.
2
Learning defense transformations for counterattacking adversarial examples.学习防御变换以反击对抗样本。
Neural Netw. 2023 Jul;164:177-185. doi: 10.1016/j.neunet.2023.03.008. Epub 2023 Mar 24.
3
Remix: Towards the transferability of adversarial examples.对抗样本的可迁移性研究
Neural Netw. 2023 Jun;163:367-378. doi: 10.1016/j.neunet.2023.04.012. Epub 2023 Apr 18.
4
K-Anonymity inspired adversarial attack and multiple one-class classification defense.K-匿名启发的对抗攻击与多类单分类防御。
Neural Netw. 2020 Apr;124:296-307. doi: 10.1016/j.neunet.2020.01.015. Epub 2020 Feb 6.
5
Training Robust Deep Neural Networks via Adversarial Noise Propagation.通过对抗噪声传播训练稳健的深度神经网络。
IEEE Trans Image Process. 2021;30:5769-5781. doi: 10.1109/TIP.2021.3082317.
6
Towards evaluating the robustness of deep diagnostic models by adversarial attack.通过对抗攻击评估深度诊断模型的稳健性。
Med Image Anal. 2021 Apr;69:101977. doi: 10.1016/j.media.2021.101977. Epub 2021 Jan 22.
7
DEFEAT: Decoupled feature attack across deep neural networks.击败:跨深度神经网络的解耦特征攻击。
Neural Netw. 2022 Dec;156:13-28. doi: 10.1016/j.neunet.2022.09.009. Epub 2022 Sep 20.
8
Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition.对抗训练和特征融合在糖尿病视网膜病变识别中的对抗攻击和防御。
Sensors (Basel). 2021 Jun 7;21(11):3922. doi: 10.3390/s21113922.
9
Defense Against Adversarial Attacks by Reconstructing Images.通过图像重建抵御对抗性攻击
IEEE Trans Image Process. 2021;30:6117-6129. doi: 10.1109/TIP.2021.3092582. Epub 2021 Jul 7.
10
Provable Unrestricted Adversarial Training Without Compromise With Generalizability.可证明的无妥协于泛化性的无限制对抗训练。
IEEE Trans Pattern Anal Mach Intell. 2024 Dec;46(12):8302-8319. doi: 10.1109/TPAMI.2024.3400988. Epub 2024 Nov 6.

引用本文的文献

1
Predicting extremely low body weight from 12-lead electrocardiograms using a deep neural network.使用深度神经网络预测 12 导联心电图中的极低体重。
Sci Rep. 2024 Feb 26;14(1):4696. doi: 10.1038/s41598-024-55453-3.