(已认证!!)免费获取对抗鲁棒性!
机器学习
2023-03-07 v2 密码学与安全
摘要
本文展示了如何仅依靠现成的预训练模型实现针对2-范数有界扰动的当前最优认证对抗鲁棒性。为此,我们实例化Salman等人2020年的去噪平滑方法,将预训练的去噪扩散概率模型与标准高精度分类器相结合。这使我们能在ImageNet上针对2-范数约束不超过0.5的对抗扰动认证71%的准确率,比先前使用任何方法的认证SOTA提高14个百分点,或比去噪平滑提高30个百分点。我们仅使用预训练扩散模型和图像分类器获得这些结果,无需对任何模型参数进行微调或重训练。
引用
@article{arxiv.2206.10550,
title = {(Certified!!) Adversarial Robustness for Free!},
author = {Nicholas Carlini and Florian Tramer and Krishnamurthy Dj Dvijotham and Leslie Rice and Mingjie Sun and J. Zico Kolter},
journal= {arXiv preprint arXiv:2206.10550},
year = {2023}
}