中文

语义分割中对抗补丁攻击的认证防御

计算机视觉与模式识别 2023-02-22 v2 人工智能 密码学与安全 机器学习

摘要

对抗补丁攻击是现实世界深度学习应用的新兴安全威胁。我们提出 Demasked Smoothing,据我们所知是首个认证语义分割模型针对该威胁模型鲁棒性的方法。先前关于认证防御补丁攻击的工作大多聚焦于图像分类任务,且常需改变模型架构并额外训练,这是不可取且计算昂贵的。在 Demasked Smoothing 中,任何分割模型均可应用,无需特定训练、微调或架构限制。使用不同的掩蔽策略,Demasked Smoothing 可同时用于认证检测与认证恢复。在大量实验中,我们表明在 ADE20K 数据集上,Demasked Smoothing 平均可认证检测任务中 1% 补丁的 64% 像素预测,以及恢复任务中 0.5% 补丁的 48% 像素预测。

关键词

引用

@article{arxiv.2209.05980,
  title  = {Certified Defences Against Adversarial Patch Attacks on Semantic Segmentation},
  author = {Maksym Yatsura and Kaspar Sakmann and N. Grace Hua and Matthias Hein and Jan Hendrik Metzen},
  journal= {arXiv preprint arXiv:2209.05980},
  year   = {2023}
}

备注

accepted at ICLR 2023