语义分割中对抗补丁攻击的认证防御
计算机视觉与模式识别
2023-02-22 v2 人工智能
密码学与安全
机器学习
摘要
对抗补丁攻击是现实世界深度学习应用的新兴安全威胁。我们提出 Demasked Smoothing,据我们所知是首个认证语义分割模型针对该威胁模型鲁棒性的方法。先前关于认证防御补丁攻击的工作大多聚焦于图像分类任务,且常需改变模型架构并额外训练,这是不可取且计算昂贵的。在 Demasked Smoothing 中,任何分割模型均可应用,无需特定训练、微调或架构限制。使用不同的掩蔽策略,Demasked Smoothing 可同时用于认证检测与认证恢复。在大量实验中,我们表明在 ADE20K 数据集上,Demasked Smoothing 平均可认证检测任务中 1% 补丁的 64% 像素预测,以及恢复任务中 0.5% 补丁的 48% 像素预测。
引用
@article{arxiv.2209.05980,
title = {Certified Defences Against Adversarial Patch Attacks on Semantic Segmentation},
author = {Maksym Yatsura and Kaspar Sakmann and N. Grace Hua and Matthias Hein and Jan Hendrik Metzen},
journal= {arXiv preprint arXiv:2209.05980},
year = {2023}
}
备注
accepted at ICLR 2023