中文

MEAD:一种用于对抗样本检测器评估的多臂方法

计算机视觉与模式识别 2022-07-01 v1

摘要

由于在对关键应用中机器学习算法的安全部署具有重要意义,对抗样本检测在过去几年中成为热点话题。然而,检测方法通常在假设单一隐式已知攻击策略下进行验证,这未必能涵盖现实威胁。实际上,这可能导致对检测器性能的过于乐观的评估,并可能在相互竞争的检测方案比较中引入某些偏差。我们提出了一种新颖的多臂框架 MEAD,基于多种攻击策略来评估检测器以克服此局限。其中,我们利用三个新目标来生成攻击。所提出的性能指标基于最坏情形:当且仅当所有不同攻击均被正确识别时,检测才成功。我们通过实验展示了该方法的有效性。此外,最先进检测器所表现出的较差性能开辟了一条令人振奋的新研究方向。

关键词

引用

@article{arxiv.2206.15415,
  title  = {MEAD: A Multi-Armed Approach for Evaluation of Adversarial Examples Detectors},
  author = {Federica Granese and Marine Picot and Marco Romanelli and Francisco Messina and Pablo Piantanida},
  journal= {arXiv preprint arXiv:2206.15415},
  year   = {2022}
}

备注

This paper has been accepted to appear in the Proceedings of the 2022 European Conference on Machine Learning and Data Mining (ECML-PKDD), 19th to the 23rd of September, Grenoble, France