中文

关于对抗训练范数无关鲁棒性的探讨

机器学习 2019-05-17 v1 密码学与安全 机器学习

摘要

对抗样本是为欺骗机器学习模型而精心扰动的输入。对此类样本公认良好的防御方法是对抗训练,即将对抗样本注入训练数据以提升鲁棒性。本文中,我们提出一种新攻击以揭示最先进对抗训练的一个不良特性:它无法同时获得对 2\ell_2\ell_\infty 范数扰动的鲁棒性。我们讨论了该问题的一种可能解决方案及其局限性。

关键词

引用

@article{arxiv.1905.06455,
  title  = {On Norm-Agnostic Robustness of Adversarial Training},
  author = {Bai Li and Changyou Chen and Wenlin Wang and Lawrence Carin},
  journal= {arXiv preprint arXiv:1905.06455},
  year   = {2019}
}

备注

4 pages, 2 figures, presented at the ICML 2019 Workshop on Uncertainty and Robustness in Deep Learning. arXiv admin note: text overlap with arXiv:1809.03113