中文

论深度学习中权重的安防相关性

密码学与安全 2020-12-01 v2 机器学习

摘要

近来,一种针对随机梯度下降、诱导过拟合的基于权重的攻击被提出。我们表明该威胁更为广泛:对初始权重施加与任务无关的置换就足以将所达精度限制为例如 Fashion MNIST 数据集上从初始 90% 以上降至 50%。这些发现在 MNIST 与 CIFAR 上得到确认。我们形式化确认该攻击以高概率成功且不依赖于数据。经验上,权重统计与损失看似无异常,若用户未察觉则难以检测该攻击。因此我们的论文呼吁采取行动以承认深度学习中初始权重的重要性。

关键词

引用

@article{arxiv.1902.03020,
  title  = {On the security relevance of weights in deep learning},
  author = {Kathrin Grosse and Thomas A. Trost and Marius Mosbach and Michael Backes and Dietrich Klakow},
  journal= {arXiv preprint arXiv:1902.03020},
  year   = {2020}
}

备注

16 pages, 18 figures, long version of paper published at ICANN 2020