中文

旋转等变网络对对抗扰动的鲁棒性

计算机视觉与模式识别 2018-05-18 v2 密码学与安全 机器学习

摘要

深度神经网络已被证明易受对抗样本的影响:输入的极微小扰动会对预测产生剧烈影响。已有大量对抗攻击和用于量化自然图像与对抗图像相似性的距离度量被提出,近期更将对抗样本的范围从逐像素攻击扩展到了几何变换。在此背景下,我们研究了提供旋转等变性的新型卷积神经网络(CNN)架构对对抗攻击的鲁棒性。我们发现,在MNIST、CIFAR-10和ImageNet数据集上,旋转等变网络比常规网络显著更不易受基于几何的攻击影响。

关键词

引用

@article{arxiv.1802.06627,
  title  = {Robustness of Rotation-Equivariant Networks to Adversarial Perturbations},
  author = {Beranger Dumont and Simona Maggio and Pablo Montalvo},
  journal= {arXiv preprint arXiv:1802.06627},
  year   = {2018}
}

备注

4 pages + references; public implementation of Spatially Transformed Adversarial Examples can be found at https://github.com/rakutentech/stAdv