Skip to main content
QUICK REVIEW

[論文レビュー] Adversarial Examples - A Complete Characterisation of the Phenomenon

Alexandru Constantin Serban, Erik Poll|arXiv (Cornell University)|Oct 2, 2018
Adversarial Robustness in Machine Learning参考文献 183被引用数 44
ひとこと要約

敵対的サンプルを特徴づける包括的な調査であり、その存在、セキュリティへの影響、生成と防御手法、モデル間の転移性を包括的に扱う。

ABSTRACT

We provide a complete characterisation of the phenomenon of adversarial examples - inputs intentionally crafted to fool machine learning models. We aim to cover all the important concerns in this field of study: (1) the conjectures on the existence of adversarial examples, (2) the security, safety and robustness implications, (3) the methods used to generate and (4) protect against adversarial examples and (5) the ability of adversarial examples to transfer between different machine learning models. We provide ample background information in an effort to make this document self-contained. Therefore, this document can be used as survey, tutorial or as a catalog of attacks and defences using adversarial examples.

研究の動機と目的

  • 敵対的サンプルの存在と基本的な問いを調査する。
  • 機械学習システムに対するセキュリティ、安全性、およびロバストネスの影響を説明する。
  • 敵対的サンプルを生成する方法とそれに対抗する防御手法を列挙・比較する。
  • 異なるモデルや設定間での敵対的サンプルの転移性を検討する。
  • チュートリアル、調査、あるいは攻撃と防御のカタログとして自己完結型の背景を提供する。

提案手法

  • 文書を自己完結型にするために十分な背景を提供する。
  • 攻撃モデル、ロバスト性、原因、攻撃、防御、転移性、蒸留/防御技術を扱う章に内容を整理する。
  • 広範な攻撃と防御を文脈的な説明と共に列挙する。
  • 機械学習におけるロバストネスとセキュリティの理論的・実践的側面を議論する。
  • 敵対的サンプルをより広いMLセキュリティの文脈に位置づけるため、広範な研究を参照する。

実験結果

リサーチクエスチョン

  • RQ1敵対的サンプルの存在と性質についてどのような推測があるか。
  • RQ2機械学習システムに対するセキュリティ、安全性、ロバストネスの影響は何か。
  • RQ3敵対的サンプルを生成するためにどのような手法が用いられ、対抗する防御は何があるか。
  • RQ4敵対的サンプルは異なるモデルや設定間でどの程度転移するのか。

主な発見

  • 本研究は理論・実践・防御の全域にわたる敵対的サンプルの完全な特徴付けを提供する。
  • 本文書は読者に自己完結型の背景を提供しつつ、攻撃と防御のカタログとして機能する。
  • この調査はモデル間の敵対的サンプルの転移性とセキュリティのロバストネスへの影響を扱う。
  • 敵対的機械学習の全体像を示すため、関連研究と手法の幅広い範囲を体系化している。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。