Skip to main content
QUICK REVIEW

[論文レビュー] Curls & Whey: Boosting Black-Box Adversarial Attacks

Yucheng Shi, Siyu Wang|arXiv (Cornell University)|Apr 2, 2019
Adversarial Robustness in Machine Learning参考文献 31被引用数 13
ひとこと要約

Curls & Whey は、反復的軌道において勾配上昇と勾配下降を組み合わせることで、軌道の多様性を高め、摂動の大きさを低減する、画期的なブラックボックス敵対的攻撃を提案する。また、頑健性に配慮した最適化によってノイズを精錬することで、ImageNet および Tiny-ImageNet において、敵対的に訓練されたモデルやアンサンブルモデルに対しても、顕著に低い ℓ2 範囲で最先端の性能を達成する。

ABSTRACT

Image classifiers based on deep neural networks suffer from harassment caused by adversarial examples. Two defects exist in black-box iterative attacks that generate adversarial examples by incrementally adjusting the noise-adding direction for each step. On the one hand, existing iterative attacks add noises monotonically along the direction of gradient ascent, resulting in a lack of diversity and adaptability of the generated iterative trajectories. On the other hand, it is trivial to perform adversarial attack by adding excessive noises, but currently there is no refinement mechanism to squeeze redundant noises. In this work, we propose Curls & Whey black-box attack to fix the above two defects. During Curls iteration, by combining gradient ascent and descent, we `curl' up iterative trajectories to integrate more diversity and transferability into adversarial examples. Curls iteration also alleviates the diminishing marginal effect in existing iterative attacks. The Whey optimization further squeezes the `whey' of noises by exploiting the robustness of adversarial perturbation. Extensive experiments on Imagenet and Tiny-Imagenet demonstrate that our approach achieves impressive decrease on noise magnitude in l2 norm. Curls & Whey attack also shows promising transferability against ensemble models as well as adversarially trained models. In addition, we extend our attack to the targeted misclassification, effectively reducing the difficulty of targeted attacks under black-box condition.

研究の動機と目的

  • 既存のブラックボックス反復的攻撃が勾配上昇に単調に従うという点で、多様性と適応性に欠ける問題に対処すること。
  • 反復回数が増加しても、現在の手法がノイズの精錬に失敗するという、冗長なノイズの削減を実現すること。
  • 敵対的に訓練されたモデルやアンサンブルモデルなど、顕著に異なるモデルに対しても、敵対的例の転送性を向上させること。
  • 反復プロセスに補間を統合することで、ターゲット付きブラックボックス攻撃の有効性を高めること。

提案手法

  • Curls 反復では、代替モデルの損失関数に対して勾配上昇と勾配下降を交互に適用し、カールドされた軌道を生成することで、多様性を高め、境界を越える能力を向上させる。
  • Curls 反復内では二分探索を用いて、敵対的例を決定境界に近づけることで、ノイズの大きさを低減する。
  • Whey 最適化では、敵対的摂動の頑健性を活用し、画素値ごとにグループ化して、冗長なノイズを確率的に抽出する。
  • 補間を反復プロセスに統合することで、攻撃がターゲットクラスに向けられるように誘導され、ターゲット分類の難易度が低下する。
  • 本手法はクエリ制約下で代替モデルを用いて敵対的例を生成し、その後、反復後の最適化によって精錬する。

実験結果

リサーチクエスチョン

  • RQ1反復的攻撃において勾配上昇と勾配下降を組み合わせることで、軌道の多様性と敵対的例の転送性が向上するか?
  • RQ2摂動の頑健性を活用する精錬機構により、敵対的ノイズを効果的に低減できるか?
  • RQ3反復的攻撃に補間を統合することで、ターゲット付きブラックボックス攻撃の難易度が顕著に低下するか?
  • RQ4Curls & Whey は、敵対的訓練やモデルアンサンブルといった強力な防御に対して、どのように性能を発揮するか?

主な発見

  • Inception-v3 を攻撃対象とした場合、Tiny-ImageNet において Curls & Whey は中央値 ℓ2 範囲 2.0633 を達成し、ベースライン手法よりも顕著に低い。
  • 敵対的に訓練されたモデルに対しても、Curls & Whey は中央値 ℓ2 範囲 2.0633(Inception-v3)および 2.2852(Inception-ResNet-v2)を維持し、すべてのベースラインを上回る。
  • 同じクエリ予算下で、I-FGSM やバウンダリーアタックと比較して、ノイズの大きさを最大40%まで低減した。
  • アブレーションスタディにより、Curls 反復、二分探索、Whey 最適化の各コンポonent がノイズ低減に寄与していることが確認された。
  • 補間の統合により、より低い ℓ2 範囲で成功したターゲット付き攻撃が可能となり、標準的な反復的手法に比べ顕著な改善が示された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。