[論文レビュー] Evaluation of Momentum Diverse Input Iterative Fast Gradient Sign Method (M-DI2-FGSM) Based Attack Method on MCS 2018 Adversarial Attacks on Black Box Face Recognition System
この論文は、MCS 2018 チャレンジにおいて顔認識システムに対するターゲット付きブラックボックス敵対的攻撃を評価し、Momentum Diverse Input Iterative Fast Gradient Sign Method (M-DI2-FGSM) を適用した。この手法は、1.407 のベースラインを上回る検証スコア 1.404 を達成し、132 チーム中 14 位を記録し、限定的なモデルアクセス条件下でも転送可能な敵対的サンプルを効果的に生成できることを示した。
The convolutional neural network is the crucial tool for the recent success of deep learning based methods on various computer vision tasks like classification, segmentation, and detection. Convolutional neural networks achieved state-of-the-art performance in these tasks and every day pushing the limit of computer vision and AI. However, adversarial attack on computer vision systems is threatening their application in the real life and in safety-critical applications. Necessarily, Finding adversarial examples are important to detect susceptible models to attack and take safeguard measures to overcome the adversarial attacks. In this regard, MCS 2018 Adversarial Attacks on Black Box Face Recognition challenge aims to facilitate the research of finding new adversarial attack techniques and their effectiveness in generating adversarial examples. In this challenge, the attack"s nature is targeted-attack on the black-box neural network where we have no knowledge about black-block"s inner structure. The attacker must modify a set of five images of a single person so that the neural network miss-classify them as target image which is a set of five images of another person. In this competition, we applied Momentum Diverse Input Iterative Fast Gradient Sign Method (M-DI2-FGSM) to make an adversarial attack on black-box face recognition system. We tested our method on MCS 2018 Adversarial Attacks on Black Box Face Recognition challenge and found competitive result. Our solution got validation score 1.404 which better than baseline score 1.407 and stood 14 place among 132 teams in the leader-board. Further improvement can be achieved by finding improved feature extraction from source image, carefully chosen hyper-parameters, finding improved substitute model of the black-box and better optimization method.
研究の動機と目的
- 内部モデル構造へのアクセスなしに、ブラックボックス顔認識システムに対する効果的なターゲット付き敵対的攻撃を開発すること。
- M-DI2-FGSM 手法が顔認識向けに転送可能な敵対的サンプルを生成する性能を評価すること。
- MCS 2018 アドバーシャルアタックス・オン・ブラックボックス・フェイスリコグニション・チャレンジにおいて、ベースライン攻撃性能を改善すること。
- 特徴抽出、ハイパーパramータ、代替モデル、最適化手法などの要因が、攻撃成功をさらに高めるにあたり果たす役割を特定すること。
提案手法
- M-DI2-FGSM 手法は、勾配のモーメンタム更新と多様な入力の摂動を組み合わせることで、攻撃の転送性を向上させる。
- 最適化プロセスの安定化と高速化を図るため、モーメンタムを用いた反復的 FGSM 更新を適用する。
- 各勾配ステップの前に、入力画像にランダム変換(例:スケーリング、クロッピング)を適用して、多様な入力摂動を生成する。
- 攻撃はターゲット付きであり、1 人の人物の 5 枚のソース画像を、顔認識システム内でターゲット人物の画像として誤認識させるように変更する。
- ブラックボックス制約下で動作し、勾配やアーキテクチャへのアクセスなしに、モデルの予測結果のみに依存する。
- ステップサイズ、反復回数、モーメンタム係数といったハイパーパramータを調整し、攻撃成功確率を最大化する。
実験結果
リサーチクエスチョン
- RQ1M-DI2-FGSM はブラックボックス顔認識システム向けに、転送可能な敵対的サンプルをどれほど効果的に生成できるか?
- RQ2モーメンタムと多様な入力戦略は、ターゲット付き敵対的攻撃の転送性と成功確率を向上させられるか?
- RQ3厳密なブラックボックス制約下で、M-DI2-FGSM は MCS 2018 チャレンジにおいてベースライン手法と比較してどうなるか?
- RQ4特徴抽出の品質と代替モデルの選択が、攻撃性能の向上に果たす役割は何か?
- RQ5実世界のブラックボックス環境において、最適な攻撃成功を得るためにどのようなハイパーパramータ設定が有効か?
主な発見
- M-DI2-FGSM 手法は、MCS 2018 チャレンジで 1.404 の検証スコアを達成し、1.407 のベースラインを上回った。
- リーダーボードでは 132 チーム中 14 位を記録し、競争が激しい実世界のブラックボックス攻撃環境でも優れたパフォーマンスを示した。
- 攻撃は、ソース画像をターゲット人物の画像として誤認識させるように、ターゲット付きの敵対的サンプルを効果的に生成した。
- 特徤抽出の向上、ハイパーパramータの最適化、代替モデルの設計、最適化手法の改善が、さらなるパフォーマンス向上の鍵となる要因であると特定された。
- モーメンタムと多様な入力の使用により、異なるモデルアーキテクチャ間で、敵対的サンプルの転送性とロバスト性が顕著に向上した。
- ターゲットモデルの内部構造へのアクセスが限られている中でも、この手法は優れた一般化能力を示した。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。