Skip to main content
QUICK REVIEW

[论文解读] Adversarial Examples - A Complete Characterisation of the Phenomenon

Alexandru Constantin Serban, Erik Poll|arXiv (Cornell University)|Oct 2, 2018
Adversarial Robustness in Machine Learning参考文献 183被引用 44
一句话总结

对对抗性样本进行全面特征化的综述,涵盖它们的存在性、安全性影响、生成与防御方法,以及在模型之间的可转移性。

ABSTRACT

We provide a complete characterisation of the phenomenon of adversarial examples - inputs intentionally crafted to fool machine learning models. We aim to cover all the important concerns in this field of study: (1) the conjectures on the existence of adversarial examples, (2) the security, safety and robustness implications, (3) the methods used to generate and (4) protect against adversarial examples and (5) the ability of adversarial examples to transfer between different machine learning models. We provide ample background information in an effort to make this document self-contained. Therefore, this document can be used as survey, tutorial or as a catalog of attacks and defences using adversarial examples.

研究动机与目标

  • 调查对抗性样本的存在性及相关基本问题。
  • 解释对机器学习系统的安全性、可靠性与鲁棒性方面的影响。
  • 编目并比较用于生成对抗性样本以及针对它们的防御的方法。
  • 检验对抗性样本在不同模型和设定之间的可转移性。
  • 提供自包含的背景信息,以作为教程、综述或攻击与防御目录。

提出的方法

  • 提供充足的背景信息,使文档自成一体。
  • 将内容组织为章节,涵盖攻击模型、鲁棒性、原因、攻击、防御、可转移性以及蒸馏/防御技术。
  • 结合上下文解释,编目大量攻击与防御方法。
  • 讨论机器学习中鲁棒性与安全性的理论与实践方面。
  • 参考大量工作,将对抗性样本置于更广泛的ML安全领域中。

实验结果

研究问题

  • RQ1关于对抗性样本的存在性及其性质存在哪些猜想?
  • RQ2机器学习系统的安全性、可靠性与鲁棒性方面的含义是什么?
  • RQ3用于生成对抗性样本的方法有哪些,以及有哪些防御?
  • RQ4对抗性样本在不同模型和设定之间的可转移程度有多大?

主要发现

  • 该工作在理论、实践与防御层面完整刻画了对抗性样本。
  • 该文档作为攻击与防御的目录,为读者提供自包含的背景。
  • 综述涵盖对抗性样本在模型之间的可转移性以及对安全性的鲁棒性影响。
  • 整理了大量相关工作和方法,以展示对抗性机器学习的全景。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。