Skip to main content
QUICK REVIEW

[论文解读] Adversarial Transferability in Wearable Sensor Systems

Ramesh Kumar Sah, Hassan Ghasemzadeh|arXiv (Cornell University)|Mar 17, 2020
Adversarial Robustness in Machine Learning参考文献 45被引用 5
一句话总结

本文研究可穿戴传感器系统中的对抗性可迁移性,展示了在不同模型、受试者、传感器位置和数据集之间具有很强的非目标性可迁移性。研究发现,当源系统与目标系统的数据分布差异增大时,可迁移性会急剧下降,并为构建鲁棒的传感器系统提供了设计指南。

ABSTRACT

Machine learning is used for inference and decision making in wearable sensor systems. However, recent studies have found that machine learning algorithms are easily fooled by the addition of adversarial perturbations to their inputs. What is more interesting is that adversarial examples generated for one machine learning system is also effective against other systems. This property of adversarial examples is called transferability. In this work, we take the first stride in studying adversarial transferability in wearable sensor systems from the following perspectives: 1) transferability between machine learning systems, 2) transferability across subjects, 3) transferability across sensor body locations, and 4) transferability across datasets. We found strong untargeted transferability in most cases. Targeted attacks were less successful with success scores from $0\%$ to $80\%$. The transferability of adversarial examples depends on many factors such as the inclusion of data from all subjects, sensor body position, number of samples in the dataset, type of learning algorithm, and the distribution of source and target system dataset. The transferability of adversarial examples decreases sharply when the data distribution of the source and target system becomes more distinct. We also provide guidelines for the community for designing robust sensor systems.

研究动机与目标

  • 研究对抗性可迁移性的程度及其影响因素在可穿戴传感器系统中的表现。
  • 评估在不同机器学习模型、受试者、传感器身体位置和数据集之间的可迁移性。
  • 识别对抗性样本在不同系统间成功迁移的条件。
  • 为设计抵御对抗性攻击的鲁棒可穿戴传感器系统提供可操作的指导原则。

提出的方法

  • 在多个可穿戴传感器数据集(UCI、MHEALTH等)上使用五种对抗性攻击方法进行实验。
  • 评估在不同数据集和模型架构上训练的多种机器学习模型之间的可迁移性。
  • 测量使用不同学习算法、超参数和传感器位置的系统之间的可迁移性。
  • 利用真实世界可穿戴传感器数据,评估在不同受试者和传感器身体位置之间的可迁移性。
  • 分析数据集大小、数据分布相似性以及模型架构对抗敌意迁移成功率的影响。
  • 采用基于oracle的攻击方法,模拟对手对目标系统访问有限的真实威胁模型。

实验结果

研究问题

  • RQ1在可穿戴传感器系统中,不同机器学习模型之间的对抗性可迁移性在多大程度上发生?
  • RQ2可迁移性在不同受试者和传感器身体位置之间如何变化?
  • RQ3数据集大小和分布如何影响对抗性迁移的成功率?
  • RQ4在此背景下,目标性攻击与非目标性攻击的性能差异是什么?
  • RQ5哪些因素对可穿戴系统中对抗性样本的可迁移性影响最大?

主要发现

  • 在大多数模型、受试者、传感器位置和数据集的组合中,观察到显著的非目标性可迁移性。
  • 目标性攻击的成功率参差不齐,范围在0%至80%之间,表明其效果有限。
  • 当源系统与目标系统的数据分布差异增大时,可迁移性显著下降。
  • 更大的数据集(如UCI数据集,含10,299个样本)导致更高的可迁移性,表明数据量的增加可增强对抗鲁棒性。
  • 在多样化、全面的数据集上训练的模型,对可迁移对抗性攻击表现出更强的抵抗能力。
  • 本研究强调,对抗性漏洞并非局限于特定模型或配置,而是可穿戴传感器系统中的系统性问题。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。