Adversarial examples bring a considerable security threat to support vector machines (SVMs), especially those used in safety-critical applications. Thus, robustness verification is an essential issue for SVMs, which can provide provable robustness against various kinds of adversary attacks. The evaluation results obtained through the robustness verification can provide a safe guarantee for the use of SVMs. The existing verification method does not often perform well in verifying SVMs with nonlinear kernels. To this end, we propose a method to improve the verification performance for SVMs with nonlinear kernels. We first formalize the adversarial robustness evaluation of SVMs as an optimization problem. Then a lower bound of the original problem is obtained by solving the Lagrangian dual problem of the original problem. Finally, the adversarial robustness of SVMs is evaluated concerning the lower bound. We evaluate the adversarial robustness of SVMs with linear and nonlinear kernels on the MNIST and Fashion-MNIST datasets. The experimental results show that the percentage of provable robustness obtained by our method on the test set is better than that of the state-of-the-art.
翻译:对抗样本对支持向量机(SVM)构成重大安全威胁,尤其当其在安全关键应用中使用时。因此,鲁棒性验证是SVM面临的关键问题,可针对各类对抗攻击提供可证明的鲁棒性。通过鲁棒性验证获得的评估结果可为SVM的安全使用提供保障。现有验证方法在处理非线性核SVM时往往表现不佳。为此,我们提出一种改进非线性核SVM验证性能的方法。首先将SVM的对抗鲁棒性评估形式化为优化问题,然后通过求解原问题的拉格朗日对偶问题获得原问题的下界,最终基于该下界评估SVM的对抗鲁棒性。我们在MNIST和Fashion-MNIST数据集上对线性核与非线性核SVM的对抗鲁棒性进行评估。实验结果表明,本方法在测试集上获得的可证明鲁棒性百分比优于现有最先进方法。