Adversarial robustness is a key concept in measuring the ability of neural networks to defend against adversarial attacks during the inference phase. Recent studies have shown that despite the success of improving adversarial robustness against a single type of attack using robust training techniques, models are still vulnerable to diversified $\ell_p$ attacks. To achieve diversified $\ell_p$ robustness, we propose a novel robust mode connectivity (RMC)-oriented adversarial defense that contains two population-based learning phases. The first phase, RMC, is able to search the model parameter space between two pre-trained models and find a path containing points with high robustness against diversified $\ell_p$ attacks. In light of the effectiveness of RMC, we develop a second phase, RMC-based optimization, with RMC serving as the basic unit for further enhancement of neural network diversified $\ell_p$ robustness. To increase computational efficiency, we incorporate learning with a self-robust mode connectivity (SRMC) module that enables the fast proliferation of the population used for endpoints of RMC. Furthermore, we draw parallels between SRMC and the human immune system. Experimental results on various datasets and model architectures demonstrate that the proposed defense methods can achieve high diversified $\ell_p$ robustness against $\ell_\infty$, $\ell_2$, $\ell_1$, and hybrid attacks. Codes are available at \url{https://github.com/wangren09/MCGR}.


翻译:对抗鲁棒性是衡量神经网络在推理阶段抵御对抗攻击能力的关键概念。近期研究表明,尽管使用鲁棒训练技术能成功提升模型对单一类型攻击的鲁棒性,但模型在面对多样化$\ell_p$攻击时仍然脆弱。为实现多样化$\ell_p$鲁棒性,我们提出了一种新颖的基于鲁棒模式连通性(RMC)的对抗防御方法,该方法包含两个基于种群的训练阶段。第一阶段(RMC)能够在两个预训练模型之间搜索参数空间,并找到一条包含高鲁棒性点的路径以抵御多样化$\ell_p$攻击。鉴于RMC的有效性,我们开发了第二阶段(RMC优化),以RMC为基本单元进一步提升神经网络的多样化$\ell_p$鲁棒性。为提高计算效率,我们引入了带自鲁棒模式连通性(SRMC)模块的学习机制,该模块能够快速扩充RMC端点的种群规模。此外,我们将SRMC与人类免疫系统进行类比。在多种数据集和模型架构上的实验结果表明,所提出的防御方法能够针对$\ell_\infty$、$\ell_2$、$\ell_1$及混合攻击实现高水平的多样化$\ell_p$鲁棒性。相关代码已开源至\url{https://github.com/wangren09/MCGR}。

0
下载
关闭预览

相关内容

【ECCV2022】UniNet:具有卷积、Transformer和MLP的统一架构搜索
【AAAI2022】学会学习可迁移攻击
专知会员服务
16+阅读 · 2021年12月15日
专知会员服务
29+阅读 · 2021年8月2日
专知会员服务
39+阅读 · 2021年6月11日
专知会员服务
20+阅读 · 2021年3月28日
【ICLR2021】神经元注意力蒸馏消除DNN中的后门触发器
专知会员服务
15+阅读 · 2021年1月31日
CVPR 2022 | 子空间对抗训练
PaperWeekly
1+阅读 · 2022年5月31日
ICLR2019 图上的对抗攻击
图与推荐
17+阅读 · 2020年3月15日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
3+阅读 · 2013年12月31日
国家自然科学基金
3+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
Arxiv
0+阅读 · 2023年5月9日
Arxiv
1+阅读 · 2023年5月8日
Arxiv
12+阅读 · 2020年12月10日
VIP会员
最新内容
反制无人机:乌克兰提供的五点启示
专知会员服务
10+阅读 · 9月23日
《各指挥层级均亟需红队能力》报告
专知会员服务
9+阅读 · 9月23日
《航电任务系统框架(FAMOS)》50页报告
专知会员服务
6+阅读 · 9月22日
《对抗行动中的人工智能与自主性》智库报告
专知会员服务
12+阅读 · 9月22日
《从数据到胜利:战争中的分析优势之争》
专知会员服务
15+阅读 · 9月22日
战争不仅需要机器人:人类仍不可或缺
专知会员服务
6+阅读 · 9月21日
《描绘美国防部创新基础设施的未来蓝图》100页
专知会员服务
13+阅读 · 9月21日
相关VIP内容
【ECCV2022】UniNet:具有卷积、Transformer和MLP的统一架构搜索
【AAAI2022】学会学习可迁移攻击
专知会员服务
16+阅读 · 2021年12月15日
专知会员服务
29+阅读 · 2021年8月2日
专知会员服务
39+阅读 · 2021年6月11日
专知会员服务
20+阅读 · 2021年3月28日
【ICLR2021】神经元注意力蒸馏消除DNN中的后门触发器
专知会员服务
15+阅读 · 2021年1月31日
相关基金
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
3+阅读 · 2013年12月31日
国家自然科学基金
3+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
Top
微信扫码咨询专知VIP会员