Mixtures of classifiers (a.k.a. randomized ensembles) have been proposed as a way to improve robustness against adversarial attacks. However, it has been shown that existing attacks are not well suited for this kind of classifiers. In this paper, we discuss the problem of attacking a mixture in a principled way and introduce two desirable properties of attacks based on a geometrical analysis of the problem (effectiveness and maximality). We then show that existing attacks do not meet both of these properties. Finally, we introduce a new attack called lattice climber attack with theoretical guarantees on the binary linear setting, and we demonstrate its performance by conducting experiments on synthetic and real datasets.
翻译:分类器混合(也称随机集成)被提出作为一种提升对抗攻击鲁棒性的方法。然而,已有研究表明现有攻击方法并不适合此类分类器。本文从理论层面探讨了如何对混合分类器进行攻击,基于几何分析提出了攻击方法应具备的两个理想性质(有效性与极大性),并指出现有攻击方法无法同时满足这两个性质。最后,我们提出一种名为“格点攀爬攻击”的新方法,在线性二分类设定下具有理论保证,并通过合成数据集与真实数据集的实验验证了其性能。