节点文献
自适应攻击强度的模型集成对抗训练方法
Model ensemble adversarial training with adaptive attack strength
【摘要】 为提高深度学习模型在对抗样本攻击时的鲁棒性,提出了一种自适应攻击强度的模型集成对抗训练方法。在训练模型过程中,根据模型梯度范数的变化,采用多步迭代法动态调整扰动步长,在不同训练阶段获得相应攻击强度的对抗样本。此外,采用集成对抗训练,将不同模型梯度之间的余弦相似度作为正则化项,降低多个模型生成对抗样本的特征重叠度,使模型能够适应多样化数据分布的对抗样本,从而增强模型的鲁棒性。实验结果表明,相较于现有方法,所提方法在CIFAR-10和CIFAR-100数据集的鲁棒准确率分别提升8.32%和4.01%。
【Abstract】 To improve the robustness of deep learning models against adversarial sample attacks, an adaptive attack strength model ensemble adversarial training method was proposed. During the model training process, the perturbation step size was dynamically adjusted using a multi-step iterative method based on the changes in the model gradient norm, obtaining adversarial samples with corresponding attack intensities at different training stages. Moreover, ensemble adversarial training was employed, where the cosine similarity between the gradients of different models was used as a regularization term to reduce the feature overlap of adversarial samples generated by multiple models, allowing the model to adapt to adversarial examples from diverse data distributions and thus enhancing its robustness. Experimental results show that compared to existing methods, the proposed method improves the robust accuracy by 8. 32% and 4. 01% on the CIFAR-10 and CIFAR-100 datasets, respectively.
【Key words】 deep neural network; adversarial example; adversarial training; robustness; adaptive attack strength; ensemble model; gradient norm;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2026年04期
- 【分类号】TP18
- 【下载频次】16