节点文献

自适应攻击强度的模型集成对抗训练方法

Model ensemble adversarial training with adaptive attack strength

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 朱国豪常兆斌赵宏孙其翔

【Author】 ZHU Guo-hao;CHANG Zhao-bin;ZHAO Hong;SUN Qi-xiang;College of Computer and Communication,Lanzhou University of Technology;School of Information Science & Engineering,Lanzhou University;

【通讯作者】 赵宏;

【机构】 兰州理工大学计算机与通信学院兰州大学信息科学与工程学院

【摘要】 为提高深度学习模型在对抗样本攻击时的鲁棒性,提出了一种自适应攻击强度的模型集成对抗训练方法。在训练模型过程中,根据模型梯度范数的变化,采用多步迭代法动态调整扰动步长,在不同训练阶段获得相应攻击强度的对抗样本。此外,采用集成对抗训练,将不同模型梯度之间的余弦相似度作为正则化项,降低多个模型生成对抗样本的特征重叠度,使模型能够适应多样化数据分布的对抗样本,从而增强模型的鲁棒性。实验结果表明,相较于现有方法,所提方法在CIFAR-10和CIFAR-100数据集的鲁棒准确率分别提升8.32%和4.01%。

【Abstract】 To improve the robustness of deep learning models against adversarial sample attacks, an adaptive attack strength model ensemble adversarial training method was proposed. During the model training process, the perturbation step size was dynamically adjusted using a multi-step iterative method based on the changes in the model gradient norm, obtaining adversarial samples with corresponding attack intensities at different training stages. Moreover, ensemble adversarial training was employed, where the cosine similarity between the gradients of different models was used as a regularization term to reduce the feature overlap of adversarial samples generated by multiple models, allowing the model to adapt to adversarial examples from diverse data distributions and thus enhancing its robustness. Experimental results show that compared to existing methods, the proposed method improves the robust accuracy by 8. 32% and 4. 01% on the CIFAR-10 and CIFAR-100 datasets, respectively.

【基金】 国家自然科学基金项目(62166025);中国科协青年人才推举工程“博士生专项计划”学术基金项目
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2026年04期
  • 【分类号】TP18
  • 【下载频次】16
节点文献中: 

本文链接的文献网络图示:

本文的引文网络