节点文献
基于负相关集成的对抗样本防御方法研究
Research on Adversarial Example Defense Methods Based on Negative Correlation Ensemble
【作者】 张宏伟;
【导师】 罗文坚;
【作者基本信息】 哈尔滨工业大学 , 电子信息(专业学位), 2023, 硕士
【摘要】 随着深度神经网络在工业界的广泛应用,如何安全高效的部署深度神经网络成为一个重要问题。对抗样本是指在原始样本的基础上添加一个肉眼不可区分的微小扰动,而这个微小扰动是被攻击者精心设计过的,且深度神经网络以高置信度输出攻击者想要的标签分类。显然,对抗样本的出现给深度学习的发展带来了巨大的安全风险。目前,针对对抗样本的攻防研究主要集中在单标签分类领域,研究者们也提出了很多高性能的攻防算法。一般来说,相比于单标签分类,多标签分类更贴合现实应用,具有更高的应用价值。本文针对单标签分类和多标签分类应用,基于负相关原理分别提出了具有较高性能的集成防御算法。针对单标签分类应用,本文提出了一种新的集成防御方案,称为负相关集成(NCEn)。与其他集成防御方案不同,NCEn充分考虑了集成中各成员之间的相互作用,同时协同地对集成中各成员进行训练。NCEn通过使集成中所有成员的梯度方向和梯度幅度同时负相关来提高集成的对抗鲁棒性。攻击者沿某个方向添加的对抗扰动,可能会使集成中的某个成员产生误判,但并不会影响集成中的大多数成员。实验表明,NCEn不仅可以降低对抗样本在各成员之间的迁移性,而且在两个数据集和四种模型集成结构中都表现出良好的对抗鲁棒性。针对多标签分类应用,本文通过考虑数据集中的正标签集合和负标签集合,提出一种新的多标签集成防御算法:称为多标签负相关集成(ML-NCEn)。MLNCEn使集成中各成员在学习时分别考虑正标签和负标签的梯度方向和梯度幅度来避免隐藏单标签的攻击。当对抗样本可以使集成中的某个成员将特定正标签隐藏为负标签时,ML-NCEn中的其他成员并不一定会被该对抗样本欺骗。本文通过使集成中各成员梯度方向和梯度幅度分别在正标签集合和负标签集合中负相关来降低攻击者沿某个方向添加的对抗扰动可以欺骗集成中大多数成员的可能性。实验表明,ML-NCEn在两个数据集上与其他五种对照方案相比均表现出良好的对抗鲁棒性。
【Abstract】 With the widespread use of deep neural networks in industry,how to deploy deep neural networks safely and efficiently has become an important issue.An adversarial example is a tiny perturbation that is indistinguishable to the naked eye added to the original example.And this tiny perturbation is carefully designed by the attacker,and the deep neural network outputs the labeled classification that the attacker wants with high confidence.Clearly,the emergence of adversarial examples poses a significant security risk to the development of deep learning.Currently,the research on attack and defense against adversarial examples is mainly focused on the field of single-label classification,and researchers have proposed many high-performance attack and defense algorithms.Generally,compared with single-label classification,multi-label classification is more relevant to real applications and has higher application value.In this thesis,ensemble defense algorithms with high performance are proposed for single-label classification and multi-label classification applications based on the negative correlation principle,respectively.For single-label classification applications,this thesis proposes a new ensemble defense scheme called Negative Correlation Ensemble(NCEn).Unlike other ensemble defense schemes,NCEn takes into account the interaction between the members of the ensemble and cooperates to train the ensemble members.NCEn improves the adversarial robustness of the ensemble by negatively correlating the gradient direction and gradient magnitude of all members in the ensemble simultaneously.An adversarial perturbation added by an attacker in a certain direction may cause a miscalculation of a member of the ensemble,but it will not affect most members in the ensemble.Experiments have verified that NCEn can not only reduce the transferability of adversarial examples between members,but also show good adversarial robustness in two datasets and four model ensemble structures.For multi-label classification,this thesis proposes a new multi-label ensemble defense algorithm,called Multi-Label Negative Correlation Ensemble(ML-NCEn),by considering the positive label set and negative label set in the dataset.ML-NCEn enables each member of the ensemble to consider the gradient direction and gradient magnitude of positive and negative labels respectively when learning to avoid hidden single-label attacks.While adversarial examples can enable a member of the ensemble to hide a particular positive tag as a negative tag,other members in ML-NCEn are not necessarily spoofed by that adversarial example.This thesis reduces the possibility that an adversarial perturbation added by an attacker in one direction can fool most members in the ensemble by making the gradient direction and gradient magnitude negatively correlated in the positive label set and negative label set,respectively.Experiments have verified that ML-NCEn shows good adversarial robustness compared with the other five control schemes on both datasets.
【Key words】 Deep learning; adversarial examples; ensemble; negative correlation;
- 【网络出版投稿人】 哈尔滨工业大学 【网络出版年期】2025年 04期
- 【分类号】TP183;TP391.41