论文标题

梯度混淆清单测试给出了错误的安全感

Gradient Obfuscation Checklist Test Gives a False Sense of Security

论文作者

Popovic, Nikola, Paudel, Danda Pani, Probst, Thomas, Van Gool, Luc

论文摘要

一组受欢迎的防御技术反对对抗性攻击,是基于向网络注入随机噪声的基础。然而,这种随机防御的鲁棒性的主要来源通常是由于梯度混淆,提供了错误的安全感。由于大多数流行的对抗攻击都是基于优化的,因此混淆的梯度降低了其攻击能力,而模型仍然容易受到更强或专门定制的对抗性攻击的影响。最近,已经确定了五个特征,当鲁棒性的改善主要是由梯度混淆引起的时,通常会观察到。此后,将这五个特征用作足够的测试成为一种趋势,以确定梯度混淆是否是鲁棒性的主要来源。但是,这些特征并不能完美地表征所有现有的梯度混淆案例,因此无法作为结论性测试的基础。在这项工作中,我们提出反例,表明该测试不足以结论梯度混淆并不是鲁棒性改善的主要原因。

One popular group of defense techniques against adversarial attacks is based on injecting stochastic noise into the network. The main source of robustness of such stochastic defenses however is often due to the obfuscation of the gradients, offering a false sense of security. Since most of the popular adversarial attacks are optimization-based, obfuscated gradients reduce their attacking ability, while the model is still susceptible to stronger or specifically tailored adversarial attacks. Recently, five characteristics have been identified, which are commonly observed when the improvement in robustness is mainly caused by gradient obfuscation. It has since become a trend to use these five characteristics as a sufficient test, to determine whether or not gradient obfuscation is the main source of robustness. However, these characteristics do not perfectly characterize all existing cases of gradient obfuscation, and therefore can not serve as a basis for a conclusive test. In this work, we present a counterexample, showing this test is not sufficient for concluding that gradient obfuscation is not the main cause of improvements in robustness.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源