Adversarial parameter defense by multi-step risk minimization

被引:3
|
作者
Zhang, Zhiyuan [1 ]
Luo, Ruixuan [2 ]
Ren, Xuancheng [1 ]
Su, Qi [1 ,3 ]
Li, Liangyou [4 ]
Sun, Xu [1 ,2 ]
机构
[1] Peking Univ, Sch EECS, MOE Key Lab Computat Linguist, Beijing, Peoples R China
[2] Peking Univ, Ctr Data Sci, Beijing, Peoples R China
[3] Peking Univ, Sch Foreign Languages, Beijing, Peoples R China
[4] Huawei Noahs Ark Lab, Hong Kong, Peoples R China
基金
国家重点研发计划;
关键词
Vulnerability of deep neural networks; Parameter corruption; Adversarial parameter defense; NETWORKS;
D O I
10.1016/j.neunet.2021.08.022
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Previous studies demonstrate DNNs' vulnerability to adversarial examples and adversarial training can establish a defense to adversarial examples. In addition, recent studies show that deep neural networks also exhibit vulnerability to parameter corruptions. The vulnerability of model parameters is of crucial value to the study of model robustness and generalization. In this work, we introduce the concept of parameter corruption and propose to leverage the loss change indicators for measuring the flatness of the loss basin and the parameter robustness of neural network parameters. On such basis, we analyze parameter corruptions and propose the multi-step adversarial corruption algorithm. To enhance neural networks, we propose the adversarial parameter defense algorithm that minimizes the average risk of multiple adversarial parameter corruptions. Experimental results show that the proposed algorithm can improve both the parameter robustness and accuracy of neural networks. (C) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页码:154 / 163
页数:10
相关论文
共 50 条
  • [31] Defense against Adversarial Swarms with Parameter Uncertainty
    Walton, Claire
    Kaminer, Isaac
    Gong, Qi
    Clark, Abram H.
    Tsatsanifos, Theodoros
    SENSORS, 2022, 22 (13)
  • [32] Chaos control of gear system with elastomeric web based on multi-parameter multi-step method
    刘海霞
    江波
    王三民
    郭家舜
    Journal of Harbin Institute of Technology, 2012, 19 (05) : 23 - 30
  • [33] Chaos control of gear system with elastomeric web based on multi-parameter multi-step method
    刘海霞
    江波
    王三民
    郭家舜
    Journal of Harbin Institute of Technology(New series), 2012, (05) : 23 - 30
  • [34] Multi-step carcinogenesis and the implications for low dose radiation risk philosophy
    Chadwick, KH
    Leenhouts, HP
    PROCESS SAFETY AND ENVIRONMENTAL PROTECTION, 1995, 73 (B4) : S18 - S23
  • [35] Chaos control of gear system with elastomeric web based on multi-parameter multi-step method
    Jiang, B. (ilysay@opt.ac.cn), 1600, Harbin Institute of Technology, P.O. Box 136, Harbin, 150001, China (19):
  • [36] An optimal multi-step quadratic risk-adjusted hedging strategy
    Shih-Feng Huang
    Meihui Guo
    Journal of the Korean Statistical Society, 2013, 42 : 37 - 49
  • [37] An optimal multi-step quadratic risk-adjusted hedging strategy
    Huang, Shih-Feng
    Guo, Meihui
    JOURNAL OF THE KOREAN STATISTICAL SOCIETY, 2013, 42 (01) : 37 - 49
  • [38] Knowledge Base System for Risk Analysis of the Multi-step Computer Attacks
    Yakhyaeva, Gulnara
    Ershov, Aleksey
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL 2 (ICEIS), 2016, : 143 - 150
  • [39] Security risk assessment based on bayesian multi-step attack graphs
    Yang, Yunxue
    Jin, Shuyuan
    Fang, Binxing
    Journal of Computational Information Systems, 2015, 11 (11): : 3911 - 3918
  • [40] Application of Multi-Step Parameter Estimation Method Based on Optimization Algorithm in Sacramento Model
    Zhang, Gang
    Xie, Tuo
    Zhang, Lei
    Hua, Xia
    Liu, Fuchao
    WATER, 2017, 9 (07)