The Adversarial Attack and Detection under the Fisher Information Metric

被引:0
|
作者
Zhao, Chenxiao [1 ]
Fletcher, P. Thomas [2 ,3 ]
Yu, Mixue [1 ]
Peng, Yaxin [4 ,5 ]
Zhang, Guixu [1 ]
Shen, Chaomin [1 ,5 ]
机构
[1] East China Normal Univ, Dept Comp Sci, Shanghai, Peoples R China
[2] Univ Virginia, Dept Elect & Comp Sci, Charlottesville, VA 22903 USA
[3] Univ Virginia, Dept Comp Sci, Charlottesville, VA 22903 USA
[4] Shanghai Univ, Dept Math, Shanghai, Peoples R China
[5] Westlake Inst Brain Like Sci & Technol, Hangzhou, Zhejiang, Peoples R China
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many deep learning models are vulnerable to the adversarial attack, i.e., imperceptible but intentionally-designed perturbations to the input can cause incorrect output of the networks. In this paper, using information geometry, we provide a reasonable explanation for the vulnerability of deep learning models. By considering the data space as a non-linear space with the Fisher information metric induced from a neural network, we first propose an adversarial attack algorithm termed one-step spectral attack (OSSA). The method is described by a constrained quadratic form of the Fisher information matrix, where the optimal adversarial perturbation is given by the first eigenvector, and the vulnerability is reflected by the eigenvalues. The larger an eigenvalue is, the more vulnerable the model is to be attacked by the corresponding eigenvector. Taking advantage of the property, we also propose an adversarial detection method with the eigenvalues serving as characteristics. Both our attack and detection algorithms are numerically optimized to work efficiently on large datasets. Our evaluations show superior performance compared with other methods, implying that the Fisher information is a promising approach to investigate the adversarial attacks and defenses.
引用
收藏
页码:5869 / 5876
页数:8
相关论文
共 50 条
  • [1] The uniqueness of the Fisher metric as information metric
    Hong Van Le
    ANNALS OF THE INSTITUTE OF STATISTICAL MATHEMATICS, 2017, 69 (04) : 879 - 896
  • [2] The uniqueness of the Fisher metric as information metric
    Hông Vân Lê
    Annals of the Institute of Statistical Mathematics, 2017, 69 : 879 - 896
  • [3] Detection of image structures using the Fisher information and the Rao metric
    Maybank, SJ
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2004, 26 (12) : 1579 - 1589
  • [4] Dynamics of the Fisher information metric
    Calmet, X
    Calmet, J
    PHYSICAL REVIEW E, 2005, 71 (05):
  • [5] UDP Flooding Attack Detection Using Information Metric Measure
    Boro, Debojit
    Basumatary, Himant
    Goswami, Tribeni
    Bhattacharyya, Dhruba K.
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON ICT FOR SUSTAINABLE DEVELOPMENT, ICT4SD 2015, VOL 1, 2016, 408 : 143 - 153
  • [6] Conformal Fisher information metric with torsion
    Pal, Kunal
    Pal, Kuntal
    Sarkar, Tapobrata
    JOURNAL OF PHYSICS A-MATHEMATICAL AND THEORETICAL, 2023, 56 (33)
  • [7] Fisher information metric and Poisson kernels
    Itoh, Mitsuhiro
    Shishido, Yuichi
    DIFFERENTIAL GEOMETRY AND ITS APPLICATIONS, 2008, 26 (04) : 347 - 356
  • [8] Fisher Information as a Utility Metric for Frequency Estimation under Local Differential Privacy
    Lopuhaa-Zwakenberg, Milan
    Skoric, Boris
    Li, Ninghui
    PROCEEDINGS OF THE 21ST WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2022, 2022, : 41 - 53
  • [9] Inspecting adversarial examples using the fisher information
    Martin, Joerg
    Elster, Clemens
    NEUROCOMPUTING, 2020, 382 : 80 - 86
  • [10] Geometry of Fisher Information Metric and the Barycenter Map
    Itoh, Mitsuhiro
    Satoh, Hiroyasu
    ENTROPY, 2015, 17 (04): : 1814 - 1849