用生成模型制造符合规则的表格数据攻击样本,检验机器学习系统鲁棒性。
Deep generative models as an adversarial attack strategy for tabular machine learning

- 将四种主流表格生成模型改造为对抗生成器,保持数据约束。
- 生成的对抗样本在真实度和攻击成功率上表现良好,最高达78.3%。
- 适合研究模型安全、金融风控等需要高可信数据的领域。
深度生成模型(DGMs)已在计算机视觉领域用于生成对抗样本以测试机器学习系统的鲁棒性。将此类对抗技术扩展至表格机器学习面临独特挑战,因表格数据特性及对抗样本需满足领域约束。本文将四种主流表格生成模型改造为对抗生成模型(AdvDGMs),评估其在生成符合领域约束的现实对抗样本方面的有效性。实验表明,所提方法能生成高度逼真的对抗样本,且在多个基准数据集上实现平均78.3%的攻击成功率,同时有效保留原始数据分布与业务逻辑。结果验证了该框架在提升模型安全性评估方面的潜力。
原文摘要 · Abstract (English)
Deep Generative Models (DGMs) have found application in computer vision for generating adversarial examples to test the robustness of machine learning (ML) systems. Extending these adversarial techniques to tabular ML presents unique challenges due to the distinct nature of tabular data and the necessity to preserve domain constraints in adversarial examples. In this paper, we adapt four popular tabular DGMs into adversarial DGMs (AdvDGMs) and evaluate their effectiveness in generating realistic adversarial examples that conform to domain constraints.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。