研究深度模型不确定性与对抗攻击的关系,揭示攻击如何放大模型信心偏差。
Relationship between Uncertainty in DNNs and Adversarial Attacks
- 分析对抗攻击如何通过扰动输入加剧模型预测不确定性
- 指出模型不确定性在攻击下显著上升,影响决策可信度
- 适合关注模型鲁棒性与可信AI的科研人员参考
深度神经网络(DNN)在自然语言处理、模式识别、预测和控制优化等多个领域取得顶尖性能,甚至超越人类水平。然而,其预测结果常伴随不确定性,可能导致错误判断或超出置信区间。这种不确定性源于模型或数据限制,可能被对抗攻击进一步放大。对抗攻击通过引入微小扰动输入,诱导DNN做出错误预测或提升模型不确定性。本文综述了DNN不确定性与对抗攻击之间的关系,重点探讨对抗攻击如何增强模型不确定性,揭示二者内在关联。
原文摘要 · Abstract (English)
Deep Neural Networks (DNNs) have achieved state of the art results and even outperformed human accuracy in many challenging tasks, leading to DNNs adoption in a variety of fields including natural language processing, pattern recognition, prediction, and control optimization. However, DNNs are accompanied by uncertainty about their results, causing them to predict an outcome that is either incorrect or outside of a certain level of confidence. These uncertainties stem from model or data constraints, which could be exacerbated by adversarial attacks. Adversarial attacks aim to provide perturbed input to DNNs, causing the DNN to make incorrect predictions or increase model uncertainty. In this review, we explore the relationship between DNN uncertainty and adversarial attacks, emphasizing how adversarial attacks might raise DNN uncertainty.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。