arXiv:2409.13470cs.LGcond-mat.dis-nn2024-09被引 4

用神经动力学模型对抗随机对抗攻击,噪声让分类更稳健

Deterministic versus stochastic dynamical classifiers: opposing random adversarial attacks with noise

论文配图:Deterministic versus stochastic dynamical classifiers: opposing random adversarial attacks with noise
图 1 · 摘自论文原文
  • 用耦合微分方程建模神经动力学,通过吸引子引导分类
  • 随机变体在对抗攻击下仍保持高准确率,鲁棒性显著提升
  • 适合对生物可解释性与抗干扰性有要求的研究者

连续变量放电率(CVFR)模型广泛用于描述兴奋性生物神经元之间的复杂动态。本文将其作为动态辅助分类器进行训练与测试:通过谱分解将预设吸引子自洽嵌入节点间耦合矩阵中。分类学习即为调整各平衡态的吸引盆,使不同输入导向对应目标,反映其类别归属。研究还考察了该模型的随机变体,发现其对随机对抗攻击具有显著鲁棒性——此类攻击会破坏待分类输入。这一惊人结果揭示了当噪声与动力学属性相互共振时,产生的诸多意想不到效应。总体而言,本研究证明了一类基于耦合常微分方程的生物可解释模型,能够高效应对非平凡的分类任务。

原文摘要 · Abstract (English)

The Continuous-Variable Firing Rate (CVFR) model, widely used in neuroscience to describe the intertangled dynamics of excitatory biological neurons, is here trained and tested as a veritable dynamically assisted classifier. To this end the model is supplied with a set of planted attractors which are self-consistently embedded in the inter-nodes coupling matrix, via its spectral decomposition. Learning to classify amounts to sculp the basin of attraction of the imposed equilibria, directing different items towards the corresponding destination target, which reflects the class of respective pertinence. A stochastic variant of the CVFR model is also studied and found to be robust to aversarial random attacks, which corrupt the items to be classified. This remarkable finding is one of the very many surprising effects which arise when noise and dynamical attributes are made to mutually resonate.

神经动力学对抗攻击随机模型分类器

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。