arXiv:2409.16491cs.CV2024-09IJCV综述被引 4

用隐秘模板加密数据,提升模型性能,助力AI安全发展

Proactive Schemes: A Survey of Adversarial Attacks for Social Good

  • 用不可见模板加密输入数据,主动增强模型表现
  • 相比被动方法,可显著提升图像与文本任务性能
  • 适合关注AI安全与鲁棒性的研究者与开发者

计算机视觉中的对抗攻击通过在输入数据中引入细微扰动,利用机器学习模型的脆弱性导致错误预测,随着深度学习的发展愈发复杂,可能对社会造成危害。然而,也有研究从积极角度出发,利用对抗技术实现社会价值。本文聚焦于主动方案——通过额外信号(称为模板)加密输入数据,以提升深度学习模型性能。将这些不可察觉的模板嵌入数字媒体后,主动方案被应用于从图像增强到复杂深度学习框架等多种场景,相较不改变输入分布的被动方案更具优势。本综述深入探讨了主动方案的方法论、加密与学习过程,及其在现代计算机视觉与自然语言处理中的应用。同时分析其挑战、潜在漏洞及未来方向,最终强调其在推动深度学习技术负责任、安全演进方面的潜力。

原文摘要 · Abstract (English)

Adversarial attacks in computer vision exploit the vulnerabilities of machine learning models by introducing subtle perturbations to input data, often leading to incorrect predictions or classifications. These attacks have evolved in sophistication with the advent of deep learning, presenting significant challenges in critical applications, which can be harmful for society. However, there is also a rich line of research from a transformative perspective that leverages adversarial techniques for social good. Specifically, we examine the rise of proactive schemes-methods that encrypt input data using additional signals termed templates, to enhance the performance of deep learning models. By embedding these imperceptible templates into digital media, proactive schemes are applied across various applications, from simple image enhancements to complicated deep learning frameworks to aid performance, as compared to the passive schemes, which don't change the input data distribution for their framework. The survey delves into the methodologies behind these proactive schemes, the encryption and learning processes, and their application to modern computer vision and natural language processing applications. Additionally, it discusses the challenges, potential vulnerabilities, and future directions for proactive schemes, ultimately highlighting their potential to foster the responsible and secure advancement of deep learning technologies.

对抗攻击AI安全主动防御深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。