arXiv:2410.20284cs.LGmath.OC2024-10被引 4

用悲观双层优化建模对抗者操纵,提升分类器鲁棒性。

Classification under strategic adversary manipulation using pessimistic bilevel optimisation

  • 将学习者与对抗者视为博弈双方,构建悲观双层优化框架。
  • 无需假设对抗者选择最低成本方案,支持非凸和多解场景。
  • 在垃圾邮件、恶意软件等场景中显著优于传统方法。

对抗机器学习关注学习者面对主动攻击者的情形,此类问题常见于垃圾邮件过滤、恶意软件检测和伪造图像生成等应用,安全机制需持续更新以应对不断进化的恶意数据。本文将学习者与对抗者之间的交互建模为博弈,将问题形式化为学习者作为领导者、对抗者作为追随者的悲观双层优化问题。对抗者被建模为随机数据生成器,根据分类器动态生成数据。现有模型依赖于对抗者选择最低成本解的假设,从而保证下层问题为凸且有唯一解;本文提出一种新模型与求解方法,不依赖该假设,可处理更一般情形。实验表明,放松该假设显著提升了性能,验证了模型的现实合理性。

原文摘要 · Abstract (English)

Adversarial machine learning concerns situations in which learners face attacks from active adversaries. Such scenarios arise in applications such as spam email filtering, malware detection and fake-image generation, where security methods must be actively updated to keep up with the ever improving generation of malicious data.We model these interactions between the learner and the adversary as a game and formulate the problem as a pessimistic bilevel optimisation problem with the learner taking the role of the leader. The adversary, modelled as a stochastic data generator, takes the role of the follower, generating data in response to the classifier. While existing models rely on the assumption that the adversary will choose the least costly solution leading to a convex lower-level problem with a unique solution, we present a novel model and solution method which do not make such assumptions. We compare these to the existing approach and see significant improvements in performance suggesting that relaxing these assumptions leads to a more realistic model.

对抗学习双层优化鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。