用对齐+对抗训练,让脑机接口更准更抗干扰
Alignment-Based Adversarial Training (ABAT) for Improving the Robustness and Accuracy of EEG-Based BCIs
- 先对齐不同数据域的脑电信号,再进行对抗训练
- 在5个数据集上同时提升分类准确率与抗攻击能力
- 适合关注脑机接口安全与性能的科研人员
机器学习在脑电(EEG)基脑机接口(BCI)中取得显著进展。现有研究多聚焦于提升解码准确率,较少关注对抗安全性。尽管计算机视觉等领域已有多种对抗防御方法,但直接迁移至BCI会降低正常样本上的分类准确率,限制其应用。为此,本文提出基于对齐的对抗训练(ABAT),在对抗训练前对脑电信号进行跨域对齐,以减小分布差异;再通过对抗训练增强分类边界鲁棒性。该方法使模型在准确率与鲁棒性上同时提升。在两个不同BCI范式(运动想象分类、事件相关电位识别)、三个卷积神经网络模型(EEGNet、ShallowCNN、DeepCNN)及三种实验设置(离线跨块/跨会话分类、在线跨会话分类、预训练模型)下验证了有效性。令人惊讶的是,原本用于破坏系统的对抗攻击,在ABAT中反而能同步提升模型精度与鲁棒性。
原文摘要 · Abstract (English)
Machine learning has achieved great success in electroencephalogram (EEG) based brain-computer interfaces (BCIs). Most existing BCI studies focused on improving the decoding accuracy, with only a few considering the adversarial security. Although many adversarial defense approaches have been proposed in other application domains such as computer vision, previous research showed that their direct extensions to BCIs degrade the classification accuracy on benign samples. This phenomenon greatly affects the applicability of adversarial defense approaches to EEG-based BCIs. To mitigate this problem, we propose alignment-based adversarial training (ABAT), which performs EEG data alignment before adversarial training. Data alignment aligns EEG trials from different domains to reduce their distribution discrepancies, and adversarial training further robustifies the classification boundary. The integration of data alignment and adversarial training can make the trained EEG classifiers simultaneously more accurate and more robust. Experiments on five EEG datasets from two different BCI paradigms (motor imagery classification, and event related potential recognition), three convolutional neural network classifiers (EEGNet, ShallowCNN and DeepCNN) and three different experimental settings (offline within-subject cross-block/-session classification, online cross-session classification, and pre-trained classifiers) demonstrated its effectiveness. It is very intriguing that adversarial attacks, which are usually used to damage BCI systems, can be used in ABAT to simultaneously improve the model accuracy and robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。