arXiv:2411.15878cs.LG2024-11

用强化探索生成更有效的对抗样本,提升模型防御能力

ExAL: An Exploration Enhanced Adversarial Learning Algorithm

  • 引入改进的粒子群优化算法,主动探索多样对抗扰动
  • 在MNIST和恶意软件数据集上显著提升模型抗攻击能力
  • 适合关注对抗训练与模型鲁棒性增强的研究者

对抗学习对提升模型鲁棒性至关重要,旨在防御威胁机器学习系统的对抗攻击。传统方法往往缺乏高效机制来探索多样化的对抗扰动,导致模型防御能力受限。受博弈论启发,我们提出一种新型探索增强型对抗学习算法(ExAL),利用指数加权动量粒子群优化器(EMPSO)生成优化后的对抗扰动。ExAL通过探索驱动机制,发现能最大化影响模型决策边界、同时保持数据结构一致性的扰动。我们在手写数字数据集MNIST和混合恶意软件数据集Blended Malware上评估了ExAL性能。实验结果表明,该方法通过对抗学习显著增强了模型对对抗攻击的韧性。

原文摘要 · Abstract (English)

Adversarial learning is critical for enhancing model robustness, aiming to defend against adversarial attacks that jeopardize machine learning systems. Traditional methods often lack efficient mechanisms to explore diverse adversarial perturbations, leading to limited model resilience. Inspired by game-theoretic principles, where adversarial dynamics are analyzed through frameworks like Nash equilibrium, exploration mechanisms in such setups allow for the discovery of diverse strategies, enhancing system robustness. However, existing adversarial learning methods often fail to incorporate structured exploration effectively, reducing their ability to improve model defense comprehensively. To address these challenges, we propose a novel Exploration-enhanced Adversarial Learning Algorithm (ExAL), leveraging the Exponentially Weighted Momentum Particle Swarm Optimizer (EMPSO) to generate optimized adversarial perturbations. ExAL integrates exploration-driven mechanisms to discover perturbations that maximize impact on the model's decision boundary while preserving structural coherence in the data. We evaluate the performance of ExAL on the MNIST Handwritten Digits and Blended Malware datasets. Experimental results demonstrate that ExAL significantly enhances model resilience to adversarial attacks by improving robustness through adversarial learning.

对抗学习优化算法模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。