提出适用于双曲网络的新型对抗攻击方法,揭示几何差异对鲁棒性的影响。
Adversarial Attacks on Hyperbolic Networks
- 设计双曲空间下的FGM和PGD攻击变体
- 发现双曲与欧氏网络存在不同脆弱性模式
- 适合研究非欧几何下模型安全性的学者
随着双曲深度学习日益流行,其非欧几里得几何背景下的对抗鲁棒性需求也随之增长。本文提出了适用于双曲空间的FGM和PGD对抗攻击的替代方案。通过可解释的合成基准和现有数据集上的实验,我们展示了现有攻击与新提出的攻击之间的差异。此外,我们研究了欧氏网络与全双曲网络在对抗鲁棒性上的区别,发现两类网络表现出不同的脆弱性特征,且新提出的双曲攻击无法解决这些差异。因此,我们得出结论:对抗鲁棒性的变化源于模型因几何差异而学习到的不同模式。
原文摘要 · Abstract (English)
As hyperbolic deep learning grows in popularity, so does the need for adversarial robustness in the context of such a non-Euclidean geometry. To this end, this paper proposes hyperbolic alternatives to the commonly used FGM and PGD adversarial attacks. Through interpretable synthetic benchmarks and experiments on existing datasets, we show how the existing and newly proposed attacks differ. Moreover, we investigate the differences in adversarial robustness between Euclidean and fully hyperbolic networks. We find that these networks suffer from different types of vulnerabilities and that the newly proposed hyperbolic attacks cannot address these differences. Therefore, we conclude that the shifts in adversarial robustness are due to the models learning distinct patterns resulting from their different geometries.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。