研究对抗补丁的低维结构,发现主成分分析已足够有效。
Traversing the Subspace of Adversarial Patches
- 用降维方法分析对抗补丁的潜在空间结构
- 简单PCA在重建攻击补丁上表现不输复杂方法
- 适合关注对抗样本本质机制的研究者
尽管深度学习中的对抗样本研究持续进行,但其本质仍不明确。基于流形假设,高维数据往往位于低维流形上。本文分析一组对抗补丁,考察三种降维方法在重建上的能力。定量评估重建补丁在攻击任务中的表现,并探究对抗训练中从潜在空间采样补丁的影响。实验在两个公开的人体检测数据集上进行。结果表明,更复杂的降维方法在性能上并无优势,简单主成分分析(PCA)已足够有效。
原文摘要 · Abstract (English)
Despite ongoing research on the topic of adversarial examples in deep learning for computer vision, some fundamentals of the nature of these attacks remain unclear. As the manifold hypothesis posits, high-dimensional data tends to be part of a low-dimensional manifold. To verify the thesis with adversarial patches, this paper provides an analysis of a set of adversarial patches and investigates the reconstruction abilities of three different dimensionality reduction methods. Quantitatively, the performance of reconstructed patches in an attack setting is measured and the impact of sampled patches from the latent space during adversarial training is investigated. The evaluation is performed on two publicly available datasets for person detection. The results indicate that more sophisticated dimensionality reduction methods offer no advantages over a simple principal component analysis.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。