arXiv:2412.07559cs.LG2024-12

用自适应扰动提升引力波参数估计的抗干扰能力

Adaptive Epsilon Adversarial Training for Robust Gravitational Wave Parameter Estimation Using Normalizing Flows

  • 基于梯度对数缩放动态调整扰动强度,增强对抗训练效果
  • 在强攻击下仍保持低负对数似然(5.8),比固定方法低13%以上
  • 适合需要高鲁棒性的科学计算场景,如引力波数据分析

针对引力波参数估计中模型易受对抗样本影响的问题,本文将归一化流(NF)与对抗训练结合。提出一种自适应epsilon的快速梯度符号法(FGSM),根据梯度幅度采用对数缩放动态调节扰动强度。所提混合架构(ResNet+逆自回归流)在FGSM攻击下负对数似然(NLL)降低47%,清洁数据上NLL为4.2(仅比基线高5%)。当扰动强度在0.01至0.1之间时,平均NLL达5.8,优于固定epsilon(6.7)和渐进epsilon(7.2)方法。在投影梯度下降攻击(强度0.05)下,模型仍保持NLL为6.4,表现出更强鲁棒性且避免灾难性过拟合。

原文摘要 · Abstract (English)

Adversarial training with Normalizing Flow (NF) models is an emerging research area aimed at improving model robustness through adversarial samples. In this study, we focus on applying adversarial training to NF models for gravitational wave parameter estimation. We propose an adaptive epsilon method for Fast Gradient Sign Method (FGSM) adversarial training, which dynamically adjusts perturbation strengths based on gradient magnitudes using logarithmic scaling. Our hybrid architecture, combining ResNet and Inverse Autoregressive Flow, reduces the Negative Log Likelihood (NLL) loss by 47\% under FGSM attacks compared to the baseline model, while maintaining an NLL of 4.2 on clean data (only 5\% higher than the baseline). For perturbation strengths between 0.01 and 0.1, our model achieves an average NLL of 5.8, outperforming both fixed-epsilon (NLL: 6.7) and progressive-epsilon (NLL: 7.2) methods. Under stronger Projected Gradient Descent attacks with perturbation strength of 0.05, our model maintains an NLL of 6.4, demonstrating superior robustness while avoiding catastrophic overfitting.

引力波对抗训练归一化流

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。