arXiv:2412.10265cs.LGcs.DC2024-12ICML被引 2

研究神经网络在任务通信中的抗攻击能力,发现浅层瓶颈更易受攻击。

Adversarial Robustness of Bottleneck Injected Deep Neural Networks for Task-Oriented Communication

  • 用信息瓶颈机制注入浅层或深层瓶颈,测试抗攻击性能。
  • 深层瓶颈比浅层更抗攻击,复杂任务下差距更大。
  • 依赖生成模型恢复关键信息会增加被攻击风险,适合安全设计者参考。

本文研究基于信息瓶颈(IB)目标的深度神经网络在面向任务通信系统中的对抗鲁棒性。实验表明,尽管IB方法对下游任务攻击具有一定基础防御能力,但依赖生成模型进行信息提取与恢复的通信系统引入了新漏洞。在多个数据集上的大量实验显示,浅层变分瓶颈注入(SVBI)的抗攻击能力弱于深层变分信息瓶颈(DVIB),且任务越复杂,差距越大。此外,IB方法对高亮度显著像素的攻击更具鲁棒性,而对多低强度像素扰动的攻击防御较弱。最后,基于生成模型提取和恢复显著信息的任务通信系统存在更大的攻击面。研究揭示了下一代以神经网络为基础的目标压缩通信系统的重大安全挑战。

原文摘要 · Abstract (English)

This paper investigates the adversarial robustness of Deep Neural Networks (DNNs) using Information Bottleneck (IB) objectives for task-oriented communication systems. We empirically demonstrate that while IB-based approaches provide baseline resilience against attacks targeting downstream tasks, the reliance on generative models for task-oriented communication introduces new vulnerabilities. Through extensive experiments on several datasets, we analyze how bottleneck depth and task complexity influence adversarial robustness. Our key findings show that Shallow Variational Bottleneck Injection (SVBI) provides less adversarial robustness compared to Deep Variational Information Bottleneck (DVIB) approaches, with the gap widening for more complex tasks. Additionally, we reveal that IB-based objectives exhibit stronger robustness against attacks focusing on salient pixels with high intensity compared to those perturbing many pixels with lower intensity. Lastly, we demonstrate that task-oriented communication systems that rely on generative models to extract and recover salient information have an increased attack surface. The results highlight important security considerations for next-generation communication systems that leverage neural networks for goal-oriented compression.

对抗鲁棒性信息瓶颈通信安全生成模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。