arXiv:2501.01025cs.LGcs.AI2025-01

提出新防御方法增强度量学习模型在聚类场景下的抗攻击能力

Towards Adversarially Robust Deep Metric Learning

  • 采用集成学习与自迁移机制提升模型多样性与鲁棒性
  • 在三个数据集上显著优于传统分类模型防御方案
  • 特别适用于聚类推理场景,为度量学习安全提供新思路

深度度量学习(DML)在多个领域取得显著成功,得益于强大的深度神经网络。然而,深度神经网络易受对抗攻击,可能被对抗样本误导。当前的研究主要集中在深度分类模型的鲁棒性,对DML模型关注较少。现有工作未能全面检验DML的鲁棒性,且忽视了基于聚类的推理这一重要场景。本文首次指出DML在聚类推理中的鲁棒性问题。发现针对DML设计的防御无法直接复用,而将分类模型的防御方法迁移到DML也难以获得满意性能。为此,提出一种新型防御方法——集成对抗训练(EAT),结合集成学习与对抗训练,促进集成中各模型的差异性,使每个模型具备不同鲁棒特征,并通过自迁移机制利用整个集成的鲁棒统计信息更新单个模型。在三个常用数据集和两种主流模型架构上评估EAT,结果表明其显著优于针对分类模型设计的防御方法的适配版本。

原文摘要 · Abstract (English)

Deep Metric Learning (DML) has shown remarkable successes in many domains by taking advantage of powerful deep neural networks. Deep neural networks are prone to adversarial attacks and could be easily fooled by adversarial examples. The current progress on this robustness issue is mainly about deep classification models but pays little attention to DML models. Existing works fail to thoroughly inspect the robustness of DML and neglect an important DML scenario, the clustering-based inference. In this work, we first point out the robustness issue of DML models in clustering-based inference scenarios. We find that, for the clustering-based inference, existing defenses designed DML are unable to be reused and the adaptions of defenses designed for deep classification models cannot achieve satisfactory robustness performance. To alleviate the hazard of adversarial examples, we propose a new defense, the Ensemble Adversarial Training (EAT), which exploits ensemble learning and adversarial training. EAT promotes the diversity of the ensemble, encouraging each model in the ensemble to have different robustness features, and employs a self-transferring mechanism to make full use of the robustness statistics of the whole ensemble in the update of every single model. We evaluate the EAT method on three widely-used datasets with two popular model architectures. The results show that the proposed EAT method greatly outperforms the adaptions of defenses designed for deep classification models.

度量学习对抗鲁棒性集成学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。