arXiv:2501.05588cs.LGhep-ex2025-01被引 5

通过扰动输入相关性提升分类性能,适用于多领域科学任务

Enforcing Fundamental Relations via Adversarial Attacks on Input Parameter Correlations

  • 设计新对抗攻击法RDSA,聚焦特征间相关性而非单个特征
  • 在6个任务中显著提升分类准确率,尤其在数据增强场景下
  • 适用于高能物理、医疗、气象等依赖输入关联性的领域

输入参数间的相关性在诸多科学分类任务中至关重要,因它们常反映自然基本规律。例如,在高能物理中,深度学习常用于粒子碰撞中信号与背景过程的分类,而可观测量之间的基本关联原理往往比其分布本身更易理解。本文提出一种新型对抗攻击算法——随机分布置换攻击(RDSA),重点扰动网络中可观测量之间的相关性,而非单个特征。正确应用该攻击可显著提升分类性能,尤其在对抗训练中使用生成的对抗样本时效果明显。由于输入特征相关性在多个学科中同样关键,我们在六个分类任务上验证了RDSA的有效性:包括两个基于CERN开放数据的粒子碰撞挑战、手写数字识别(MNIST784)、人体活动识别(HAR)、天气预测(Rain in Australia)以及重症监护患者死亡率预测(MIMIC-IV),证明该方法具有超越基础物理领域的广泛适用性。

原文摘要 · Abstract (English)

Correlations between input parameters play a crucial role in many scientific classification tasks, since these are often related to fundamental laws of nature. For example, in high energy physics, one of the common deep learning use-cases is the classification of signal and background processes in particle collisions. In many such cases, the fundamental principles of the correlations between observables are often better understood than the actual distributions of the observables themselves. In this work, we present a new adversarial attack algorithm called Random Distribution Shuffle Attack (RDSA), emphasizing the correlations between observables in the network rather than individual feature characteristics. Correct application of the proposed novel attack can result in a significant improvement in classification performance - particularly in the context of data augmentation - when using the generated adversaries within adversarial training. Given that correlations between input features are also crucial in many other disciplines. We demonstrate the RDSA effectiveness on six classification tasks, including two particle collision challenges (using CERN Open Data), hand-written digit recognition (MNIST784), human activity recognition (HAR), weather forecasting (Rain in Australia), and ICU patient mortality (MIMIC-IV), demonstrating a general use case beyond fundamental physics for this new type of adversarial attack algorithms.

对抗攻击相关性建模科学分类数据增强

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。