提出新搜索方法评估解释稳定性,更精准衡量模型脆弱性。
Improving Stability Estimates in Adversarial Explainable AI through Alternate Search Methods
- 用替代搜索法寻找最小扰动以暴露解释不稳定性
- 发现需更少扰动即能触发相同不稳定性,说明方法更脆弱
- 适合关注AI可解释性安全性的研究人员参考
机器学习模型性能提升伴随巨大复杂性,导致其运行机制难以理解。局部代理方法常被用于近似复杂模型的运作,但近期研究揭示这些方法易受对抗攻击:解释结果显著变化,而原模型输出的意义和结构保持不变。此前工作仅关注此类弱点的存在性,未量化其程度。本文通过交替搜索方法,旨在找到实现特定解释相似度所需的最小扰动量。直观上,达到给定不稳定程度所需扰动越少,说明该解释方法越脆弱。这一细微差异使不同可解释性方法的稳定性比较更加精确。
原文摘要 · Abstract (English)
Advances in the effectiveness of machine learning models have come at the cost of enormous complexity resulting in a poor understanding of how they function. Local surrogate methods have been used to approximate the workings of these complex models, but recent work has revealed their vulnerability to adversarial attacks where the explanation produced is appreciably different while the meaning and structure of the complex model's output remains similar. This prior work has focused on the existence of these weaknesses but not on their magnitude. Here we explore using an alternate search method with the goal of finding minimum viable perturbations, the fewest perturbations necessary to achieve a fixed similarity value between the original and altered text's explanation. Intuitively, a method that requires fewer perturbations to expose a given level of instability is inferior to one which requires more. This nuance allows for superior comparisons of the stability of explainability methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。