系统梳理视觉模型防御方法,助你快速掌握对抗攻击应对策略。
A Survey of Adversarial Defenses in Vision-based Systems: Categorization, Methods and Challenges
- 按防御机制分类,梳理图像分类与目标检测中的防御方法
- 总结各类防御在典型攻击和数据集上的表现效果
- 适合研究者与工程师快速了解防御技术全貌
对抗攻击已成为机器学习模型可信部署的重大挑战,尤其在计算机视觉应用中。这些攻击具有不同程度的破坏力,可采用白盒或黑盒方式实施,甚至通过操控物理世界引发目标神经网络的对抗行为。文献中已有多种针对不同类型攻击的防御方法,各有优劣。本文对对抗防御技术进行全面系统化整理,聚焦图像分类与目标检测两大核心任务。综述当前最先进的防御手段,并进行分类以便对比分析。同时,在整体机器学习流程中绘制防御类别示意图,提升理解与基准评估清晰度。进一步将各类防御映射到对应的攻击类型与测试数据集,为研究人员与实践者提供实用指导。本研究有助于厘清现有防御措施应对对抗威胁的能力与局限,推动该领域研究向构建可信赖人工智能系统的方向发展。
原文摘要 · Abstract (English)
Adversarial attacks have emerged as a major challenge to the trustworthy deployment of machine learning models, particularly in computer vision applications. These attacks have a varied level of potency and can be implemented in both white box and black box approaches. Practical attacks include methods to manipulate the physical world and enforce adversarial behaviour by the corresponding target neural network models. Multiple different approaches to mitigate different kinds of such attacks are available in the literature, each with their own advantages and limitations. In this survey, we present a comprehensive systematization of knowledge on adversarial defenses, focusing on two key computer vision tasks: image classification and object detection. We review the state-of-the-art adversarial defense techniques and categorize them for easier comparison. In addition, we provide a schematic representation of these categories within the context of the overall machine learning pipeline, facilitating clearer understanding and benchmarking of defenses. Furthermore, we map these defenses to the types of adversarial attacks and datasets where they are most effective, offering practical insights for researchers and practitioners. This study is necessary for understanding the scope of how the available defenses are able to address the adversarial threats, and their shortcomings as well, which is necessary for driving the research in this area in the most appropriate direction, with the aim of building trustworthy AI systems for regular practical use-cases.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。