arXiv:2503.06276cs.CV2025-03被引 4

首次揭示KAN模型间对抗迁移性差的根源,并提出有效攻击方法AdvKAN。

Exploring Adversarial Transferability between Kolmogorov-arnold Networks

  • 设计突破性防御代理模型,缓解对KAN特定结构的过拟合
  • 引入全局-局部交互机制,平滑损失曲面提升攻击迁移性
  • 在多个数据集上验证了攻击有效性,暴露KAN模型安全漏洞

Kolmogorov-Arnold Networks (KANs) 作为一种新兴模型范式,已在多个领域产生重要影响。然而,其对抗鲁棒性尚未得到充分研究,尤其是在不同KAN架构间的迁移性方面。本文分析发现,由于对KAN特定基函数的过拟合,导致其在不同KAN间具有较差的对抗迁移性。为此,我们提出首个针对KAN的迁移攻击方法AdvKAN,包含两个核心组件:1)突破性防御代理模型(BDSM),采用突破性防御训练策略减轻对特定结构的过拟合;2)全局-局部交互(GLI)技术,促进层级间对抗梯度的充分交互,进一步平滑KAN的损失表面。二者协同提升不同KAN间的攻击迁移能力。大量实验在多种KAN架构与数据集上验证了AdvKAN的有效性,展现出显著更强的攻击能力,并深入揭示了KAN的脆弱性。代码将在接受后公开。

原文摘要 · Abstract (English)

Kolmogorov-Arnold Networks (KANs) have emerged as a transformative model paradigm, significantly impacting various fields. However, their adversarial robustness remains less underexplored, especially across different KAN architectures. To explore this critical safety issue, we conduct an analysis and find that due to overfitting to the specific basis functions of KANs, they possess poor adversarial transferability among different KANs. To tackle this challenge, we propose AdvKAN, the first transfer attack method for KANs. AdvKAN integrates two key components: 1) a Breakthrough-Defense Surrogate Model (BDSM), which employs a breakthrough-defense training strategy to mitigate overfitting to the specific structures of KANs. 2) a Global-Local Interaction (GLI) technique, which promotes sufficient interaction between adversarial gradients of hierarchical levels, further smoothing out loss surfaces of KANs. Both of them work together to enhance the strength of transfer attack among different KANs. Extensive experimental results on various KANs and datasets demonstrate the effectiveness of AdvKAN, which possesses notably superior attack capabilities and deeply reveals the vulnerabilities of KANs. Code will be released upon acceptance.

对抗攻击KAN模型安全迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。