提出新方法让变分自编码器在对抗攻击下有可认证的鲁棒性。
Support is All You Need for Certified VAE Training
- 通过约束潜在空间支持集来控制最坏情况误差。
- 在多数据集和多种攻击强度下,优于现有最先进方法。
- 适合对安全性要求高的视觉与无线应用。
变分自编码器(VAEs)在安全关键场景中的应用日益广泛。在这些场景中,需要对对抗攻击下的性能提供可认证的概率保障。本文提出一种新方法CIVET,用于对VAEs进行可认证训练。其核心思想是:可通过限制潜在层上精心选择的支持集上的误差,来界定向量自编码器的最大误差。我们从数学上证明了这一观点,并提出了基于该思想的新训练算法。在涵盖无线与视觉应用领域的多个数据集、不同网络架构及扰动幅度的广泛评估中,本方法在保持良好标准性能的同时,显著提升了鲁棒性保证,优于当前最先进的方法。
原文摘要 · Abstract (English)
Variational Autoencoders (VAEs) have become increasingly popular and deployed in safety-critical applications. In such applications, we want to give certified probabilistic guarantees on performance under adversarial attacks. We propose a novel method, CIVET, for certified training of VAEs. CIVET depends on the key insight that we can bound worst-case VAE error by bounding the error on carefully chosen support sets at the latent layer. We show this point mathematically and present a novel training algorithm utilizing this insight. We show in an extensive evaluation across different datasets (in both the wireless and vision application areas), architectures, and perturbation magnitudes that our method outperforms SOTA methods achieving good standard performance with strong robustness guarantees.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。