arXiv:2504.19000cs.LGeess.SP2025-04被引 4

发现迭代优化器易受对抗攻击,可通过训练提升鲁棒性。

Unveiling and Mitigating Adversarial Vulnerabilities in Iterative Optimizers

  • 将迭代优化器视为可训练模型,揭示其对抗脆弱性。
  • 对抗攻击能改变优化目标表面,引导求解至错误极小值。
  • 通过对抗训练和深度展开,显著提升优化器鲁棒性。

机器学习模型对精心设计但看似无害的扰动敏感,此类对抗样本被视为模型固有特性,常与黑箱操作及数据特征敏感性相关。本文研究非学习型决策规则,特别是迭代优化器的对抗敏感性。受深度展开技术启发,这类优化器被视作机器学习模型。我们发现,非学习型迭代优化器同样具有对抗敏感性,且攻击能有效改变优化目标的曲面,从而改变所寻求的极小值。随后,利用有限迭代优化器可被建模为机器学习模型的特性,通过对抗训练增强其鲁棒性。针对一类近端梯度优化器,我们严格证明了其学习过程如何影响对抗敏感性。数值实验验证了多种优化器的脆弱性,以及深度展开与对抗训练带来的鲁棒性提升。

原文摘要 · Abstract (English)

Machine learning (ML) models are often sensitive to carefully crafted yet seemingly unnoticeable perturbations. Such adversarial examples are considered to be a property of ML models, often associated with their black-box operation and sensitivity to features learned from data. This work examines the adversarial sensitivity of non-learned decision rules, and particularly of iterative optimizers. Our analysis is inspired by the recent developments in deep unfolding, which cast such optimizers as ML models. We show that non-learned iterative optimizers share the sensitivity to adversarial examples of ML models, and that attacking iterative optimizers effectively alters the optimization objective surface in a manner that modifies the minima sought. We then leverage the ability to cast iteration-limited optimizers as ML models to enhance robustness via adversarial training. For a class of proximal gradient optimizers, we rigorously prove how their learning affects adversarial sensitivity. We numerically back our findings, showing the vulnerability of various optimizers, as well as the robustness induced by unfolding and adversarial training.

优化器对抗攻击深度展开

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。