提出可证明鲁棒的多标签分类防御框架,对抗物理攻击贴纸
PatchDEMUX: A Certifiably Robust Framework for Multi-label Classifiers Against Adversarial Patches
- 将多标签任务拆解为独立二分类问题,实现可证明鲁棒性
- 在MS-COCO和PASCAL VOC上保持高干净准确率的同时实现非平凡鲁棒性
- 适用于受限单贴纸攻击场景,提供更紧的鲁棒性边界
深度学习显著提升了计算机视觉性能,但对对抗性贴纸攻击仍脆弱。这类攻击具有物理可实现性,亟需可证明的防御机制。尽管单标签分类已有成功案例,多标签分类仍缺乏有效方法。本文提出PatchDEMUX,一种可证明鲁棒的多标签分类防御框架。该方法将多标签任务转化为一系列独立的二分类问题,可扩展任意现有单标签可证明防御。在攻击者仅使用一个贴纸的场景下,额外引入认证流程以获得更紧的鲁棒性边界。以当前最先进(SOTA)的单标签防御PatchCleanser为基础,实验证明PatchDEMUX在MS-COCO和PASCAL VOC数据集上实现了非平凡的鲁棒性,同时保持了高干净准确率。
原文摘要 · Abstract (English)
Deep learning techniques have enabled vast improvements in computer vision technologies. Nevertheless, these models are vulnerable to adversarial patch attacks which catastrophically impair performance. The physically realizable nature of these attacks calls for certifiable defenses, which feature provable guarantees on robustness. While certifiable defenses have been successfully applied to single-label classification, limited work has been done for multi-label classification. In this work, we present PatchDEMUX, a certifiably robust framework for multi-label classifiers against adversarial patches. Our approach is a generalizable method which can extend any existing certifiable defense for single-label classification; this is done by considering the multi-label classification task as a series of isolated binary classification problems to provably guarantee robustness. Furthermore, in the scenario where an attacker is limited to a single patch we propose an additional certification procedure that can provide tighter robustness bounds. Using the current state-of-the-art (SOTA) single-label certifiable defense PatchCleanser as a backbone, we find that PatchDEMUX can achieve non-trivial robustness on the MS-COCO and PASCAL VOC datasets while maintaining high clean performance
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。