arXiv:2506.09640stat.MLcs.LG2025-06中稿 · as an oral present…被引 2

提出针对贝叶斯预测模型的新型逃避攻击方法。

Evasion Attacks Against Bayesian Predictive Models

  • 基于梯度设计优化攻击,可扰动点预测与后验分布
  • 在多种计算环境下验证攻击有效性,效果显著
  • 为贝叶斯模型安全研究提供新视角,适合安全方向研究者

机器学习系统在对抗攻击下的行为受到越来越多关注。然而,现有研究多聚焦于经典设定中预测模型对逃避或投毒攻击的脆弱性,而贝叶斯预测模型的抗攻击能力仍缺乏深入探讨。本文提出一种通用的最优逃避攻击设计方法,针对两类对抗目标:扰动特定点预测结果、改变整个后验预测分布。对于这两种场景,我们提出新的基于梯度的攻击方法,并在多种计算设置下研究其实施方式与性质。

原文摘要 · Abstract (English)

There is an increasing interest in analyzing the behavior of machine learning systems against adversarial attacks. However, most of the research in adversarial machine learning has focused on studying weaknesses against evasion or poisoning attacks to predictive models in classical setups, with the susceptibility of Bayesian predictive models to attacks remaining underexplored. This paper introduces a general methodology for designing optimal evasion attacks against such models. We investigate two adversarial objectives: perturbing specific point predictions and altering the entire posterior predictive distribution. For both scenarios, we propose novel gradient-based attacks and study their implementation and properties in various computational setups.

贝叶斯模型对抗攻击逃避攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。