arXiv:2506.10888cs.LG2025-06中稿 · ECML 2025

提出新型攻击方法,破解随机集成分类器的防御机制

Lattice Climber Attack: Adversarial attacks for randomized mixtures of classifiers

  • 基于几何分析设计新攻击策略,兼顾有效性和最大性
  • 在二元线性设置下有理论保证,实测优于现有方法
  • 适合研究模型鲁棒性或对抗样本攻防的学者

有限混合分类器(即随机集成)被提出用于提升对抗攻击下的鲁棒性。然而,现有攻击方法并不适用于此类分类器。本文通过几何分析,系统讨论了攻击混合分类器的合理方式,并提出两个理想攻击特性:有效性与最大性。我们证明现有攻击无法同时满足这两项特性。为此,提出一种名为「晶格攀登攻击」的新方法,在二元线性设定下具有理论保证,并在合成与真实数据集上验证了其有效性。

原文摘要 · Abstract (English)

Finite mixtures of classifiers (a.k.a. randomized ensembles) have been proposed as a way to improve robustness against adversarial attacks. However, existing attacks have been shown to not suit this kind of classifier. In this paper, we discuss the problem of attacking a mixture in a principled way and introduce two desirable properties of attacks based on a geometrical analysis of the problem (effectiveness and maximality). We then show that existing attacks do not meet both of these properties. Finally, we introduce a new attack called {\em lattice climber attack} with theoretical guarantees in the binary linear setting, and demonstrate its performance by conducting experiments on synthetic and real datasets.

对抗攻击集成学习机器学习安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。