提升神经概率电路的抗攻击能力,关键在加固属性识别模块
Understanding and Improving Adversarial Robustness of Neural Probabilistic Circuits
- 通过类间融合机制增强模块输出组合的鲁棒性
- 实验证明新模型在对抗攻击下准确率显著优于现有模型
- 适合关注可解释性与安全性的机器学习研究者
神经概率电路(NPC)是一类概念瓶颈模型,由属性识别模型和概率电路组成,能生成可解释且性能优异的预测。然而,基于神经网络的属性识别模块仍是黑箱,易受细微扰动攻击,影响最终决策。本文理论分析表明,NPC的对抗鲁棒性仅取决于属性识别模块,与概率电路无关。为此提出RNPC,首个针对识别模块攻击的鲁棒型神经概率电路。RNPC引入类间融合机制,在推理时实现更稳健的模块输出整合。理论证明其对抗鲁棒性优于原NPC。图像分类任务的实验证明,RNPC在保持良性输入高精度的同时,显著提升对抗鲁棒性,优于现有概念瓶颈模型。
原文摘要 · Abstract (English)
Neural Probabilistic Circuits (NPCs), a new class of concept bottleneck models, comprise an attribute recognition model and a probabilistic circuit for reasoning. By integrating the outputs from these two modules, NPCs produce compositional and interpretable predictions. While offering enhanced interpretability and high performance on downstream tasks, the neural-network-based attribute recognition model remains a black box. This vulnerability allows adversarial attacks to manipulate attribute predictions by introducing carefully crafted subtle perturbations to input images, potentially compromising the final predictions. In this paper, we theoretically analyze the adversarial robustness of NPC and demonstrate that it only depends on the robustness of the attribute recognition model and is independent of the robustness of the probabilistic circuit. Moreover, we propose RNPC, the first robust neural probabilistic circuit against adversarial attacks on the recognition module. RNPC introduces a novel class-wise integration for inference, ensuring a robust combination of outputs from the two modules. Our theoretical analysis demonstrates that RNPC exhibits provably improved adversarial robustness compared to NPC. Empirical results on image classification tasks show that RNPC achieves superior adversarial robustness compared to existing concept bottleneck models while maintaining high accuracy on benign inputs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。