arXiv:2510.02707cs.CRcs.CV2025-10

通过压缩前后网络行为对比,实现无需预知攻击类型的实时检测

A Statistical Method for Attack-Agnostic Adversarial Attack Detection with Compressive Sensing Comparison

  • 用压缩与未压缩网络的输出差异构建对抗样本检测指标
  • 在多种攻击类型下检测准确率接近完美,误报率显著降低
  • 适合部署于对安全性要求高的实际系统,无需预先知晓攻击方式

对抗攻击对现代机器学习系统构成严重威胁。现有检测方法往往难以识别未见过的攻击,或对不同攻击类型检测精度不足。本文提出一种统计方法,在神经网络部署前建立检测基准,实现高效的实时对抗检测。通过比较压缩与未压缩神经网络对输入的响应行为,生成对抗存在性度量。该方法在多种前沿攻击上测试表现优异,实现了近乎完美的检测效果,同时大幅降低误报率,兼具可靠性与实用性,适用于真实场景。

原文摘要 · Abstract (English)

Adversarial attacks present a significant threat to modern machine learning systems. Yet, existing detection methods often lack the ability to detect unseen attacks or detect different attack types with a high level of accuracy. In this work, we propose a statistical approach that establishes a detection baseline before a neural network's deployment, enabling effective real-time adversarial detection. We generate a metric of adversarial presence by comparing the behavior of a compressed/uncompressed neural network pair. Our method has been tested against state-of-the-art techniques, and it achieves near-perfect detection across a wide range of attack types. Moreover, it significantly reduces false positives, making it both reliable and practical for real-world applications.

对抗检测统计方法压缩感知

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。