arXiv:2510.16443cs.LG2025-10

针对高能物理中的对抗攻击,提出双阶段鲁棒模型,准确率达80%。

Colliding with Adversaries at ECML-PKDD 2025 Model Robustness Competition 1st Prize Solution

  • 用自定义RDSA生成1500万对抗样本,增强训练数据多样性。
  • 设计共享权重特征嵌入+密集融合输出的结构,混合准确率80%。
  • 适合关注高能物理中模型抗干扰能力的研究者。

本文介绍在ECML-PKDD 2025高能物理发现中对抗鲁棒性挑战赛任务2的冠军解决方案。挑战目标是设计并训练一个基于人工神经网络的鲁棒模型,在干净数据和随机分布置换攻击(RDSA)生成的对抗数据上均实现高分类准确率。本方案包含两个阶段:第一阶段,基于自定义方法生成1500万条人工训练样本;第二阶段,引入一种鲁棒架构,包含(i)具有同类型特征共享权重的特征嵌入模块,以及(ii)负责最终预测的密集融合尾部。在对抗数据集上训练该架构,混合准确率达到80%,比第二名高出两个百分点。

原文摘要 · Abstract (English)

This report presents the winning solution for Task 2 of Colliding with Adversaries: A Challenge on Robust Learning in High Energy Physics Discovery at ECML-PKDD 2025. The goal of the challenge was to design and train a robust ANN-based model capable of achieving high accuracy in a binary classification task on both clean and adversarial data generated with the Random Distribution Shuffle Attack (RDSA). Our solution consists of two components: a data generation phase and a robust model training phase. In the first phase, we produced 15 million artificial training samples using a custom methodology derived from Random Distribution Shuffle Attack (RDSA). In the second phase, we introduced a robust architecture comprising (i)a Feature Embedding Block with shared weights among features of the same type and (ii)a Dense Fusion Tail responsible for the final prediction. Training this architecture on our adversarial dataset achieved a mixed accuracy score of 80\%, exceeding the second-place solution by two percentage points.

对抗鲁棒性高能物理神经网络分类

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。