针对复数神经网络的相位扰动攻击,揭示其对相位变化的高度敏感性。
Perturbing the Phase: Analyzing Adversarial Robustness of Complex-Valued Neural Networks
- 设计专攻复数输入相位信息的相位攻击方法。
- 相位攻击使模型性能下降幅度超过同等强度的传统攻击。
- 复数神经网络在部分场景下比实数网络更鲁棒,但对相位变化极敏感。
复数神经网络(CVNNs)在各类应用中日益流行。为确保其实际使用安全,分析其对异常值的鲁棒性至关重要。一种常用方法是研究深度神经网络在对抗攻击下的行为,这类攻击可视为最坏情况下的最小扰动。本文设计了针对复数输入相位信息的相位攻击,并推导出常用的对抗攻击在复数域的版本。实验表明,在某些场景下CVNNs比实数神经网络(RVNNs)更具鲁棒性,但两者均对相位变化高度敏感;相位攻击导致的性能下降程度超过同等强度的常规攻击(可同时扰动相位和模值),凸显了相位信息的关键作用。
原文摘要 · Abstract (English)
Complex-valued neural networks (CVNNs) are rising in popularity for all kinds of applications. To safely use CVNNs in practice, analyzing their robustness against outliers is crucial. One well known technique to understand the behavior of deep neural networks is to investigate their behavior under adversarial attacks, which can be seen as worst case minimal perturbations. We design Phase Attacks, a kind of attack specifically targeting the phase information of complex-valued inputs. Additionally, we derive complex-valued versions of commonly used adversarial attacks. We show that in some scenarios CVNNs are more robust than RVNNs and that both are very susceptible to phase changes with the Phase Attacks decreasing the model performance more, than equally strong regular attacks, which can attack both phase and magnitude.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。