研究不同ℓₚ范数对对抗攻击的稀疏性和平滑性影响,发现1.3≤p≤1.5效果最佳。
Exploring Sparsity and Smoothness of Arbitrary $\ell_p$ Norms in Adversarial Attacks
- 通过新定义的稀疏度与平滑度指标,系统分析ℓₚ范数在[1,2]区间的影响。
- 实验表明ℓ₁和ℓ₂在多数情况下非最优,最优值集中在1.3至1.5之间。
- 适用于设计更隐蔽、更有效的对抗攻击,适合安全与模型鲁棒性研究者。
针对深度神经网络的对抗攻击通常在ℓₚ范数约束下构建,常见取值为p=1、p=2或p=∞,并可能根据需求引入稀疏性或平滑性正则化。这些选择往往缺乏对范数参数p如何影响对抗扰动的结构与感知特性的系统研究。本文研究了p∈[1,2]时ℓₚ范数约束下对抗攻击的稀疏性与平滑性。为实现定量分析,采用文献中的两种稀疏度度量,并提出三种平滑度度量,其中一种基于平滑操作,另一种基于一阶泰勒近似。在多个真实图像数据集及多样化模型架构(包括卷积与Transformer)上进行了全面实验。结果表明,ℓ₁与ℓ₂通常不是最优选择,最优p值依赖具体任务;在实验中,使用p∈[1.3,1.5]的ℓₚ范数可获得稀疏性与平滑性之间的最佳平衡。该发现强调了在设计与评估对抗攻击时,应基于原理选择范数。
原文摘要 · Abstract (English)
Adversarial attacks against deep neural networks are commonly constructed under $\ell_p$ norm constraints, most often using $p=1$, $p=2$ or $p=\infty$, and potentially regularized for specific demands such as sparsity or smoothness. These choices are typically made without a systematic investigation of how the norm parameter \( p \) influences the structural and perceptual properties of adversarial perturbations. In this work, we study how the choice of \( p \) affects sparsity and smoothness of adversarial attacks generated under \( \ell_p \) norm constraints for values of $p \in [1,2]$. To enable a quantitative analysis, we adopt two established sparsity measures from the literature and introduce three smoothness measures. In particular, we propose a general framework for deriving smoothness measures based on smoothing operations and additionally introduce a smoothness measure based on first-order Taylor approximations. Using these measures, we conduct a comprehensive empirical evaluation across multiple real-world image datasets and a diverse set of model architectures, including both convolutional and transformer-based networks. We show that the choice of $\ell_1$ or $\ell_2$ is suboptimal in most cases and the optimal $p$ value is dependent on the specific task. In our experiments, using $\ell_p$ norms with $p\in [1.3, 1.5]$ yields the best trade-off between sparse and smooth attacks. These findings highlight the importance of principled norm selection when designing and evaluating adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。