arXiv:2605.12792cs.LG2026-05

分析神经切线泛化攻击现状,揭示其漏洞并提出改进方向。

SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions

论文配图:SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions
图 1 · 摘自论文原文
  • 分类梳理神经网络攻击方法,定位NTGA为首个黑盒干净标签泛化攻击。
  • 实验证明NTGA易受对抗训练和图像变换影响,线性可分性加剧其脆弱性。
  • 指出当前攻击已超越NTGA,适合安全研究者与防御算法开发者参考。

深度神经网络训练中日益严重的未经授权数据使用问题引发关注。干净标签泛化攻击作为一种数据投毒攻击,被提出用于应对该问题。神经切线泛化攻击(NTGA)是首个在黑盒设置下知名的干净标签泛化攻击,为数据保护提供了新思路。本文首次系统分析了NTGA的最新进展:首先对各类针对DNN的攻击进行分类与关联解析;其次构建黑盒攻击分类体系,证实NTGA是首个黑盒干净标签泛化攻击;通过自建实验复现并对比现有研究,发现NTGA易受对抗训练和图像变换影响,且其生成样本的线性可分性会增强其脆弱性。我们总结了NTGA的优缺点,并提出增强鲁棒性的改进建议。进一步实验表明,若干新提出的干净标签泛化攻击在数据保护效果上已优于NTGA。最后,本文揭示了该领域仍需深入研究,提出了未来研究方向。

原文摘要 · Abstract (English)

There is recently a serious issue that Deep Neural Networks (DNNs) training uses more and more unauthorized data. A clean-label generalization attack, one type of data poisoning attacks, has been suggested to address this issue. The Neural Tangent Generalization Attack (NTGA) is considered as the first well-known clean-label generalization attack under the black-box settings, which provided an unprecedented step in data protection approaches. In this paper, we conduct a comprehensive analysis on the state-of-the-art of NTGA; to the best of our knowledge, this is the first thorough analysis regarding NTGA. First, we provide a classification of attacks against DNNs with their explanations and relations to NTGA. Then, this paper presents a taxonomy of black-box attacks and demonstrate that the NTGA is the first clean-label generalization attack under the black-box setting. We further analyze the existing studies of NTGA and give a comprehensive comparisons of their findings by conducting our own experiments to verify these findings. Moreover, our extensive experiments show that NTGA is vulnerable to adversarial training and image transformations, and applying linear separability to NTGA-generated images makes them more susceptible to such vulnerablities. We present the pros and cons of NTGA and suggest ways to improve NTGA robustness based on our analysis. Our further experiments indicate that several recently proposed clean-label generalization attacks outperform NTGA on data protection. Finally, we unveil the necessity of further research with future research insights on NTGA.

安全攻防数据投毒神经网络黑盒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。