输入维度越高,越容易生成对抗样本且目标攻击难度更低。
The Role of Input Dimensionality in the Emergence and Targeted Control of Adversarial Examples

- 通过实证分析高维几何对对抗样本的影响。
- 维度越高,对抗样本越易构造,目标攻击与非目标攻击差距缩小。
- 适合研究模型安全性和对抗防御的学者参考。
多项理论研究尝试通过高维几何特性解释深度神经网络的对抗脆弱性,但这些理论假设很少得到实证检验,系统性证据仍有限。本文系统研究了输入维度在对抗样本生成与目标控制中的作用。首先分析现有基于测度集中理论的框架,发现真实图像类别表现出强局部化特征,超出理论假设。随后在涵盖多种层级图像数据集和神经网络架构的广泛实验中,结果一致显示:随着输入维度增加,对抗样本更易生成。我们进一步探究维度对目标攻击难度的影响,提出理论论证表明高维几何下,指定目标标签仅需额外少量扰动。实验验证该观点,显示目标与非目标扰动差距小,且随维度增加进一步缩小。综合来看,高输入维度是导致对抗样本出现及目标控制的关键因素,但其根源究竟是高维几何与数据分布的相互作用,还是深层网络架构特性,仍是未解之谜。
原文摘要 · Abstract (English)
Several theoretical works have tried to explain the adversarial vulnerability of deep neural networks through properties of high-dimensional geometry. However, the assumptions underlying these works are rarely examined empirically, and systematic evidence remains limited. In this work, we present a systematic study of the role of input dimensionality in both the emergence and the targeted control of adversarial examples. We first analyse the scope and limitations of existing theoretical frameworks based on concentration of measure, showing that real image classes exhibit strong empirical localization, beyond what such theories typically assume. We then conduct an extensive empirical evaluation across hierarchical image datasets spanning a wide range of input dimensionalities and diverse neural architectures. Our results consistently show that adversarial examples become easier to construct as dimensionality increases. We also investigate how input dimensionality affects the additional difficulty of crafting targeted adversarial examples. In particular, we provide theoretical arguments showing that high-dimensional geometry implies that enforcing a specific target label entails only a limited additional distortion compared to untargeted attacks. We corroborate this insight through extensive experiments, demonstrating that the gap between targeted and untargeted perturbations remains small and further narrows as input dimensionality increases. While, taken together, our findings establish high input dimensionality as a fundamental factor underlying the emergence and targeted control of adversarial examples, whether this phenomenon primarily arises from the interplay between high-dimensional geometry and data distributions or from the architectural properties of deep neural networks remains an open question.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。