测试柯尔莫哥洛夫-阿诺德网络在强对抗攻击下的鲁棒性,找最优防御方案。
KAN-Robust-Bench: A Benchmark for Evaluating the Robustness of Kolmogorov-Arnold Networks

- 基于随机平滑与区间传播理论构建评估框架
- 在FGSM、PGD、C&W攻击下验证多模型的鲁棒性表现
- 提供$oldsymbol{ ext{l}_2}$认证鲁棒性数据,适合安全研究者参考
尽管机器学习模型在多个领域表现出色,但在面对对抗性威胁时仍存在显著漏洞。其中最突出的是规避攻击:攻击者生成人眼难以察觉的扰动样本,使模型高置信度误判。本文系统评估多种柯尔莫哥洛夫-阿诺德网络(KAN)架构在强规避攻击下的认证鲁棒性与实证鲁棒性。首先,建立随机平滑与区间边界传播的数学基础,并报告经随机平滑处理后的模型在$oldsymbol{ ext{l}_2}$范数下的认证鲁棒性。随后,在FGSM、PGD和C&W攻击下,系统评估不同防御与未防御的KAN模型性能,以识别最优防御策略与网络结构。
原文摘要 · Abstract (English)
While machine learning models have demonstrated strong performance in many domains, these models have shown profound vulnerabilities when they are exposed to adversarial threats. While adversarial attacks fall into various categories, the most prominent category in research studies is evasion. In evasion attacks, the adversary generates perturbed versions of samples, which might not be observable by human eyes. These samples generally fool the machine learning models with high confidence. This phenomenon poses a significant security violation against machine learning models. In this paper, we investigate the certified and empirical robustness of various Kolmogorov-Arnold network architectures against strong evasion attacks. At first, we provide the mathematical foundations for randomized smoothing and interval bound propagation, and report the $\ell_2$-certified robustness of the models under randomized smoothing. After that, we systematically evaluate the robustness of various defended and undefended KAN models under FGSM, PGD, and C&W attacks in order to find out the optimal defense strategies and architectures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。