返回
Adversarial parameter defense by multi-step risk minimization
DOI:10.1016/j.neunet.2021.08.022.png)
摘要
En 中文
Previous studies demonstrate DNNs' vulnerability to adversarial examples and adversarial training can establish a defense to adversarial examples. In addition, recent studies show that deep neural networks also exhibit vulnerability to parameter corruptions. The vulnerability of model parameters is of crucial value to the study of model robustness and generalization. In this work, we introduce the concept of parameter corruption and propose to leverage the loss change indicators for measuring the flatness of the loss basin and the parameter robustness of neural network parameters. On such basis, we analyze parameter corruptions and propose the multi-step adversarial corruption algorithm. To enhance neural networks, we propose the adversarial parameter defense algorithm that minimizes the average risk of multiple adversarial parameter corruptions. Experimental results show that the proposed algorithm can improve both the parameter robustness and accuracy of neural networks. (C) 2021 Elsevier Ltd. All rights reserved.
Keyword:
Vulnerability of deep neural networks
Parameter corruption
Adversarial parameter defense
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
6.3
论文数:
8.2K
被引数:
3.0W
机构
引用论文
BadNets: Evaluating Backdooring Attacks on Deep Neural NetworksBadNets: 评估对深度神经网络的后台攻击
IEEE ACCESS
IF3.6
A Backdoor Attack Against LSTM-Based Text Classification Systems一种针对基于LSTM的文本分类系统的后门攻击
IEEE ACCESS
IF3.6
Developing Wind and/or Solar Powered Crop Irrigation Systems for the Great Plains为大平原开发风能和/或太阳能作物灌溉系统
N-6 and N-3 Fatty Acid Cholesteryl Esters in Relation to Fatal CHD in a Dutch Adult Population: A Nested Case-Control Study and Meta-Analysis
PLoS ONE
IF0

