返回
Adversarial vulnerability bounds for Gaussian process classification
DOI:10.1007/s10994-022-06224-6.png)
摘要
En 中文
Protecting ML classifiers from adversarial examples is crucial. We propose that the main threat is an attacker perturbing a confidently classified input to produce a confident misclassification. We consider in this paper the L-0 attack in which a small number of inputs can be perturbed by the attacker at test-time. To quantify the risk of this form of attack we have devised a formal guarantee in the form of an adversarial bound (AB) for a binary, Gaussian process classifier using the EQ kernel. This bound holds for the entire input domain, bounding the potential of any future adversarial attack to cause a confident misclassification. We explore how to extend to other kernels and investigate how to maximise the bound by altering the classifier (for example by using sparse approximations). We test the bound using a variety of datasets and show that it produces relevant and practical bounds for many of them.
Keyword:
Machine learning
Gaussian process
Adversarial example
Bound
Classification
Gaussian process classification
期刊
IF:
2.9
论文数:
2.7K
被引数:
3.4W
机构
引用论文
Hyposensitization with Dermatophagoides pteronyssinus Antigen: Trial in Asthma Induced by House Dust
BMJ
IF0
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究
The Early Cambrian Mianyang-Changning Intracratonic Sag and Its Control on Petroleum Accumulation in the Sichuan Basin, China
Geofluids
IF0
Gradient-based learning applied to document recognition基于梯度的学习在文档识别中的应用
PROCEEDINGS OF THE IEEE
IF25.9

