arrow
返回

Recursive reasoning-based training-time adversarial machine learning

delete2023-02-01
delete2
PRE
AI
Y
Yizhou Chen
Z
Zhongxiang Dai
余海斌 封面图
余海斌 (Haibin Yu)
B
Bryan Kian Hsiang Low *
T
Teck‐Hua Ho
DOI:10.1016/j.artint.2022.103837delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The training process of a machine learning (ML) model may be subject to adversarial attacks from an attacker who attempts to undermine the test performance of the ML model by perturbing the training minibatches, and thus needs to be protected by a defender. Such a problem setting is referred to as training-time adversarial ML. We formulate it as a two-player game and propose a principled Recursive Reasoning-based TrainingTime adversarial ML (R2T2) framework to model this game. R2T2 models the reasoning process between the attacker and the defender and captures their bounded reasoning capabilities (due to bounded computational resources) through the recursive reasoning formalism. In particular, we associate a deeper level of recursive reasoning with the use of a higher-order gradient to derive the attack (defense) strategy, which naturally improves its performance while requiring greater computational resources. Interestingly, our R2T2 framework encompasses a variety of existing adversarial ML methods which correspond to attackers (defenders) with different recursive reasoning capabilities. We show how an R2T2 attacker (defender) can utilize our proposed nested projected gradient descentbased method to approximate the optimal attack (defense) strategy at an arbitrary level of reasoning. R2T2 can empirically achieve state-of-the-art attack and defense performances on benchmark image datasets.
Keyword:
Recursive reasoning
Adversarial machine learning
Game theory

期刊

Artificial Intelligence Review 封面图
Artificial Intelligence Review
IF:
13.9
论文数:
6.1K
被引数:
1.9W

机构

N
National University of Singapore
学者数:
7.5W
论文数: 6.5W
被引数: 11.4W