BriefGPT.xyz
Mar, 2019
利用范数界限对抗鲁棒性引起的过度不变性
Exploiting Excessive Invariance caused by Norm-Bounded Adversarial Robustness
HTML
PDF
Jörn-Henrik Jacobsen, Jens Behrmannn, Nicholas Carlini, Florian Tramèr, Nicolas Papernot
TL;DR
本文演示了对扰动型对抗样本的稳健性不仅不足以实现普遍的稳健性,而且它还会增加模型对于不变性型对抗样本的脆弱性,并呼吁一组精确的定义来对学习中的这些限制进行分类和解决。
Abstract
adversarial examples
are malicious inputs crafted to cause a model to misclassify them. Their most common instantiation, "
perturbation-based
"
adv
→