vix.ing · top · new · best · stats · spec

Generalizable Adversarial Attacks with Latent Variable Perturbation\n Modelling

2019/05/26 by Avishek Joey Bose, Bose, Avishek Joey, Andre Cianflone +3
Computer Science · Medicine · #Adversarial Robustness in Machine Learning #Cardiac Arrest and Resuscitation #Explainable Artificial Intelligence (XAI)

paper · pdf · doi:10.48550/arxiv.1905.10864

Abstract

Adversarial attacks on deep neural networks traditionally rely on a\nconstrained optimization paradigm, where an optimization procedure is used to\nobtain a single adversarial perturbation for a given input example. In this\nwork we frame the problem as learning a distribution of adversarial\nperturbations, enabling us to generate diverse adversarial distributions given\nan unperturbed input. We show that this framework is domain-agnostic in that\nthe same framework can be employed to attack different input domains with\nminimal modification. Across three diverse domains---images, text, and\ngraphs---our approach generates whitebox attacks with success rates that are\ncompetitive with or superior to existing approaches, with a new\nstate-of-the-art achieved in the graph domain. Finally, we demonstrate that our\nframework can efficiently generate a diverse set of attacks for a single given\ninput, and is even capable of attacking \unseen test instances in a\nzero-shot manner, exhibiting attack generalization.\n

Citations

Related