| 研究生: |
曾士峰 Zeng, Shih-Feng |
|---|---|
| 論文名稱: |
基於分類器分析探索對抗式樣本與主動式學習關係 Toward Evaluating Classifiers for Exploring Connection Between Active Learning and Adversarial Examples |
| 指導教授: |
林英超
Lin, Ing-Chao |
| 學位類別: |
碩士 Master |
| 系所名稱: |
電機資訊學院 - 資訊工程學系 Department of Computer Science and Information Engineering |
| 論文出版年: | 2021 |
| 畢業學年度: | 109 |
| 語文別: | 英文 |
| 論文頁數: | 30 |
| 中文關鍵詞: | 機器學習 、主動式學習 、對抗樣本 |
| 外文關鍵詞: | Machine Learning, Adversarial Example, Active Learning |
| 相關次數: | 點閱:190 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
機器學習研究人員早已發現一現象: 當我們對模型進行訓練時,密集採樣鄰近決策邊界的樣本做訓練,能使得整體訓練過程更有效率且獲得更好的成果。而另一發現為:即便是不同的模型使用不同的訓練集訓練,在相似的應用下,模型間會有類似的決策邊界。當這些觀察早在機器學習安全領域被廣泛使用時,卻還未有理論分析證明此現象的正確性。在本篇文章中,我們會探索主動式學習與對抗樣本之間的關係。透過分析性質類似的分類方法像是 k 相近鄰或者是核回歸。我們在此證明透過對抗式樣本蒐集決策邊界附近之樣本,能使得我們主動式學習更加有效率,並且獲得更好的訓練成果。於此我們也透過實驗驗證對抗式樣本除了讓機器辨識錯誤外,在 k相近鄰、核回歸與神經網路上透過我們改良後的對抗式主動學習方法也能被用來提升訓練結果。除此之外,我們在此也考慮主動式學習中如何挑選樣本做訓練,並分析卷積網路在不同選擇樣本方法下對訓練過程與結果分別帶來怎樣的衝擊,我們在此也提供相關的實驗證明。有了這樣的理論分析與實驗證明後,日後能夠讓研究者透過對抗式樣本發展出更高效的主動式學習演算法。
Machine learning researchers have long noticed the phenomenon that the model training process will be more effective and efficient when the training samples are densely sampled around the underlying decision boundary. Another observation is that machine learning models trained under different datasets closely share decision boundaries, especially for those models for similar purposes. While these observations have already been widely applied in machine learning security techniques, it lacks theoretical analyses of the correctness of these observations. In this work, we will look into this problem by investigating the connections between active learning and adversarial examples. Through analyzing common classifiers including k-NN classifiers and kernel methods, we establish a theoretical foundation for these observations. Our theoretical proofs provide support to more efficient active learning methods with the help of adversarial examples, contrary to previous work where adversarial examples are often used as destructive solutions. Moreover, we also consider different sample selection strategies in active learning. We show the impact of sample selection strategies on a convolution neural network during the training phase. Experimental results show that the established theoretical foundation will guide better new adversarial example guided active learning strategies.
[1] G. Biau and L. Devroye. Lectures on the Nearest Neighbor Method. Springer Series in the Data Sciences. Springer International Publishing, 2015.
[2] Battista Biggio and Fabio Roli. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84:317–331, 2018.
[3] Bastian Bohn, Michael Griebel, and Christian Rieger. A representer theorem for deep kernel learning. Journal of Machine Learning Research, 20(64):1–32, 2019.
[4] Nicholas Carlini and David Wagner. Towards evaluating the robustness of neural networks. In Security and Privacy (S&P), 2017 IEEE Symposium on, pages 39–57, 2017.
[5] Nicholas Carlini and David Wagner. Towards evaluating the robustness of neural networks, 2017.
[6] Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Song-bai Yan. Exploring connections between active learning and model extraction. In 29th USENIX Security Symposium (USENIX Security 20), pages 1309–1326. USENIX Association, August 2020.
[7] Kamalika Chaudhuri and Sanjoy Dasgupta. Rates of convergence for nearest neighbor classification. In Proceedings of the 27th International Conference on Neural Information Processing Systems Volume 2, NIPS'14, page 3437–3445, Cambridge, MA,USA, 2014. MIT Press.
[8] G.H. Chen and D. Shah. Explaining the Success of Nearest Neighbor Methods in Prediction. Foundations and Trends in Machine Learning Series. Now Publishers, 2018.
[9] David A. Cohn, Zoubin Ghahramani, and Michael I. Jordan. Active learning with statistical models. J. Artif. Int. Res., 4(1):129–145, 1996.
[10] Alexis Conneau, Holger Schwenk, Loïc Barrault, and Yann LeCun. Very deep convolutional networks for natural language processing. CoRR, abs/1606.01781, 2016.
[11] Dheeru Dua and Casey Graff. UCI machine learning repository, 2017.
[12] Melanie Ducoffe and Frederic Precioso. Adversarial active learning for deep networks:a margin based approach. arXiv preprint arXiv:1802.09841, 2018.
[13] Mengyang Feng, Huchuan Lu, and Errui Ding. Attentive feedback network for boundaryaware salient object detection. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR), June 2019.
[14] Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014.
[15] Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot. High accuracy and high fidelity extraction of neural networks. In 29th USENIX Security Symposium (USENIX Security 20), pages 1345–1362. USENIX Association, August 2020.
[16] Yujie Ji, Xinyang Zhang, Shouling Ji, Xiapu Luo, and Ting Wang. Modelreuse attacks on deep learning systems. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS ’18, pages 349–363, 2018.
[17] Jason Ku, Alex D. Pon, and Steven L. Waslander. Monocular 3d object detection leveraging accurate proposals and shape reconstruction. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR), June 2019.
[18] Kibok Lee, Kimin Lee, Kyle Min, Yuting Zhang, Jinwoo Shin, and Honglak Lee. Hierarchical novelty detection for visual object recognition. In The IEEE Conference on Computer Vision and Pattern Recognition (CVPR), June 2018.
[19] SIYUAN MA and Mikhail Belkin. Diving into the shallows: a computational perspective on largescale shallow learning. In I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett, editors, Advances in Neural Information Processing Systems 30, pages 3778–3787. Curran Associates, Inc., 2017.
[20] Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks. ICLR,2018.
[21] Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks, 2019.
[22] SeyedMohsen MoosaviDezfooli, Alhussein Fawzi, and Pascal Frossard. Deepfool: a simple and accurate method to fool deep neural networks, 2016.
[23] Nicolas Papernot, Fartash Faghri, Nicholas Carlini, Ian Goodfellow, Reuben Fein-man, Alexey Kurakin, Cihang Xie, Yash Sharma, Tom Brown, Aurko Roy, Alexander Matyasko, Vahid Behzadan, Karen Hambardzumyan, Zhishuai Zhang, YiLin Juang, Zhi Li, Ryan Sheatsley, Abhibhav Garg, Jonathan Uesato, Willi Gierke, Yinpeng Dong, David Berthelot, Paul Hendricks, Jonas Rauber, and Rujun Long. Technical report on the cleverhans v2.1.0 adversarial examples library. arXiv preprint arXiv:1610.00768,2018.
[24] Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. Practical blackbox attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS '17, page 506–519, New York, NY, USA, 2017. Association for Computing Machinery.
[25] Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami. The limitations of deep learning in adversarial settings. In Security and Privacy (EuroS&P), 2016 IEEE European Symposium on, pages 372–387, Saarbrucken, 2016. IEEE.
[26] Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. Distillation as a defense to adversarial perturbations against deep neural networks, 2016.
[27] Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow. Transferability in machine learning: from phenomena to blackbox attacks using adversarial samples. volume abs/1605.07277, 2016.
[28] Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow. Transferability in machine learning: from phenomena to blackbox attacks using adversarial samples. CoRR, abs/1605.07277, 2016.
[29] Nicolas Papernot, Patrick D. McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. Practical blackbox attacks against machine learning. In AsiaCCS, 2017.
[30] Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami. The limitations of deep learning in adversarial settings. CoRR, abs/1511.07528, 2015.
[31] F. Pedregosa, G. Varoquaux, A. Gramfort, V. Michel, B. Thirion, O. Grisel, M. Blondel, P. Prettenhofer, R. Weiss, V. Dubourg, J. Vanderplas, A. Passos, D. Cournapeau, M. Brucher, M. Perrot, and E. Duchesnay. Scikitlearn: Machine learning in Python. Journal of Machine Learning Research, 12:2825–2830, 2011.
[32] Tegjyot Singh Sethi and Mehmed Kantardzic. Data driven exploratory attacks on black box classifiers in adversarial domains. Neurocomput., 289(C):129–143, 2018.
[33] Burr Settles and Mark Craven. An analysis of active learning strategies for sequencelabeling tasks. In Proceedings of the Conference on Empirical Methods in Natural Language Processing, EMNLP ’08, pages 1070–1079, 2008.
[34] Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter. Accessorize to a crime: Real and stealthy attacks on stateoftheart face recognition. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 1528–1540. ACM, 2016.
[35] S. M. Silva and C. R. Jung. License plate detection and recognition in unconstrained scenarios. In 2018 European Conference on Computer Vision (ECCV), pages 580–596, Sep 2018.
[36] Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks. In arXiv preprint arXiv:1312.6199, 2013.
[37] Peter Teufl, Udo Payer, and Guenter Lackner. From nlp (natural language processing) to mlp (machine language processing). In Igor Kotenko and Victor Skormin, editors, Computer Network Security, pages 256–269, Berlin, Heidelberg, 2010. Springer Berlin Heidelberg.
[38] Simon Tong and Daphne Koller. Support vector machine active learning with applications to text classification. J. Mach. Learn. Res., 2:45–66, 2002.
[39] Cihang Xie, Mingxing Tan, Boqing Gong, Jiang Wang, Alan Yuille, and Quoc V. Le. Adversarial examples improve image recognition, 2020.
[40] YaoYuan Yang, Cyrus Rashtchian, Yizhen Wang, and Kamalika Chaudhuri. Robustness for nonparametric classification: A generic attack and defense, 2019.
[41] Honggang Yu, Kaichen Yang, Teng Zhang, YunYun Tsai, TsungYi Ho, and Yier Jin. Cloudleak: Largescale deep learning models stealing through adversarial examples. In Proceedings of Network and Distributed Systems Security Symposium (NDSS), 2020.
[42] Honggang Yu, Kaichen Yang, Teng Zhang, YunYun Tsai, TsungYi Ho, and Yier Jin. Cloudleak: Largescale deep learning models stealing through adversarial examples. In NDSS, 2020.