| 摘要: |
| 深度学习模型存在一定的安全隐患, 和这些模型关联的应用一旦发生安全事故, 很可能带来难以承受的后果. 为此, 需要对深度学习模型进行加固. 已有的加固方法包括针对对抗性噪声的对抗性训练方法、对抗噪声净化方法等. 对抗训练作为其中最常使用的方法具有较好的对抗攻击防御效果. 但是, 对抗训练后的模型容易出现鲁棒泛化不足的问题, 且会牺牲较多的原始精度. 基于此提出一种基于代理分布的对抗训练 (proxy-distribution-based adversarial training, PBAT)方法. 该方法利用概率模型捕获数据样本分布规律, 以生成能够协调原始精度和鲁棒性能的增强训练样本. 然后通过调整训练过程实现对模型的加固. 利用ResNet-20和GoogLeNet在2个典型的数据集CIFAR10和MNIST上开展实验, 并进一步在Faster R-CNN模型和PASCAL VOC数据集上针对目标检测任务开展实验. 实验结果表明, PBAT比其他4种典型的方法效果要好. |
| 关键词: 深度学习模型 模型加固 模型防御 对抗网络 |
| DOI:10.13328/j.cnki.jos.007548 |
| 分类号:TP183 |
| 基金项目:国家重点研发计划 (2023YFD2201805) |
|
| PBAT: Defense Reinforcement Method for Deep Learning Models Based on Proxy Distribution |
|
YANG Bo1,2, XIONG Qian1, XU Luo3
|
|
1.School of Information Science and Technology, Beijing Forestry University, Beijing 100083, China;2.Engineering Research Center for Forestry-oriented Intelligent Information Processing of National Forestry and Grassland
Administration (Beijing Forestry University), Beijing 100083, China;3.Information Science Academy, China Electronics Technology Group Co., Beijing 100040, China
|
| Abstract: |
| Deep learning models face some security risks, and security breaches in their applications can lead to severe consequences. Enhancing the security of deep learning models is therefore necessary. Existing reinforcement methods include adversarial training against adversarial noise, adversarial noise purification methods, and others. Among them, adversarial training is the most widely used method and provides effective defense against adversarial attacks. However, models trained with adversarial training often suffer from insufficient robust generalization and considerable loss of original accuracy. To address these issues, this study proposes a new adversarial training method called proxy-distribution-based adversarial training (PBAT). The proposed method employs a probabilistic model to capture the distribution patterns of data samples and generate enhanced training samples that balance original accuracy and robustness. The resilience of the model is further enhanced through an adjusted training process. Experiments are conducted using ResNet-20 and GoogLeNet on two benchmark datasets, CIFAR10 and MNIST. Furthermore, experiments are conducted on the Faster R-CNN model and the PASCAL VOC dataset for object detection tasks. The experimental results demonstrate that PBAT outperforms four representative methods. |
| Key words: deep learning model model reinforcement model defense adversarial network |