PBAT: 基于代理分布的深度学习模型防御加固方法
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP183

基金项目:

国家重点研发计划 (2023YFD2201805)


PBAT: Defense Reinforcement Method for Deep Learning Models Based on Proxy Distribution
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    深度学习模型存在一定的安全隐患, 和这些模型关联的应用一旦发生安全事故, 很可能带来难以承受的后果. 为此, 需要对深度学习模型进行加固. 已有的加固方法包括针对对抗性噪声的对抗性训练方法、对抗噪声净化方法等. 对抗训练作为其中最常使用的方法具有较好的对抗攻击防御效果. 但是, 对抗训练后的模型容易出现鲁棒泛化不足的问题, 且会牺牲较多的原始精度. 基于此提出一种基于代理分布的对抗训练 (proxy-distribution-based adversarial training, PBAT)方法. 该方法利用概率模型捕获数据样本分布规律, 以生成能够协调原始精度和鲁棒性能的增强训练样本. 然后通过调整训练过程实现对模型的加固. 利用ResNet-20和GoogLeNet在2个典型的数据集CIFAR10和MNIST上开展实验, 并进一步在Faster R-CNN模型和PASCAL VOC数据集上针对目标检测任务开展实验. 实验结果表明, PBAT比其他4种典型的方法效果要好.

    Abstract:

    Deep learning models face some security risks, and security breaches in their applications can lead to severe consequences. Enhancing the security of deep learning models is therefore necessary. Existing reinforcement methods include adversarial training against adversarial noise, adversarial noise purification methods, and others. Among them, adversarial training is the most widely used method and provides effective defense against adversarial attacks. However, models trained with adversarial training often suffer from insufficient robust generalization and considerable loss of original accuracy. To address these issues, this study proposes a new adversarial training method called proxy-distribution-based adversarial training (PBAT). The proposed method employs a probabilistic model to capture the distribution patterns of data samples and generate enhanced training samples that balance original accuracy and robustness. The resilience of the model is further enhanced through an adjusted training process. Experiments are conducted using ResNet-20 and GoogLeNet on two benchmark datasets, CIFAR10 and MNIST. Furthermore, experiments are conducted on the Faster R-CNN model and the PASCAL VOC dataset for object detection tasks. The experimental results demonstrate that PBAT outperforms four representative methods.

    参考文献
    相似文献
    引证文献
引用本文

杨波,熊倩,徐珞. PBAT: 基于代理分布的深度学习模型防御加固方法.软件学报,2026,37(7):2989-3012

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-09-06
  • 最后修改日期:2025-04-21
  • 录用日期:
  • 在线发布日期: 2026-04-29
  • 出版日期: 2026-07-06
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号