Automatic Attack Discovery for Few-Shot Class-Incremental Learning via Large Language Models
Few-shot class incremental learning (FSCIL) is a more realistic and challenging paradigm in continual learning to incrementally learn unseen classes and overcome catastrophic forgetting on base classes with only a few training examples. Previous efforts have primarily centered around studying more effective FSCIL approaches. By contrast, less attention was devoted to thinking the security issues in contributing to FSCIL. This paper aims to provide a holistic study of the impact of attacks on FSCIL. We first derive insights by systematically exploring how human expert-designed attack methods (i.e., PGD, FGSM) affect FSCIL. We find that those methods either fail to attack base classes, or suffer from huge labor costs due to relying on huge expert knowledge. This highlights the need to craft a specialized attack method for FSCIL. Grounded in these insights, in this paper, we propose a simple yet effective ACraft method to automatically steer and discover optimal attack methods targeted at FSCIL by leveraging Large Language Models (LLMs) without human experts. Moreover, to improve the reasoning between LLMs and FSCIL, we introduce a novel Proximal Policy Optimization (PPO) based reinforcement learning to optimize learning, making LLMs generate better attack methods in the next generation by establishing positive feedback. Experiments on mainstream benchmarks show that our ACraft significantly degrades the performance of state-of-the-art FSCIL methods and dramatically beyond human expert-designed attack methods while maintaining the lowest costs of attack.
Code (0)
등록된 구현이 없습니다.
Tasks
Few-Shot Class-Incremental LearningClass Incremental LearningReinforcement LearningContinual LearningSimilar Papers 제목 키워드 기반
MetaFSCIL: A Meta-Learning Approach for Few-Shot Class Incremental Learning
In this paper, we tackle the problem of few-shot class incremental learning (FSCIL). FSCIL aims to incrementally learn new classes with only a few samples in each class. Most existing methods only consider the increm…
class-incremental learningClass Incremental LearningFew-Shot Class-Incremental LearningIncremental Learning+1FSCIL-SEI: Few-Shot Class-Incremental Learning Approach for Specific Emitter Identification
—Specific emitter identification (SEI) is a non-password authentication method that adds an extra layer of security to wireless devices. However, existing SEI methods are unable to continuously learn new classes from …
class-incremental learningClass Incremental LearningContrastive LearningFew-Shot Class-Incremental Learning+1Few-Shot Class-Incremental Learning For Efficient SAR Automatic Target Recognition
Synthetic aperture radar automatic target recognition (SAR-ATR) systems have rapidly evolved to tackle incremental recognition challenges in operational settings. Data scarcity remains a major hurdle that conventional SA…
class-incremental learningClass Incremental LearningComputational EfficiencyFew-Shot Class-Incremental Learning+1Automated Adversarial Discovery for Safety Classifiers
Safety classifiers are critical in mitigating toxicity on online forums such as social media and in chatbots. Still, they continue to be vulnerable to emergent, and often innumerable, adversarial attacks. Traditional aut…
DiversityA Forward and Backward Compatible Framework for Few-shot Class-incremental Pill Recognition
Automatic Pill Recognition (APR) systems are crucial for enhancing hospital efficiency, assisting visually impaired individuals, and preventing cross-infection. However, most existing deep learning-based pill recognition…
class-incremental learningClass Incremental LearningFew-Shot Class-Incremental LearningGraph Attention+5