paper-with-me

홈 › Papers

$A^{3}D$: A Platform of Searching for Robust Neural Architectures and Efficient Adversarial Attacks

2022-03-07 · Jialiang Sun, Wen Yao, Tingsong Jiang, Chao Li, Xiaoqian Chen

The robustness of deep neural networks (DNN) models has attracted increasing attention due to the urgent need for security in many applications. Numerous existing open-sourced tools or platforms are developed to evaluate the robustness of DNN models by ensembling the majority of adversarial attack or defense algorithms. Unfortunately, current platforms do not possess the ability to optimize the architectures of DNN models or the configuration of adversarial attacks to further enhance the robustness of models or the performance of adversarial attacks. To alleviate these problems, in this paper, we first propose a novel platform called auto adversarial attack and defense ($A^{3}D$), which can help search for robust neural network architectures and efficient adversarial attacks. In $A^{3}D$, we employ multiple neural architecture search methods, which consider different robustness evaluation metrics, including four types of noises: adversarial noise, natural noise, system noise, and quantified metrics, resulting in finding robust architectures. Besides, we propose a mathematical model for auto adversarial attack, and provide multiple optimization algorithms to search for efficient adversarial attacks. In addition, we combine auto adversarial attack and defense together to form a unified framework. Among auto adversarial defense, the searched efficient attack can be used as the new robustness evaluation to further enhance the robustness. In auto adversarial attack, the searched robust architectures can be utilized as the threat model to help find stronger adversarial attacks. Experiments on CIFAR10, CIFAR100, and ImageNet datasets demonstrate the feasibility and effectiveness of the proposed platform, which can also provide a benchmark and toolkit for researchers in the application of automated machine learning in evaluating and improving the DNN model robustnesses.

📄 PDF Abstract BibTeX arXiv:2203.03128

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackAdversarial DefenseNeural Architecture Search

Methods 이 논문이 사용한 방법론

Random Search Random Search replaces the exhaustive enumeration of all combinations by selecting them randomly. This can be simply applied to the discrete setting described above, but also…

Similar Papers 제목 키워드 기반

Dual-Path Distillation: A Unified Framework to Improve Black-Box Attacks

2020-01-01 · ICML 2020 1 · Yonggang Zhang, Ya Li, Tongliang Liu, Xinmei Tian

We study the problem of constructing black-box adversarial attacks, where no model information is revealed except for the feedback knowledge of the given inputs. To obtain sufficient knowledge for crafting adversarial ex…

A Branch and Bound Framework for Stronger Adversarial Attacks of ReLU Networks

2021-09-29 · huan zhang, Shiqi Wang, Kaidi Xu, Yihan Wang 외

Strong adversarial attacks are important for evaluating the true robustness of deep neural networks. Most existing attacks find adversarial examples via searching in the input space, e.g., using gradient descent. In this…

Adversarial AttackGPU

Heterogeneous Architecture Search Approach within Adversarial Dynamic Defense Framework

2021-11-22 · AAAI Workshop AdvML 2022 2 · Qi Peng, Ruoxi Qin, Wenlin Liu, Libin Hou 외

Recent advances in adversarial attacks uncover the intrinsic vulnerability of modern deep neural networks (DNNs). To address this issue, various methods have been proposed to design network architectures that are robust …

Adversarial AttackAdversarial RobustnessDiversity

Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGA

2020-11-05 · Adnan Siraj Rakin, Yukui Luo, Xiaolin Xu, Deliang Fan

The wide deployment of Deep Neural Networks (DNN) in high-performance cloud computing platforms brought to light multi-tenant cloud field-programmable gate arrays (FPGA) as a popular choice of accelerator to boost perfor…

Adversarial AttackCloud Computingimage-classificationImage Classification+2

Bi-fidelity Evolutionary Multiobjective Search for Adversarially Robust Deep Neural Architectures

2022-07-12 · Jia Liu, Ran Cheng, Yaochu Jin

Deep neural networks have been found vulnerable to adversarial attacks, thus raising potentially concerns in security-sensitive contexts. To address this problem, recent research has investigated the adversarial robustne…

Adversarial RobustnessMultiobjective OptimizationNeural Architecture Search