典型文献
ACHIEVING OPTIMAL ADVERSARIAL ACCURACY FOR ADVERSARIAL DEEP LEARNING USING STACKELBERG GAMES
文献摘要:
The purpose of adversarial deep learning is to train robust DNNs against adver-sarial attacks,and this is one of the major research focuses of deep learning.Game theory has been used to answer some of the basic questions about adversarial deep learning,such as those regarding the existence of a classifier with optimal robustness and the existence of optimal adversarial samples for a given class of classifiers.In most previous works,adversarial deep learning was formulated as a simultaneous game and the strategy spaces were assumed to be certain probability distributions in order for the Nash equilibrium to exist.However,this assumption is not applicable to practical situations.In this paper,we give answers to these basic questions for the practical case where the classifiers are DNNs with a given structure;we do that by formulating adversarial deep learning in the form of Stackelberg games.The existence of Stackelberg equilibria for these games is proven.Furthermore,it is shown that the equilibrium DNN has the largest adversarial accuracy among all DNNs with the same structure,when Carlini-Wagner's margin loss is used.The trade-off between robustness and accuracy in adversarial deep learning is also studied from a game theoretical perspective.
文献关键词:
中图分类号:
作者姓名:
Xiao-shan GAO;Shuang LIU;Lijia YU
作者机构:
Academy of Mathematics and Systems Science,Chinese Academy of Sciences,University of Chinese Academy of Sciences,Beijing 100190,China
文献出处:
引用格式:
[1]Xiao-shan GAO;Shuang LIU;Lijia YU-.ACHIEVING OPTIMAL ADVERSARIAL ACCURACY FOR ADVERSARIAL DEEP LEARNING USING STACKELBERG GAMES)[J].数学物理学报(英文版),2022(06):2399-2418
A类:
ACHIEVING,OPTIMAL,ADVERSARIAL,ACCURACY,LEARNING,USING,STACKELBERG,GAMES,Carlini
B类:
FOR,DEEP,purpose,adversarial,deep,learning,train,DNNs,against,attacks,this,one,major,research,focuses,Game,theory,has,been,used,some,basic,questions,about,such,those,regarding,existence,optimal,robustness,samples,given,classifiers,In,most,previous,works,was,formulated,simultaneous,strategy,spaces,were,assumed,certain,probability,distributions,order,Nash,equilibrium,However,assumption,not,applicable,practical,situations,paper,answers,these,case,where,are,structure,do,that,by,formulating,Stackelberg,games,equilibria,proven,Furthermore,shown,largest,accuracy,among,all,same,when,Wagner,margin,loss,trade,off,between,also,studied,from,theoretical,perspective
AB值:
0.462389
相似文献
机标中图分类号,由域田数据科技根据网络公开资料自动分析生成,仅供学习研究参考。