Deep learning models have been proven to be severely affected by adversarial examples, which limit the widespread deployment of deep learning models. Prior research largely focused on defending against single types of perturbations using a single network. However, these methods are susceptible to sacrificing defense range because defense models that are trained to be robust against one perturbation type may not be robust against other types. Moreover, it is unrealistic to assume that neural networks would only be affected by a single type of perturbation. To defend against multiple perturbations, recent works have attempted to improve the overall robustness against multiple perturbations. Nonetheless, when evaluating the model’s robustness against each type of perturbation, multi-perturbation defenses are still significantly less effective than models that are robust against a single perturbation type. To address these issues, we propose Poseidon, an ensemble defense method based on neural architecture search to defend against multiple perturbations. We first highlight the importance of architecture evolution in enhancing model robustness. And a novel robust architecture search method is proposed to identify perturbation-tailored architectures for sub-models. Furthermore, we explore a dedicated ensemble method that can combine these diverse sub-model architectures to be robust against multiple types of perturbations. The experimental results demonstrate that Poseidon outperforms the state-of-the-art multiple perturbation defense methods by 10.9% and 7.4% in robustness on the CIFAR-10 and CIFAR-100 datasets, respectively.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Poseidon: A NAS-Based Ensemble Defense Method Against Multiple Perturbations

  • Yulan Su,
  • Sisi Zhang,
  • Zechao Lin,
  • Xingbin Wang,
  • Lutan Zhao,
  • Dan Meng,
  • Rui Hou

摘要

Deep learning models have been proven to be severely affected by adversarial examples, which limit the widespread deployment of deep learning models. Prior research largely focused on defending against single types of perturbations using a single network. However, these methods are susceptible to sacrificing defense range because defense models that are trained to be robust against one perturbation type may not be robust against other types. Moreover, it is unrealistic to assume that neural networks would only be affected by a single type of perturbation. To defend against multiple perturbations, recent works have attempted to improve the overall robustness against multiple perturbations. Nonetheless, when evaluating the model’s robustness against each type of perturbation, multi-perturbation defenses are still significantly less effective than models that are robust against a single perturbation type. To address these issues, we propose Poseidon, an ensemble defense method based on neural architecture search to defend against multiple perturbations. We first highlight the importance of architecture evolution in enhancing model robustness. And a novel robust architecture search method is proposed to identify perturbation-tailored architectures for sub-models. Furthermore, we explore a dedicated ensemble method that can combine these diverse sub-model architectures to be robust against multiple types of perturbations. The experimental results demonstrate that Poseidon outperforms the state-of-the-art multiple perturbation defense methods by 10.9% and 7.4% in robustness on the CIFAR-10 and CIFAR-100 datasets, respectively.