적대적 공격에서의 임의의 $\ell_p$ 노름의 희소성 및 부드러움 탐구
Exploring Sparsity and Smoothness of Arbitrary $\ell_p$ Norms in Adversarial Attacks
심층 신경망에 대한 적대적 공격은 일반적으로 $\ell_p$ 노름 제약 조건 하에서 구성되며, 주로 $p=1$, $p=2$ 또는 $p=\infty$를 사용하며, 희소성 또는 부드러움과 같은 특정 요구 사항을 위해 정규화될 수 있습니다. 이러한 선택은 일반적으로 노름 파라미터 $p$가 적대적 섭동의 구조적 및 인식적 특성에 미치는 영향에 대한 체계적인 조사 없이 이루어집니다. 본 연구에서는 $p \in [1,2]$ 범위의 값에 대해 $\ell_p$ 노름 제약 조건 하에서 생성된 적대적 공격의 희소성과 부드러움에 대한 $p$ 값의 영향을 연구합니다. 정량적 분석을 위해 기존 문헌에서 사용된 두 가지 희소성 측정 방법을 채택하고 세 가지 부드러움 측정 방법을 소개합니다. 특히, 스무딩 연산을 기반으로 부드러움 측정 방법을 도출하는 일반적인 프레임워크를 제안하고, 또한 1차 테일러 근사를 기반으로 하는 부드러움 측정 방법을 추가로 소개합니다. 이러한 측정 방법을 사용하여 여러 실제 이미지 데이터 세트와 다양한 모델 아키텍처(컨볼루션 및 트랜스포머 기반 네트워크 포함)에 대한 종합적인 경험적 평가를 수행합니다. 실험 결과, $\ell_1$ 또는 $\ell_2$ 노름은 대부분의 경우 최적이 아니며, 최적의 $p$ 값은 특정 작업에 따라 달라짐을 보여줍니다. 실험 결과, $p \in [1.3, 1.5]$ 범위의 $\ell_p$ 노름을 사용하면 희소성과 부드러움 간의 최적의 균형을 제공합니다. 이러한 결과는 적대적 공격을 설계하고 평가할 때 원칙적인 노름 선택의 중요성을 강조합니다.
Adversarial attacks against deep neural networks are commonly constructed under $\ell_p$ norm constraints, most often using $p=1$, $p=2$ or $p=\infty$, and potentially regularized for specific demands such as sparsity or smoothness. These choices are typically made without a systematic investigation of how the norm parameter \( p \) influences the structural and perceptual properties of adversarial perturbations. In this work, we study how the choice of \( p \) affects sparsity and smoothness of adversarial attacks generated under \( \ell_p \) norm constraints for values of $p \in [1,2]$. To enable a quantitative analysis, we adopt two established sparsity measures from the literature and introduce three smoothness measures. In particular, we propose a general framework for deriving smoothness measures based on smoothing operations and additionally introduce a smoothness measure based on first-order Taylor approximations. Using these measures, we conduct a comprehensive empirical evaluation across multiple real-world image datasets and a diverse set of model architectures, including both convolutional and transformer-based networks. We show that the choice of $\ell_1$ or $\ell_2$ is suboptimal in most cases and the optimal $p$ value is dependent on the specific task. In our experiments, using $\ell_p$ norms with $p\in [1.3, 1.5]$ yields the best trade-off between sparse and smooth attacks. These findings highlight the importance of principled norm selection when designing and evaluating adversarial attacks.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.