위상 변화를 유도하는 공격: 복소수 신경망의 적대적 강건성 분석
Perturbing the Phase: Analyzing Adversarial Robustness of Complex-Valued Neural Networks
복소수 신경망(CVNN)은 다양한 응용 분야에서 점점 더 인기를 얻고 있습니다. CVNN을 실제 환경에서 안전하게 사용하기 위해서는 이상치에 대한 강건성을 분석하는 것이 중요합니다. 심층 신경망의 동작을 이해하는 데 사용되는 대표적인 방법 중 하나는 적대적 공격(adversarial attacks) 하에서의 동작을 분석하는 것입니다. 적대적 공격은 최악의 경우에 발생하는 최소한의 변화를 의미합니다. 본 연구에서는 복소수 입력의 위상 정보에 특화된 공격인 '위상 공격(Phase Attacks)'을 설계했습니다. 또한, 일반적으로 사용되는 적대적 공격의 복소수 버전을 개발했습니다. 실험 결과, 특정 시나리오에서는 CVNN이 RVNN보다 더 강건하며, 두 모델 모두 위상 변화에 매우 취약하다는 것을 확인했습니다. 특히, 위상 공격은 위상과 크기 모두를 공격하는 일반적인 공격보다 모델 성능을 더욱 저하시키는 것으로 나타났습니다.
Complex-valued neural networks (CVNNs) are rising in popularity for all kinds of applications. To safely use CVNNs in practice, analyzing their robustness against outliers is crucial. One well known technique to understand the behavior of deep neural networks is to investigate their behavior under adversarial attacks, which can be seen as worst case minimal perturbations. We design Phase Attacks, a kind of attack specifically targeting the phase information of complex-valued inputs. Additionally, we derive complex-valued versions of commonly used adversarial attacks. We show that in some scenarios CVNNs are more robust than RVNNs and that both are very susceptible to phase changes with the Phase Attacks decreasing the model performance more, than equally strong regular attacks, which can attack both phase and magnitude.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.