rSDNet: 라벨 노이즈 및 적대적 공격에 대한 통합된 강력한 신경망 학습
rSDNet: Unified Robust Neural Learning against Label Noise and Adversarial Attacks
신경망은 현대 인공지능의 핵심이지만, 학습 과정은 데이터 오염에 매우 민감합니다. 일반적인 신경망 분류기는 범주형 교차 엔트로피 손실을 최소화하여 학습하는데, 이는 다항 분포 모델 하에서의 최대 우도 추정에 해당합니다. 이상적인 조건에서는 통계적으로 효율적이지만, 이 방법은 라벨 노이즈로 인해 출력 공간에서 발생하는 감독 정보의 왜곡, 그리고 입력 공간에서 발생하는 최악의 편차를 유발하는 적대적 공격과 같은 오염된 데이터에 매우 취약합니다. 본 논문에서는 두 가지 유형의 오염을 하나의 학습 목표 내에서 해결하는, 통계적으로 기반한 통합적인 강력한 신경망 분류 프레임워크를 제안합니다. 우리는 신경망 학습을 최소 분산 추정 문제로 공식화하고, 일반적인 $S$-분산 클래스에 기반한 강력한 학습 알고리즘인 rSDNet을 소개합니다. 결과적인 학습 목표는 고전적인 통계적 추정의 견고성 특성을 상속하며, 모델 확률을 통해 이상한 관측치를 자동으로 가중치 감소시킵니다. 우리는 rSDNet의 중요한 모집단 수준 특성을 확립했으며, 여기에는 Fisher 일관성, 베이즈 최적성을 의미하는 분류 보정, 그리고 균일한 라벨 노이즈 및 미세한 특징 오염에 대한 견고성 보장이 포함됩니다. 세 개의 벤치마크 이미지 분류 데이터 세트에 대한 실험 결과, rSDNet은 깨끗한 데이터에 대한 경쟁력 있는 정확도를 유지하면서 라벨 손상 및 적대적 공격에 대한 견고성을 향상시키는 것으로 나타났습니다. 우리의 결과는 이질적인 데이터 오염 하에서 강력한 신경망 분류를 위한 원칙적이고 효과적인 프레임워크로서 최소 분산 학습의 중요성을 강조합니다.
Neural networks are central to modern artificial intelligence, yet their training remains highly sensitive to data contamination. Standard neural classifiers are trained by minimizing the categorical cross-entropy loss, corresponding to maximum likelihood estimation under a multinomial model. While statistically efficient under ideal conditions, this approach is highly vulnerable to contaminated observations including label noises corrupting supervision in the output space, and adversarial perturbations inducing worst-case deviations in the input space. In this paper, we propose a unified and statistically grounded framework for robust neural classification that addresses both forms of contamination within a single learning objective. We formulate neural network training as a minimum-divergence estimation problem and introduce rSDNet, a robust learning algorithm based on the general class of $S$-divergences. The resulting training objective inherits robustness properties from classical statistical estimation, automatically down-weighting aberrant observations through model probabilities. We establish essential population-level properties of rSDNet, including Fisher consistency, classification calibration implying Bayes optimality, and robustness guarantees under uniform label noise and infinitesimal feature contamination. Experiments on three benchmark image classification datasets show that rSDNet improves robustness to label corruption and adversarial attacks while maintaining competitive accuracy on clean data, Our results highlight minimum-divergence learning as a principled and effective framework for robust neural classification under heterogeneous data contamination.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.