SPADE: A Spectral Method for Black-Box Adversarial Robustness Evaluation
Wuxinlin Cheng, Chenhui Deng, Zhiqiang Zhao, Yaohui Cai, Zhiru Zhang, Zhuo Feng
摘要
A black-box spectral method is introduced for evaluating the adversarial robustness of a given machine learning (ML) model. Our approach, named SPADE, exploits bijective distance mapping between the input/output graphs constructed for approximating the manifolds corresponding to the input/output data. By leveraging the generalized Courant-Fischer theorem, we propose a SPADE score for evaluating the adversarial robustness of a given model, which is proved to be an upper bound of the best Lipschitz constant under the manifold setting. To reveal the most non-robust data samples highly vulnerable to adversarial attacks, we develop a spectral graph embedding procedure leveraging dominant generalized eigenvectors. This embedding step allows assigning each data sample a robustness score that can be further harnessed for more effective adversarial training. Our experiments show the proposed SPADE method leads to promising empirical results for neural network models that are adversarially trained with the MNIST and CIFAR-10 data sets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis 等ICLR 2024 · 被引用 15 次
- SGM-PINN: Sampling Graphical Models for Faster Training of Physics-Informed Neural NetworksJohn Anticev, Ali Aghdaei, Wuxinlin Cheng, Zhuo FengDAC 2024 · 被引用 1 次
- CirSTAG: Circuit Stability Analysis on Graph-based ManifoldsWuxinlin Cheng, Yihang Yuan, Chenhui Deng, Ali Aghdaei 等DAC 2025 · 被引用 1 次
它引用的顶会 Paper6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph 等ICLR 2020 · 被引用 1,572 次
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang 等KDD 2020 · 被引用 604 次
- ML-LOO: Detecting Adversarial Examples with Feature AttributionPuyudi Yang, Jianbo Chen, Cho-Jui Hsieh, Jane-Ling Wang 等AAAI 2020 · 被引用 117 次
相关 Paper
- Lipschitz Bounds and Provably Robust Training by Laplacian SmoothingVishaal Krishnan, Abed AlRahman Al Makdah, Fabio PasqualettiNeurIPS 2020 · 被引用 28 次
- Graph Structural Attack by Perturbing Spectral DistanceLu Lin, Ethan Blaser, Hongning WangKDD 2022 · 被引用 28 次
- Certified Robustness via Dynamic Margin Maximization and Improved Lipschitz RegularizationMahyar Fazlyab, Taha Entesari, Aniket Roy, Rama ChellappaNeurIPS 2023 · 被引用 26 次
- Not All Low-Pass Filters are Robust in Graph Convolutional NetworksHeng Chang, Yu Rong, Tingyang Xu, Yatao Bian 等NeurIPS 2021 · 被引用 65 次
- Provably Safeguarding a Classifier from OOD and Adversarial SamplesNicolas Atienza, Johanne Cohen, Christophe Labreuche, Michèle SebagICLR 2025
