On the Robustness of Deep Clustering Models: Adversarial Attacks and Defenses
Anshuman Chhabra, Ashwin Sekhari, Prasant Mohapatra
摘要
Clustering models constitute a class of unsupervised machine learning methods which are used in a number of application pipelines, and play a vital role in modern data science. With recent advancements in deep learning -- deep clustering models have emerged as the current state-of-the-art over traditional clustering approaches, especially for high-dimensional image datasets. While traditional clustering approaches have been analyzed from a robustness perspective, no prior work has investigated adversarial attacks and robustness for deep clustering models in a principled manner. To bridge this gap, we propose a blackbox attack using Generative Adversarial Networks (GANs) where the adversary does not know which deep clustering model is being used, but can query it for outputs. We analyze our attack against multiple state-of-the-art deep clustering models and real-world datasets, and find that it is highly successful. We then employ some natural unsupervised defense approaches, but find that these are unable to mitigate our attack. Finally, we attack Face++, a production-level face clustering API service, and find that we can significantly reduce its performance as well. Through this work, we thus aim to motivate the need for truly robust deep clustering models.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- "What Data Benefits My Classifier?" Enhancing Model Performance and Interpretability through Influence-Based Data SelectionAnshuman Chhabra, Peizhao Li, Prasant Mohapatra, Hongfu LiuICLR 2024 · 被引用 32 次
- Adversarially Robust Deep Multi-View Clustering: A Novel Attack and Defense FrameworkHaonan Huang, Guoxu Zhou, Yanghang Zheng, Yuning Qiu 等ICML 2024 · 被引用 12 次
- Robust Fair Clustering: A Novel Fairness Attack and Defense FrameworkAnshuman Chhabra, Peizhao Li, Prasant Mohapatra, Hongfu LiuICLR 2023 · 被引用 2 次
- Towards Calibrated Deep Clustering NetworkYuheng Jia, Jianhong Cheng, Hui Liu, Junhui HouICLR 2025
它引用的顶会 Paper9
- SSD: A Unified Framework for Self-Supervised Outlier DetectionVikash Sehwag, Mung Chiang, Prateek MittalICLR 2021 · 被引用 410 次
- MiCE: Mixture of Contrastive Experts for Unsupervised Image ClusteringTsung Wei Tsai, Chongxuan Li, Jun ZhuICLR 2021 · 被引用 82 次
- Adversarial Learning for Robust Deep ClusteringXu Yang, Cheng Deng, Kun Wei, Junchi Yan 等NeurIPS 2020 · 被引用 77 次
- Suspicion-Free Adversarial Attacks on Clustering AlgorithmsAnshuman Chhabra, Abhishek Roy, Prasant MohapatraAAAI 2020 · 被引用 32 次
- End-to-end robust joint unsupervised image alignment and clusteringXiangrui Zeng, Gregory Howe, Min XuICCV 2021 · 被引用 12 次
相关 Paper
- CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial ExamplesHonggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai 等NDSS 2020
- Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup TransferShengshan Hu, Xiaogeng Liu, Yechao Zhang, Minghui Li 等CVPR 2022 · 被引用 123 次
- QEBA: Query-Efficient Boundary-Based Blackbox AttackHuichen Li, Xiaojun Xu, Xiaolu Zhang, Shuang Yang 等CVPR 2020
- Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalLong Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen 等AAAI 2024 · 被引用 13 次
- Top-Down Deep Clustering with Multi-Generator GANsDaniel P. M. de Mello, Renato M. Assunção, Fabricio MuraiAAAI 2022 · 被引用 22 次
