Maximum Mean Discrepancy is Aware of Adversarial Attacks

10/22/2020
by   Ruize Gao, et al.
1

The maximum mean discrepancy (MMD) test, as a representative two-sample test, could in principle detect any distributional discrepancy between two datasets. However, it has been shown that MMD is unaware of adversarial attacks—MMD failed to detect the discrepancy between natural data and adversarial data generated by adversarial attacks. Given this phenomenon, we raise a question: are natural and adversarial data really from different distributions but previous use of MMD on the purpose missed some key factors? The answer is affirmative. We find the previous use missed three factors and accordingly we propose three components: (a) Gaussian kernel has limited representation power, and we replace it with a novel semantic-aware deep kernel; (b) test power of MMD was neglected, and we maximize it in order to optimize our deep kernel; (c) adversarial data may be non-independent, and to this end we apply wild bootstrap for validity of the test power. By taking care of the three factors, we validate that MMD is aware of adversarial attacks, which lights up a novel road for adversarial attack detection based on two-sample tests.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/22/2019

Attack Agnostic Statistical Method for Adversarial Detection

Deep Learning based AI systems have shown great promise in various domai...
research
12/02/2020

Two-sample test based on maximum variance discrepancy

In this article, we introduce a novel discrepancy called the maximum var...
research
05/31/2023

Graph-based methods coupled with specific distributional distances for adversarial attack detection

Artificial neural networks are prone to being fooled by carefully pertur...
research
10/28/2021

MMD Aggregated Two-Sample Test

We propose a novel nonparametric two-sample test based on the Maximum Me...
research
02/07/2022

Adversarial Attacks and Defense for Non-Parametric Two-Sample Tests

Non-parametric two-sample tests (TSTs) that judge whether two sets of sa...
research
09/05/2023

Maximum Mean Discrepancy Meets Neural Networks: The Radon-Kolmogorov-Smirnov Test

Maximum mean discrepancy (MMD) refers to a general class of nonparametri...
research
05/25/2023

Detecting Adversarial Data by Probing Multiple Perturbations Using Expected Perturbation Score

Adversarial detection aims to determine whether a given sample is an adv...

Please sign up or login with your details

Forgot password? Click here to reset