Vulnerability of Deep Learning

03/16/2018
by   Richard Kenway, et al.
0

The Renormalisation Group (RG) provides a framework in which it is possible to assess whether a deep-learning network is sensitive to small changes in the input data and hence prone to error, or susceptible to adversarial attack. Distinct classification outputs are associated with different RG fixed points and sensitivity to small changes in the input data is due to the presence of relevant operators at a fixed point. A numerical scheme, based on Monte Carlo RG ideas, is proposed for identifying the existence of relevant operators and the corresponding directions of greatest sensitivity in the input data. Thus, a trained deep-learning network may be tested for its robustness and, if it is vulnerable to attack, dangerous perturbations of the input data identified.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/29/2018

Protection against Cloning for Deep Learning

The susceptibility of deep learning to adversarial attack can be underst...
research
02/22/2019

On the Sensitivity of Adversarial Robustness to Input Data Distributions

Neural networks are vulnerable to small adversarial perturbations. Exist...
research
12/21/2017

Wolf in Sheep's Clothing - The Downscaling Attack Against Deep Learning Applications

This paper considers security risks buried in the data processing pipeli...
research
09/15/2021

Universal Adversarial Attack on Deep Learning Based Prognostics

Deep learning-based time series models are being extensively utilized in...
research
08/20/2020

β-Variational Classifiers Under Attack

Deep Neural networks have gained lots of attention in recent years thank...
research
11/06/2018

SparseFool: a few pixels make a big difference

Deep Neural Networks have achieved extraordinary results on image classi...
research
11/09/2021

Learning Numerical Action Models from Noisy Input Data

This paper presents the PlanMiner-N algorithm, a domain learning techniq...

Please sign up or login with your details

Forgot password? Click here to reset