跳到正文
返回论文列表
cs.CV提交于 已译

GraphRectify:基于图结构的对抗样本检测器跨神经网络迁移

GraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural Networks

Arash Vashagh · Roozbeh Razavi-Far

中文摘要

对抗样本检测器通常与训练时依赖的分类器骨干网络紧耦合,当被保护模型被替换或升级时难以复用。由于不同网络产生的中间表示互不兼容,直接将检测器跨骨干迁移十分困难。本文提出 GraphRectify,一个基于图结构的框架,用于在分类器骨干之间迁移对抗图像检测器。GraphRectify 学习分类器中间特征的结构化表示,再将新骨干产生的表示适配到原始模型上训练得到的检测器,从而实现检测器复用。实验在多个数据集、多种骨干架构与对抗攻击下进行评估,其中包括同时针对分类器和检测器的检测器感知自适应攻击。在完整评估矩阵中,GraphRectify 的聚合 ROC-AUC 高于在新骨干上从零训练检测器以及所对比的迁移消融方案。在不同骨干家族之间的迁移以及数据充足时,优势尤为明显;而在极度受限的数据设置中,从零训练仍具竞争力。结果表明,对抗检测知识能够在异构分类器架构间迁移复用,无需在被保护骨干变化时重新学习。

关键要点

  1. 01问题:对抗样本检测器与分类器骨干紧耦合,骨干更换或升级后难以复用
  2. 02方法:GraphRectify 用图结构建模分类器中间特征,并将新骨干表示适配到原检测器
  3. 03结果:在多数据集、多骨干、多攻击下聚合 ROC-AUC 超过从零训练与多种迁移消融
  4. 04局限:在数据极度受限的场景下,从零训练检测器仍具竞争力
  5. 05意义:对抗检测能力可在异构分类器架构间迁移,无需随骨干变更重新学习

解读

尚无解读。

原始英文摘要

arXiv:2610.10423v1 Announce Type: new Abstract: Adversarial example detectors are often tied to the classifier backbone they were trained on, limiting reuse when the protected model is replaced or upgraded. Directly transferring such detectors across backbones is challenging because different networks generally produce incompatible internal representations. We propose GraphRectify, a graph-based framework for transferring adversarial image detectors across classifier backbones. GraphRectify learns a structured representation of intermediate classifier features and adapts representations from a new backbone to the detector learned on the original model, enabling detector reuse. We evaluate GraphRectify across multiple datasets, backbone architectures, and adversarial attacks, including detector-aware adaptive attacks that jointly target the classifier and detector. Across the complete evaluation matrix, GraphRectify achieves higher aggregate ROC-AUC than training a detector from scratch on the new backbone and the evaluated transfer ablations. The gains are particularly strong for transfers between different backbone families and when sufficient data are available. In contrast, training from scratch remains competitive in the most data-limited settings. These results show that adversarial detection knowledge can transfer effectively across heterogeneous classifier architectures rather than being relearned whenever the protected backbone changes.

同方向论文 · cs.CV

查看全部 →