arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.10203cs.CV

用于分布外样本与对抗攻击检测方法的卷积层激活降维技术

A Convolutional Layer Activation Dimensionality Reduction for Out-of-Distribution and Adversarial Attack Detection Methods

  • Alma Mater Studiorum Università di Bologna(博洛尼亚大学)
  • Advanced Research Center on Electronic Systems “Ercole De Castro” (ARCES) - Alma Mater Studiorum Università di Bologna(博洛尼亚大学“埃尔科莱·德·卡斯特罗”电子系统高级研究中心)

机构由 AI 辅助整理,请以论文原文为准。

Leandro de Souza Rosa, Lorenzo Capelli, Clara Nunes Barrancos, Mauro Mangia, Riccardo Rovatti

AI总结:

本文针对卷积层激活降维的不足,提出一种可控高压缩率的新型降维方法,扩展两种最先进的检测方法并在OOD与对抗攻击检测任务上验证,其性能更优且计算内存占用更低。

AI中文摘要:

尽管卷积神经网络在图像分类任务中取得成功并广泛应用于多模态模型,但它们对分布外(Out-of-Distribution, OOD)样本和对抗攻击样本的脆弱性引发了对可信度与安全性的担忧。在解决此类问题的方法中,分析模型中间激活以估计置信度分数的检测方法是一类有前景的技术,这类方法通过降维步骤实现高维激活的高效下游处理,进而评估决策过程。然而,针对卷积层,现有文献中的降维方法要么缺乏控制压缩/信息损失权衡的机制,要么生成的表示维度较大。本文仔细分析了两种最先进的检测方法及其针对卷积层的降维策略,开发了一种具有可控高压缩率的新型降维方法。我们扩展了这两种最先进的检测方法,使其可使用任意降维技术,并在分布外样本与对抗攻击检测任务上评估其性能。结果表明,采用所提降维方法的检测方法始终优于或可媲美最强的替代方法。此外,所提方法在对比方法中压缩率最高,可降低计算与内存占用。

英文摘要:

Despite the success of convolutional neural networks in image classification tasks and their general application in multi-modal models, their susceptibility to out-of-distribution and adversarial attack samples raises concerns regarding trustworthiness and safety. Among the approaches to tackle such issues, detection methods that analyze the model's intermediate activations to estimate a confidence score are a promising family that evaluates the decision process, relying on a dimensionality reduction step to enable efficient downstream processing of the high-dimensional activations. However, when considering convolutional layers, the dimensionality reduction methods in the literature either lack a mechanism to control the compression/information-loss trade-off or yield large representations. In this paper, we carefully analyze two state-of-the-art detection methods and their dimensionality reductions for convolutional layers and develop a novel reduction method with a controllable high-compression level. We extend these two state-of-the-art detection methods, enabling the usage of any dimensionality reduction, and evaluate their performance on out-of-distribution and adversarial attack detection. Results show that the detection methods with the proposed dimensionality reduction consistently perform better than, or comparable to, the strongest alternative. Furthermore, the proposed method is shown to reduce computation and memory footprints, given that it has the highest compression among the compared methods.

↑