发表机构
Örebro University; Delft University of Technology; University of Padua(厄勒布鲁大学; 代尔夫特理工大学; 帕多瓦大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文针对神经-符号模型的后门攻击开展首次系统性评估,对比DeepProbLog与基线神经网络,发现神经-符号模型平均更鲁棒,但其鲁棒性依赖推理过程的严格度及与对抗目标的兼容性。
AI 中文摘要
神经-符号(NeSy)人工智能作为一种新型范式已兴起,旨在实现可信人工智能,将亚符号的神经感知与基于基础的符号推理相融合。这类模型的神经-符号集成过程已被证实有助于构建更透明、可解释且高效的人工智能系统。同时,其在对抗环境下的特性常被忽视,被认为具有设计层面的鲁棒性。然而,这类模型所采用的神经-符号集成过程构成了额外的复杂度,可能成为攻击切入点。因此,本文提出需深入研究神经-符号(NeSy)模型的对抗鲁棒性,并针对针对神经-符号模型的后门攻击开展首次系统性评估。为此,我们对比了最流行的神经-符号框架DeepProbLog与基线神经网络,共涉及8种后门设置和4个推理任务。实验结果显示,神经-符号模型平均而言确实比其神经对应模型更具鲁棒性,但其鲁棒性极大依赖于所实施的推理过程的严格程度,以及该过程与所选对抗目标的兼容性。本文实验的复现代码已提供在此https URL。
英文摘要
Neuro-Symbolic (NeSy) AI has recently emerged as a novel paradigm to enable trustworthy AI, aiming at integrating sub-symbolic neural perception with grounded symbolic reasoning. The neuro-symbolic integration process that characterizes these models has been proven beneficial to achieve more transparent, explainable and efficient AI systems. Meanwhile, their properties under adversarial settings have been overlooked being frequently deemed robust-by-design. However, the neural-symbolic integration process they leverage constitutes an additional layer of complexity that may provide an attack entry-point. Therefore, in this paper, we claim that an in-depth investigation of the adversarial robustness of NeSy models is necessary and provide the first systematic evaluation of backdoor attacks against NeSy. To this end, we compare the most popular NeSy framework, namely DeepProbLog, against baseline neural networks across a total of eight backdoor settings and four reasoning tasks. Our experimental results show that while NeSy models are indeed more robust than their neural counterpart on average, their robustness vastly depend on the strictness of the reasoning process being enforced and its compatibility with the chosen adversarial target. The source code to reproduce our experiments is made available at https://github.com/marcoantoniocorallo/NeSy-Backdoor.