发表机构
San Jose State University(圣何塞州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究比较了经典机器学习模型(HMM、SVM)与深度学习模型(MLP、LSTM)对位级参数扰动的响应,发现经典模型脆弱且隐写容量有限,而神经网络因参数冗余具有更高隐写容量,揭示了参数敏感性与鲁棒性的差异。
AI 中文摘要
在本章中,我们研究了经典机器学习模型如何响应其参数中微小且有针对性的修改。我们将这些结果与深度学习模型上的类似实验进行比较和对照。对于经典学习模型,我们考虑了隐马尔可夫模型(HMM)和支持向量机(SVM),为了进行比较,我们进行了涉及多层感知器(MLP)和长短期记忆(LSTM)网络的类似实验。当应用于Drebin Android恶意软件数据集时,我们的结果表明经典模型是脆弱的,即一组有限的选定参数可以对模型行为产生显著影响。在一组相关的实验中,我们研究了这些相同学习模型的隐写容量,即模型参数中可以被覆盖而不会对模型产生显著不利影响的比特比例。我们发现,由于经典模型紧凑、参数高效且相对敏感的参数结构,它们提供的隐写容量有限。相比之下,神经网络是参数冗余的,从而实现了更高的隐写容量,其中修改可以分布在许多参数上,而对性能的影响最小。这些结果突显了经典模型和神经模型对参数变化的响应差异,对鲁棒性和隐藏信息嵌入都有明确的影响。总的来说,这项工作为理解不同类别学习模型的参数敏感性和隐写容量提供了一个框架。
英文摘要
In this chapter, we investigate how classical machine learning models respond to small, targeted modifications in their parameters. We compare and contrast these results to analogous experiments on deep learning models. For classical learning models, we consider Hidden Markov Models (HMM) and Support Vector Machines (SVM), and for comparison, we conduct analogous experiments involving Multilayer Perceptrons (MLP) and Long Short-Term Memory (LSTM) networks. When applied to the Drebin Android malware dataset, our results show that classical models are brittle, in the sense that a limited set of selected parameters can have a dramatic effect on model behavior. In a related set of experiments, we investigate the steganographic capacity of these same learning models, that is, the proportion of bits in model parameters that can be overwritten without having a significant adverse affect on a model. We find that classical models offer limited steganographic capacity due to their compact, parameter-efficient, and relatively sensitive parameter structure. In contrast, neural networks are parameter-redundant, enabling higher steganographic capacity, where modifications can be distributed across many parameters with minimal impact on performance. These results highlight differences in how classical and neural models respond to parameter changes, with clear implications for both robustness and hidden information embedding. Overall, this work provides a framework for understanding parameter sensitivity and steganographic capacity across different classes of learning models.
CommentsTo appear as a chapter in the book "Artificial Intelligence for Cyber Defense in Emerging Threats", to be published by Springer by early 2027