Robustness Setting Device for Adversarial Sample Neutralization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing machine learning models, particularly neural networks, are vulnerable to adversarial samples and require a significant number of adversarial samples for retraining to achieve robustness, making it challenging to simply provide robustness against such samples.
Innovation Solution
A robustness setting device and method that specify a required robustness level for a computation device by determining a noise removal level for input signals with added perturbations, using quantization to neutralize adversarial samples, and evaluating the robustness based on output accuracy across multiple perturbation levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If retraining is performed using adversarial examples, then robustness against adversarial samples is improved, but the complexity and resource requirements increase significantly
Solution Approach 1:
The invention extracts and removes the perturbation component from adversarial samples through spectral analysis. By identifying and eliminating the adversarial perturbation in the frequency domain, the system achieves robustness without requiring model retraining, thus reducing complexity while maintaining reliability
Solution Approach 2:
The invention introduces spectral analysis as an intermediary process between the adversarial sample input and the model processing. This intermediate step transforms the problem from model retraining to perturbation removal, simplifying the approach to achieving robustness
2Reliability
If a sufficient number of adversarial samples are prepared for retraining, then robustness is improved, but the time and computational resources required increase
Solution Approach 1:
The invention performs preliminary spectral analysis on the adversarial samples to identify and remove perturbations before model processing. This preliminary action eliminates the need for time-consuming retraining processes while maintaining robustness
Solution Approach 2:
The invention replaces the mechanical retraining process with a spectral analysis-based perturbation removal approach. This substitution eliminates the need for iterative model training and significantly reduces the time and computational resources required
3Reliability
If noise removal is applied to input signals, then robustness against adversarial samples is improved, but the accuracy on normal inputs may deteriorate
Solution Approach 1:
The invention applies noise removal selectively only to the perturbation components identified through spectral analysis, rather than uniformly to all input signals. This localized approach preserves the quality of normal inputs while removing adversarial perturbations, maintaining both robustness and accuracy
Data Source
AI summary
A robustness setting device provided with robustness specifying means for specifying a robustness level required in a computation device using a trained model against an adversarial sample that is an input signal to which a perturbation has been added in order to induce an erroneous determination by the trained model; and level determination means for determining a noise removal level for the input signal based on the robustness level.


