首页|期刊导航|计算机应用与软件|基于决策边界采样的神经网络对抗训练

基于决策边界采样的神经网络对抗训练OA

ADVERSARIAL TRAINING OF NEURAL NETWORKS WITH DECISION BOUNDARY SAMPLING

中文摘要英文摘要

神经网络的决策面是高维的,现有解析方法难以研究其形状特征且效率低下.传统对抗训练容易受到不均匀样本的影响,难以降低脆弱性.为了高效探究脆弱性来源,提出一种基于决策边界采样方法,通过蒙特卡洛方法避免采用高维函数分析决策边界,应用不同策略生成靠近决策边界的对抗样本来实现数据增强.实验结果表明,奇异性是脆弱性的潜在来源之一,所提改进方法能有效提高模型的鲁棒性.

The decision surface of neural networks is high-dimensional,and the existing analytical methods are difficult to study its shape characteristics and inefficient.Traditional adversarial training is easily affected by uneven samples,which is difficult to reduce the vulnerability.In order to explore the source of vulnerability efficiently,this paper proposes a sampling method based on decision boundary.It avoided using high-dimensional function to analyze decision boundary by Monte Carlo method.In order to reduce the vulnerability,this paper proposed a new adversarial training method,which generated adversarial samples close to the decision boundary through different strategies to achieve data augmentation.The experimental results show that singularity is one of the potential sources of vulnerability and the improved method can effectively improve the robustness.

贾婧玥;金澎;王兵;陈兴元

西南石油大学计算机科学学院 四川成都 610500特殊教育语言智能四川省哲学社会科学重点实验室 四川乐山 614000||乐山师范学院 四川乐山 614000西南石油大学计算机科学学院 四川成都 610500||特殊教育语言智能四川省哲学社会科学重点实验室 四川乐山 614000特殊教育语言智能四川省哲学社会科学重点实验室 四川乐山 614000||乐山师范学院 四川乐山 614000

信息技术与安全科学

决策边界对抗样本神经网络蒙特卡洛对抗训练

Decision boundaryAdversarial examplesNeural networkMonte CarloAdversarial training

《计算机应用与软件》 2026 (6)

119-125,7

国家自然科学基金项目(61003206).

10.3969/j.issn.1000-386x.2026.06.017

评论