Reprogramação Adversarial de Redes Neurais em ShortScience.org: Elsayed et al. use universal adversarial examples to reprogram neural networks in order to perform different tasks. In particular, e.g., on ImageNet, an adversarial example
$\delta = \tanh(W \cdot M)$
is computed where $M$ is a mask image (see Figure 1, in the paper the mask image essentially embeds a smaller image into an ImageNet-sized image) and $W$ is the adversarial perturbation itself (note that the notaiton was changed slightly for simplification). The hyperbolic tangent constraints the adversarial example, also called adversarial program, to the valid range of $[-1,1]$ as used in most ImageNet networks. The adversarial program is comuted by minimizing
$\min_W (-\log P(h(\tilde{y}) | \tilde{x}) + \lambda \|W\|_2^2$.
Here, $h$ is a function mapping the labels of the target taks (e.g., MNIST classification) to the $1000$ labels of the ImageNet classification task (e.g., using the first ten labels, or assigning multiple ImageNet labels to one MNIST label). Essentially, this means minimizing the cross entropy loss of the new task (with new labels) to solve for the adversarial program. Examples of adversarial programs for different tasks and architectures are shown in Figure
explicita
AS IDEIAS SÃO BEM VINDAS E AS OPINIÕES SÃO DETERMINANTES PARA SERMOS AINDA MELHORES. A DEMOCRACIA ESTÁ EM RISCO
Subscrever:
Enviar feedback (Atom)
Murdered Chinese Ambassador Tried to Defect?
Murdered Chinese Ambassador Tried to Defect? explicita
-
Turkey Refuses to Stop Trading With Iran at the Behest of Others : The US has demanded that countries stop importing Iranian oil as Presiden...
-
Murdered Chinese Ambassador Tried to Defect? explicita
Sem comentários:
Enviar um comentário