Optimization Models and Interpretations for Adversarial Perturbations against Support Vector Machines
Wen Su et al.
What the paper says
Adversarial perturbations have drawn great attention in various deep learning methods. However, little attention is paid to basic machine learning models such as support vector machines. In this paper, we investigate the optimization models and the interpretations for adversarial perturbations against linear support vector machines, including class-universal adversarial perturbations (cuAP) and universal adversarial perturbations (uAP). Unlike most of adversarial perturbations which are computed by iterative algorithms and cannot be interpreted very well, we derive explicit solutions for cuAP and uAP of binary case, and approximate solutions for cuAP and uAP of multiclassification case, respectively. We also obtain the upper bound of fooling rate for uAP. Such results not only increase the interpretability of these adversarial perturbations, but also provide great convenience in computation since iterative process can be avoided. Numerical results show that our method is fast and effective in calculating adversarial perturbations, based on which one can efficiently improve the robustness of the training model.
Evidence weight
Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40
| F · citation impact | 0.50 × 0.4 = 0.20 |
| M · momentum | 0.50 × 0.15 = 0.07 |
| V · venue signal | 0.50 × 0.05 = 0.03 |
| R · text relevance † | 0.50 × 0.4 = 0.20 |
† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.