Multi-Label Adversarial Attack With New Measures and Self-Paced Constraint Weighting

被引:0
|
作者
Su, Fengguang [1 ]
Wu, Ou [1 ]
Zhu, Weiyao [1 ]
机构
[1] Tianjin Univ, Ctr Appl Math, Tianjin 300072, Peoples R China
关键词
Optimization; Perturbation methods; Costs; Current measurement; Robustness; Indexes; Loss measurement; Multi-label learning; adversarial attack; optimization problem; optimization goal; solving strategy;
D O I
10.1109/TIP.2024.3411927
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An adversarial attack is typically implemented by solving a constrained optimization problem. In top-k adversarial attacks implementation for multi-label learning, the attack failure degree (AFD) and attack cost (AC) of a possible attack are major concerns. According to our experimental and theoretical analysis, existing methods are negatively impacted by the coarse measures for AFD/AC and the indiscriminate treatment for all constraints, particularly when there is no ideal solution. Hence, this study first develops a refined measure based on the Jaccard index appropriate for AFD and AC, distinguishing the failure degrees/costs of two possible attacks better than the existing indicator function-based scheme. Furthermore, we formulate novel optimization problems with the least constraint violation via new measures for AFD and AC, and theoretically demonstrate the effectiveness of weighting slack variables for constraints. Finally, a self-paced weighting strategy is proposed to assign different priorities to various constraints during optimization, resulting in larger attack gains compared to previous indiscriminate schemes. Meanwhile, our method avoids fluctuations during optimization, especially in the presence of highly conflicting constraints. Extensive experiments on four benchmark datasets validate the effectiveness of our method across different evaluation metrics.
引用
收藏
页码:3809 / 3822
页数:14
相关论文
共 50 条
  • [41] Feature weighting to tackle label dependencies in multi-label stacking nearest neighbor
    Rastin, Niloofar
    Jahromi, Mansoor Zolghadri
    Taheri, Mohammad
    APPLIED INTELLIGENCE, 2021, 51 (07) : 5200 - 5218
  • [42] Feature weighting to tackle label dependencies in multi-label stacking nearest neighbor
    Niloofar Rastin
    Mansoor Zolghadri Jahromi
    Mohammad Taheri
    Applied Intelligence, 2021, 51 : 5200 - 5218
  • [43] A bi-level metric learning framework via self-paced learning weighting
    Yan, Jing
    Wei, Wei
    Guo, Xinyao
    Dang, Chuangyin
    Liang, Jiye
    PATTERN RECOGNITION, 2023, 139
  • [44] A Unified View of Multi-Label Performance Measures
    Wu, Xi-Zhu
    Zhou, Zhi-Hua
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 70, 2017, 70
  • [45] Learning Local Instance Constraint for Multi-label Classification
    Luo, Shang
    Wu, Xiaofeng
    Wang, Bin
    Zhang, Liming
    IMAGE AND GRAPHICS (ICIG 2017), PT I, 2017, 10666 : 284 - 294
  • [46] MSPLD: Shilling Attack Detection Model Based on Meta Self-Paced Learning
    Yang, Yanjing
    Gao, Min
    Li, Yuerang
    Wu, Fan
    Wang, Jia
    Zhao, Quanwu
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [47] Self-paced Multi-view Co-training
    Ma, Fan
    Meng, Deyu
    Dong, Xuanyi
    Yang, Yi
    JOURNAL OF MACHINE LEARNING RESEARCH, 2020, 21
  • [48] Untargeted Attack on Targeted-label for Multi-label Image Classification
    Lin, Yangfei
    Qiao, Peng
    Dou, Yong
    TWELFTH INTERNATIONAL CONFERENCE ON GRAPHICS AND IMAGE PROCESSING (ICGIP 2020), 2021, 11720
  • [49] Unsupervised Face Morphing Attack Detection via Self-paced Anomaly Detection
    Fang, Meiling
    Boutros, Fadi
    Damer, Naser
    2022 IEEE INTERNATIONAL JOINT CONFERENCE ON BIOMETRICS (IJCB), 2022,
  • [50] FSPMTL: Flexible Self-Paced Multi-Task Learning
    Sun, Lijian
    Zhou, Yun
    IEEE ACCESS, 2020, 8 : 132012 - 132020