Improving Adversarial Robustness of Ensemble Classifiers by Diversified Feature Selection and Stochastic Aggregation

被引:0
|
作者
Zhang, Fuyong [1 ]
Li, Kuan [1 ]
Ren, Ziliang [1 ]
机构
[1] Dongguan Univ Technol, Sch Comp Sci & Technol, Dongguan 523808, Peoples R China
关键词
adversarial machine learning; evasion attacks; classifier robustness; ensemble classifiers; gradient correlation;
D O I
10.3390/math12060834
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
Learning-based classifiers are found to be vulnerable to attacks by adversarial samples. Some works suggested that ensemble classifiers tend to be more robust than single classifiers against evasion attacks. However, recent studies have shown that this is not necessarily the case under more realistic settings of black-box attacks. In this paper, we propose a novel ensemble approach to improve the robustness of classifiers against evasion attacks by using diversified feature selection and a stochastic aggregation strategy. Our proposed scheme includes three stages. Firstly, the adversarial feature selection algorithm is used to select a feature each time that can trade-offbetween classification accuracy and robustness, and add it to the feature vector bank. Secondly, each feature vector in the bank is used to train a base classifier and is added to the base classifier bank. Finally, m classifiers from the classifier bank are randomly selected for decision-making. In this way, it can cause each classifier in the base classifier bank to have good performance in terms of classification accuracy and robustness, and it also makes it difficult to estimate the gradients of the ensemble accurately. Thus, the robustness of classifiers can be improved without reducing the classification accuracy. Experiments performed using both Linear and Kernel SVMs on genuine datasets for spam filtering, malware detection, and handwritten digit recognition demonstrate that our proposed approach significantly improves the classifiers' robustness against evasion attacks.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] Improving Adversarial Robustness on Single Model via Feature Fusion and Ensemble Diversity
    Wei, Fan
    Song, Yun-Fei
    Shao, Ming-Li
    Liu, Tian
    Chen, Xiao-Hong
    Wang, Xiang-Feng
    Chen, Ming-Song
    [J]. Ruan Jian Xue Bao/Journal of Software, 2020, 31 (09): : 2756 - 2769
  • [2] Feature Denoising for Improving Adversarial Robustness
    Xie, Cihang
    Wu, Yuxin
    van der Maaten, Laurens
    Yuille, Alan
    He, Kaiming
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 501 - 509
  • [3] Bootstrap Feature Selection for Ensemble Classifiers
    Duangsoithong, Rakkrit
    Windeatt, Terry
    [J]. ADVANCES IN DATA MINING: APPLICATIONS AND THEORETICAL ASPECTS, 2010, 6171 : 28 - 41
  • [4] Unsupervised feature selection for ensemble of classifiers
    Morita, M
    Oliveira, LS
    Sabourin, R
    [J]. NINTH INTERNATIONAL WORKSHOP ON FRONTIERS IN HANDWRITING RECOGNITION, PROCEEDINGS, 2004, : 81 - 86
  • [5] Improving Ensemble Robustness by Collaboratively Promoting and Demoting Adversarial Robustness
    Anh Tuan Bui
    Trung Le
    Zhao, He
    Montague, Paul
    deVel, Olivier
    Abraham, Tamas
    Dinh Phung
    [J]. THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 6831 - 6839
  • [6] ON THE ADVERSARIAL ROBUSTNESS OF FEATURE SELECTION USING LASSO
    Li, Fuwei
    Lai, Lifeng
    Cui, Shuguang
    [J]. PROCEEDINGS OF THE 2020 IEEE 30TH INTERNATIONAL WORKSHOP ON MACHINE LEARNING FOR SIGNAL PROCESSING (MLSP), 2020,
  • [7] On the Adversarial Robustness of LASSO Based Feature Selection
    Li, Fuwei
    Lai, Lifeng
    Cui, Shuguang
    [J]. IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2021, 69 : 5555 - 5567
  • [8] Improving Adversarial Robustness via Promoting Ensemble Diversity
    Pang, Tianyu
    Xu, Kun
    Du, Chao
    Chen, Ning
    Zhu, Jun
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [9] Feature Selection and Ensemble of Classifiers for Android Malware Detection
    Coronado-De-Alba, Lilian D.
    Rodriguez-Mota, Abraham
    Escamilla-Ambrosio, Ponciano J.
    [J]. 2016 8TH IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS (LATINCOM), 2016,
  • [10] Hybrid Correlation and Causal Feature Selection for Ensemble Classifiers
    Duangsoithong, Rakkrit
    Windeatt, Terry
    [J]. ENSEMBLES IN MACHINE LEARNING APPLICATIONS, 2011, 373 : 97 - 115