Font Size: a A A

Research On Defense Methods Adversarial Sample Based On The Physical Mechanism Of Deep Neural Networks

Posted on:2024-08-14Degree:MasterType:Thesis
Country:ChinaCandidate:W L QiuFull Text:PDF
GTID:2568307097463094Subject:Electronic information
Abstract/Summary:
Deep Neural Networks(DNN)have achieved remarkable success in various fields,yet adversarial attacks have raised doubts about the reliability and credibility of DNN in realworld applications.Adversarial attacks manipulate models to produce inaccurate predictions by adding carefully crafted,tiny perturbations to the original input data.In recent years,research on adversarial examples in DNN has been thriving.Revealing and addressing these issues contribute to improving the security and usability of DNN and deepening researchers’ understanding of neural network mechanisms and properties.Therefore,this article studies the physical mechanism of DNN and the causes of adversarial sample problems,and proposes defense methods for adversarial samples based on this.The research work is as follows:(1)To address the lack of a theoretical foundation for DNN,hindering the study of neural network properties,we construct a DNN theoretical framework based on statistical mechanics and quantum mechanics.We first propose the Gaussian wave packet hypothesis,establishing a physical mapping from sample data to neuron input states,treating the training and prediction processes of neural networks as energy dissipation processes of an Ising model.We then establish the Schrodinger equation for neural networks and derive a physically meaningful learning framework.Finally,we validate the effectiveness of the theoretical framework through experiments.(2)Concerning the cause of adversarial examples,we analyze the origin of adversarial issues in neural networks based on the Schrodinger image description method.Adversarial examples essentially fine-tune the distribution of normal samples in the test set,leading the model to provide an incorrect output with high confidence.Based on the Gaussian wave packet hypothesis,this fine-tuning is equivalent to transforming the wave function describing the normal sample distribution with a transformation Q,which does not commute with the Hamiltonian H of the sample set.(3)We propose a detection method for adversarial attacks based on the Heisenberg uncertainty principle.Adversarial examples are a unique class of samples distributed in narrow regions,with significant differences in categories compared to neighboring samples.According to the Heisenberg uncertainty principle,when particles move in regions with smaller distribution widths,their energy in the potential field varies in regions with larger distribution widths.Consequently,the loss function values of samples near the adversarial examples exhibit significant differences.Based on this characteristic,we propose a gradient-based adversarial example detection method.This method is applicable to any pretrained neural network classifier and has been proven effective and accurate by comparing it to multiple detection methods on three common datasets.
Keywords/Search Tags:Adversarial Examples, Deep Neural Networks, Schrodinger Equation, Heisenberg Uncertainty Principle
Related items