arXiv:cs.LG(机器学习,全量分类)· Parker Hummel (Minot State University), Ryne Skabo (Minot State University), Muhammad Abusaqer (Minot State University)·· 14 小时前AI 评分22
规避攻击:对抗噪声如何绕过 ML 分类器
Evasion Attacks: How Adversarial Noise Bypasses ML Classifiers
AI 导读
一项可复现的教育性研究测试了图像与文本分类中的规避攻击。在 MNIST 上训练的紧凑卷积网络干净测试准确率为 98.63%,FGSM 攻击下 ε=0.15 时降至 60.20%、ε=0.30 时降至 1.72%,PGD 攻击下降至 32.47% 和 0.41%,位深缩减防御仅挽回部分损失。
正文
Abstract:This paper presents a reproducible, educational study of evasion attacks in image classification and text classification. A compact convolutional network trained on MNIST reached 98.63% clean test accuracy and was evaluated under two white-box attacks. Under FGSM, accuracy fell to 60.20% at $\epsilon$ = 0.15 and 1.72% at $\epsilon$ = 0.30; under PGD it fell to 32.47% and 0.41%, and a bit-depth-reduction defense recovered only part of the loss. In the second experiment, DistilBERT fine-tuned on the SMS Spam Collection reached 98.75% accuracy and a 94.96% F1-score, but a controlled sequence of pre-defined perturbations (character substitutions, whitespace noise, and a benign suffix) produced only modest probability shifts in most displayed examples and no flip from spam to ham. Adversarial vulnerability is strongly modality-dependent: the MNIST experiment is a clear evasion demonstration, whereas the text experiment is a controlled robustness evaluation. Robustness must be tested empirically rather than inferred from clean accuracy.
| Comments: | Presented at the 58th Midwest Instruction and Computing Symposium (MICS 2026), Eau Claire, WI, March 27 to 28, 2026. 14 pages, 7 figures, 4 tables |
| Subjects: | Cryptography and Security (cs.CR); Computation and Language (cs.CL); Machine Learning (cs.LG) |
| ACM classes: | K.6.5; I.2.6; I.2.7 |
| Cite as: | arXiv:2610.00136 [cs.CR] |
| (or arXiv:2610.00136v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.00136 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Muhammad Abusaqer [view email]
[v1]
Thu, 10 Sep 2026 01:22:43 UTC (905 KB)
来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org