跳到正文
原文
arXiv:cs.LG(机器学习,全量分类)· Melika Shirian, Kianoosh Vadaei·· 14 小时前AI 评分34

别浪费噪声:联合全局与局部约束下的重要性引导扰动分配

Don't Waste the Noise: Importance-Guided Perturbation Allocation under Joint Global and Local Constraints

AI 导读

研究提出一种重要性引导的扰动分配机制,利用固定的干净梯度先验,在共享 ℓ1 预算与局部幅度约束下将扰动导向模型敏感区域。在十组鲁棒模型—数据集配置中,该方法相比匹配的 APGD 和 PMA 基线将攻击成功率提升 2.52 至 17.70 个百分点,且未增加全局 ℓ1 消耗。消融实验显示,中心化非均匀重分配贡献了部分增益,模型导出的重要性带来额外提升。

正文

View PDF HTML (experimental)

Abstract:Adversarial optimization under a shared $\ell_1$ budget requires deciding not only how much perturbation to use, but also where that limited budget should be spent. This allocation problem becomes particularly important when individual input coordinates are subject to local magnitude constraints, which restrict the extent to which perturbation can be concentrated on a small number of locations. We introduce an importance-guided allocation mechanism that uses a fixed clean-gradient prior to steer perturbation toward model-sensitive regions while leaving the feasible perturbation set unchanged. A centered allocation objective encourages perturbation at above-average importance locations and discourages unnecessary expenditure elsewhere, thereby redistributing rather than enlarging the available budget. Across ten robust model--dataset configurations under a common capacity-limited threat setting, the proposed method improves attack success over matched APGD- and PMA-based baselines by $2.52$ to $17.70$ percentage points. Allocation analysis shows that these gains are accompanied by substantially greater perturbation mass in high-importance regions without increased global $\ell_1$ consumption. Mechanism ablations further show that centered non-uniform redistribution provides part of the benefit, while model-derived importance yields an additional improvement. These results identify perturbation allocation as a distinct and practically relevant dimension of adversarial optimization under shared-budget, locally constrained threat models.
Subjects: Machine Learning (cs.LG); Artificial Intelligence (cs.AI); Computer Vision and Pattern Recognition (cs.CV)
Cite as: arXiv:2610.00861 [cs.LG]
  (or arXiv:2610.00861v1 [cs.LG] for this version)
  https://doi.org/10.48550/arXiv.2610.00861

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Kianoosh Vadaei [view email]
[v1] Thu, 1 Oct 2026 00:25:15 UTC (9,163 KB)

来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org