Yuval Elovici

Senior Academic

Analysing the Adversarial Landscape of Binary Stochastic Networks

Yi Xiang Marcus Tan, Yuval Elovici, Alexander Binder

We investigate the robustness of stochastic ANNs to adversarial attacks. We perform experiments on three known datasets. Our experiments reveal similar susceptibility of stochastic ANNs compared to conventional ANNs when confronted with simple iterative gradient-based attacks in the white-box settings. We observe, however, that in black-box settings, SANNs are more robust than conventional ANNs against boundary and surrogate attacks. Consequently, we propose improved attacks against stochastic ANNs. In the first step, we show that using stochastic networks as surrogates outperforms deterministic ones, when performing surrogate-based black-box attacks. In order to further boost adversarial success rates, we propose in a second step the novel Variance Mimicking (VM) surrogate training, and validate its improved performance.

Publication language English
Pages 143-155
Publication status Published - 01.01.2021

Keywords

Adversarial machine learning
Binary neural network
Black-box attack
Stochastic neural network

ASJC Scopus subject areas

Industrial and Manufacturing Engineering