Dynamic Analysis of Adversarial Attacks
Kentaro Goto, Masato Uchida · 2023
This study proposes a method called “dynamic analysis” as the first step to defend against adversarial attacks, a significant vulnerability in machine learning. The method involves using actual attack methods as “samples” and observing the success or failure of attacks on each sample unit to reveal the characteristics of attack methods. Through dynamic analysis, the micro-behaviour observed can be considered essentially equivalent, even if different algorithms have different designs and intentions. The findings of the study indicate that (1) the superiority or similarity of attack methods varies depending on their combination with defense methods, (2) the strength of recently proposed attack methods is not guaranteed, as some of the early-generation attack methods remain potent, and (3) the superiority of attack methods depends on their success in attacking samples that are far from the decision boundary.