Wen Su, Yandi Shen, Chunfeng Cui, Qingna Li
tlooto Summary
Numerical results show that the optimization models and the interpretations for adversarial perturbations against linear support vector machines, including class-universal adversarial perturbations (cuAP) and universal adversarial perturbations (uAP), are fast and effective.
Abstract
Adversarial perturbations have drawn great attention in various deep learning methods. However, little attention is paid to basic machine learning models such as support vector machines. In this paper, we investigate the optimization models and the interpretations for adversarial perturbations against linear support vector machines, including class-universal adversarial perturbations (cuAP) and universal adversarial perturbations (uAP). Unlike most of adversarial perturbations which are computed by iterative algorithms and cannot be interpreted very well, we derive explicit solutions for cuAP and uAP of binary case, and approximate solutions for cuAP and uAP of multi-classification case, respectively. We also obtain the upper bound of fooling rate for uAP. Such results not only increase the interpretability of these adversarial perturbations, but also provide great convenience in computation since iterative process can be avoided. Numerical results show that our method is fast and effective in calculating adversarial perturbations, based on which one can efficiently improve the robustness of the training model.
Citation format
SU, Wen, et al. Optimization models and interpretations for adversarial perturbations against support vector machines. ASIA-PACIFIC JOURNAL OF OPERATIONAL RESEARCH, 2026.