AdvEx: Interactive Visual Explorations of Adversarial Evasion Attacks
dc.contributor.author | You, Yuzhe | |
dc.date.accessioned | 2023-06-28T20:11:22Z | |
dc.date.available | 2024-06-28T04:50:04Z | |
dc.date.issued | 2023-06-28 | |
dc.date.submitted | 2023-06-20 | |
dc.description.abstract | Adversarial machine learning (AML) focuses on studying attacks that can fool machine learning algorithms into generating incorrect outcomes as well as the defenses against worst-case attacks to strengthen the adversarial robustness of machine learning models. Specifically for image classification tasks, it is difficult to comprehend the underlying logic behind adversarial attacks due to two key challenges: 1) the attacks exploiting “non-robust” features that are not human-interpretable and 2) the perturbations applied being almost imperceptible to human eyes. We propose an interactive visualization system, AdvEx, that presents the properties and consequences of evasion attacks as well as provides data and model performance analytics on both instance and population levels. We quantitatively and qualitatively assessed AdvEx in a two-part evaluation including user studies and expert interviews. Our results show that AdvEx is effective both as an educational tool for understanding AML mechanisms and a visual analytics tool for inspecting machine learning models, which can benefit both AML learners and experienced practitioners. | en |
dc.identifier.uri | http://hdl.handle.net/10012/19592 | |
dc.language.iso | en | en |
dc.pending | false | |
dc.publisher | University of Waterloo | en |
dc.subject | information visualization | en |
dc.subject | explainable AI | en |
dc.subject | adversarial attacks | en |
dc.subject | machine learning | en |
dc.title | AdvEx: Interactive Visual Explorations of Adversarial Evasion Attacks | en |
dc.type | Master Thesis | en |
uws-etd.degree | Master of Mathematics | en |
uws-etd.degree.department | David R. Cheriton School of Computer Science | en |
uws-etd.degree.discipline | Computer Science | en |
uws-etd.degree.grantor | University of Waterloo | en |
uws-etd.embargo.terms | 1 year | en |
uws.contributor.advisor | Zhao, Jian | |
uws.contributor.affiliation1 | Faculty of Mathematics | en |
uws.peerReviewStatus | Unreviewed | en |
uws.published.city | Waterloo | en |
uws.published.country | Canada | en |
uws.published.province | Ontario | en |
uws.scholarLevel | Graduate | en |
uws.typeOfResource | Text | en |