Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
機械学習とセキュリティ
Search
setten-QB
July 07, 2020
Science
8
1.9k
機械学習とセキュリティ
機械学習モデルへの攻撃とその対策についての概要
setten-QB
July 07, 2020
Tweet
Share
More Decks by setten-QB
See All by setten-QB
第4回 確率・統計の基礎勉強会
settenqb
0
160
確率・統計の基礎勉強会3
settenqb
0
250
確率・統計勉強会2
settenqb
0
160
確率・統計の基礎勉強会1
settenqb
1
260
Other Decks in Science
See All in Science
MCMCのR-hatは分散分析である
moricup
0
380
SpatialBiologyWestCoastUS2024
lcolladotor
0
140
地表面抽出の方法であるSMRFについて紹介
kentaitakura
1
760
CV_3_Keypoints
hachama
0
190
A Guide to Academic Writing Using Generative AI - A Workshop
ks91
PRO
0
120
データベース03: 関係データモデル
trycycle
PRO
1
120
テンソル分解による糖尿病の組織特異的遺伝子発現の統合解析を用いた関連疾患の予測
tagtag
2
200
Valuable Lessons Learned on Kaggle’s ARC AGI LLM Challenge (PyDataGlobal 2024)
ianozsvald
0
390
機械学習 - 授業概要
trycycle
PRO
0
210
Lean4による汎化誤差評価の形式化
milano0017
1
250
2025-06-11-ai_belgium
sofievl
1
130
データベース10: 拡張実体関連モデル
trycycle
PRO
0
720
Featured
See All Featured
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
31
1.3k
YesSQL, Process and Tooling at Scale
rocio
173
14k
Adopting Sorbet at Scale
ufuk
77
9.5k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
Git: the NoSQL Database
bkeepers
PRO
430
65k
Visualization
eitanlees
146
16k
Being A Developer After 40
akosma
90
590k
Why Our Code Smells
bkeepers
PRO
336
57k
Into the Great Unknown - MozCon
thekraken
40
1.9k
Music & Morning Musume
bryan
46
6.6k
GraphQLとの向き合い方2022年版
quramy
49
14k
Measuring & Analyzing Core Web Vitals
bluesmoon
7
510
Transcript
ػցֶशͱηΩϡϦςΟ ௨৴ࣄۀձࣾ ΄͛΄͛։ൃ෦ 2# !TFUUFO@2# %BUB4DJFODF$BGÉ!৽॓
ػցֶशºηΩϡϦςΟ Ø %PT߈ܸΛػցֶशͰݕ Ø ϚϧΣΞΛػցֶशͰݕ ػցֶशΛηΩϡϦςΟʹԠ༻ ػցֶशϞσϧࣗମͷηΩϡϦςΟ ػցֶशͰߏஙͨ͠ϞσϧʢػցֶशϞσϧʣΛΈࠐΜͩγεςϜͰ ैདྷͷγεςϜͱҟͳͬͨݻ༗ͷ߈ܸ͕ͳ͞ΕΔϦεΫ͕༗Δ ͦͷͨΊɼػցֶशϞσϧಛ༗ͷηΩϡϦςΟରࡦ͕ඞཁ
2
"EWFSTBSJBM"UUBDL ϞσϧΛὃ͢߈ܸ .PEFM&YUSBDUJPO ϞσϧΛ౪Ή߈ܸ .PEFM*OWFSTJPO ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ
None
"EWFSTBSJBM"UUBDL ܇࿅͞ΕͨػցֶशϞσϧΛὃ͢߈ܸ ݩͷը૾ ఢରతઁಈ "EWFSTBSJBM&YBNQMF ʢςφΨβϧʣ (PPEGFMMPX FUBM ΑΓҾ༻
5
ఢରతઁಈΛݟ͚ͭΔͨΊʹ argmin " , s.t. + ≠ argmin " ,
s.t. + = # ಛఆͷΫϥεʹޡྨͤ͞Δ͜ͱΛతͱͨ͠ "EWFSTBSJBM"UUBDL ޡྨͤ͞ΔΫϥεࢦఆͤͣ ͱʹ͔͘Ͳ͔͜ͷΫϥεʹޡྨͤ͞Δ͜ͱΛ తͱͨ͠"EWFSTBSJBM"UUBDL 6
දతͳ"EWFSTBSJBM"UUBDL (PPEGFMMPX FUBM !"# = + sign ∇ ℓ
, /PUBUJPO ɿઁಈڧʢͲΕ͙Β͍ઁಈΛڧ͘༩͑Δ͔Λද͢ʣ ℓɿଛࣦؔ 3FNBSL '(4.Ұͷޯ্ঢͰ࠷దԽΛऴྃ͢Δ͕ɼ͜ΕΛෳճʹ֦ுͨ͠ͷ͕#*.Ͱɼ CBMMʹऩ·ΔΑ͏ͳ੍ͷͱͰޯ্ঢΛ܁Γฦ͢ɽ '(4.#*.! ϊϧϜͰͷઁಈΛੜ͓ͯ͠Γɼ%FFQGPPM͜ͷϊϧϜΛ" ʹɼ $8# ʹͨ͠ͷͱݟΔ͜ͱ͕Ͱ͖Δɽ 7
8IJUF#PY4FUUJOHʹ͓͚Δఢରతઁಈͷݟ͚ͭํ '(4.BUUBDL (PPEGFMMPX FUBM #*. ,VSBLJO FUBM BUUBDL.*'(4.
%POHFUBM %FFQGPPM .PPTBWJ%F[GPPMJ FUBM /FXUPO'PPM +BOHFUBM +4." 1BQFSOPU FUBM (SBEJFOU #BTFE 0CKFDUJWF 'VODUJPO #BTFE $8 $BSMJOJ FUBM &"% $IFOFUBM 0QU.BSHJO 8BSSFOFUBM ˞8IJUF#PY4FUUJOHɿଛࣦؔͷޯ͕ܭࢉͰ͖ͨΓɼϞσϧͷDPOGJEFODFTDPSFΛΔ͜ͱ͕Ͱ͖Δઃఆ 8
"EWFSTBSJBM"UUBDLͷରࡦɿ"EWFSTBSJBM5SBJOJOH Ϟσϧͷֶश࣌ʹBEWFSTBSJBMFYBNQMFTͰl༧छz͓͚ͯ͠ BEWFSTBSJBMFYBNQMFTʹର͢Δϩόετੑ্͕ΔΜ͡Όͳ͍͔ʁ 9 ℓ!"# , () ≔ ℓ !"#,
!"# + 1 − ℓ , *EFB 3FTVMU n ࣮ࡍʹBEWFSTBSJBMFYBNQMFTʹର͢Δϩόετੑ্͢Δ ҰํͰʜ n ֶशʹཁ͢Δ͕࣌ؒ૿͑Δ n "EWFSTBSJBMFYBNQMFTͷϩόετੑBEWFSTBSJBMFYBNQMFTͷ࡞Γํʹґଘ͢Δ n ѱҙͷͳ͍ϊΠζ͕ͬͨը૾Λ͏·͘ྨͰ͖ͳ͘ͳΔ ͱ͍ͬͨൃੜ͢Δ
"EWFSTBSJBM"UUBDL ϞσϧΛὃ͢߈ܸ .PEFM&YUSBDUJPO ϞσϧΛ౪Ή߈ܸ .PEFM*OWFSTJPO ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ
.PEFM&YUSBDUJPOɿϞσϧΛ౪Ή & "SDIJUFDUVSF %FDJTJPO#PVOEBSZ 'VODUJPOBMJUZ ϨΠϠʔͷχϡʔϩϯͷ ͞Βʹ׆ੑԽؔͳͲͷ ϞσϧͷߏΛ౪ΉλΠϓ ϞσϧͷܾఆڥքΛ ౪ΉλΠϓ
ϞσϧʹΑΔ ೖྗͱग़ྗͷରԠؔΛ ౪ΉλΠϓ 11
.PEFM&YUSBDUJPOͷओཁͳΞϓϩʔν $ , $ $%& ' : ℝ( → ֶश
), ) )%& * +: ℝ( → ֶश 0SJHJOBM.PEFM 4VCTUJUVUF.PEFM "1*ʹΑͬͯฦ͞ΕΔ Λతมͱͯ͠ར༻͢Δ͜ͱͰཧϞσϧΛߏங͢Δɽ දతͳݚڀͱͯ͠$PSSFJB4JMWBFUBM 0SFLPOEZ FUBM ͕ڍ͛ΒΕΔɽ 12
4VCTUJUVUF.PEFMʹؔ͢Δ߈ %FGFODF 0GGFODF "1*ୟ͚ΔճΛ੍ݶ গͳ͍ԠճͰ 4VCTUJUVUF.PEFMΛߏங͢Δํ๏͕ఏҊ͞ΕΔ 0SFLPOEZ FUBM 3PTFOCFSHFUBM
13
"EWFSTBSJBM"UUBDL ϞσϧΛὃ͢߈ܸ .PEFM&YUSBDUJPO ϞσϧΛ౪Ή߈ܸ .PEFM*OWFSTJPO ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ
ʢٛͷʣ.PEFM*OWFSTJPO"UUBDL ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ 1SPQFSUZ*OGFSFODF"UUBDL .PEFM*OWFSTJPO"UUBDL దͳ ͕Ϟσϧͷֶशσʔληοτʹؚ·Ε͍ͯΔ͔ʁ Λ໌Β͔ʹ͢Δ߈ܸ ֶशσʔληοτʹؔ͢Δੑ࣭Λਪଌ͢Δ߈ܸ FH͕͍ਓυϨεΛண͍ͯΔਓ͕ ੑผྨͷϞσϧͷֶशσʔλʹؚ·Ε͍ͯΔ͔ʁ
ֶशσʔλΛ෮ݩ͢Δ߈ܸ ˞.PEFM*OWFSTJPO"UUBDLʹ.FNCFSTIJQ*OGFSFODF1SPQFSUZ*OGFSFODFΛؚΊΔ͔ʹॾઆ͋Γ 15
("/Λ༻͍ͨ.PEFM*OWFSTJPO ,VTBOP FUBM ิॿσʔληοτ ) , )%& * ,
, ∼$$( ℱ′ ֶशσʔληοτ $ , $ $%& ' , ∼$$( ℱ ΫΤϦ & ,, … * , Ԡ (& ,), … * , (FOFSBUPS Ͱ ℱ ʢͬΆ͍ͷʣΛۙࣅ αϯϓϦϯά (FOFSBUPS͔Β ֶशσʔλͬΆ͍ͷΛੜ 16
σʔλͷҰ෦͔ΒΓͷ෦Λ෮ݩ ֶशσʔλ ∈ ℝ( ͔ΒҰ෦ͷಛྔ͚ͩΛൈ͖ग़ͯ͠ ࡞ͨ͠ϕΫτϧ " ∈ ℝ-, <
͔Β ΓͷಛྔΛ෮ݩ͢Δ จͰ " ࿙Ӯͯ͠ͳ͍ηϯγςΟϒͰͳ͍ಛྔͰ ΓͷಛྔηϯγςΟϒͳಛྔͩͱఆ͍ͯ͠Δ ("/Λ༻͍ͨ.PEFM*OWFSTJPO ;IBOFUBM 17
͍ɼϜζ͘Ͷʜʁ ./*45Λֶशσʔλͱͨ͠ྨϞσϧʹରͯ͠.PEFM *OWFSTJPO"UUBDLΛߦͬͨ݁Ռ ิॿσʔλखॻ͖จࣈͷࣈͱΞϧϑΝϕοτ ࣮ࡍʹ෮ݩͯ͠Έͨ݁Ռ 18
None
ػցֶशϞσϧͷ߈ܸʹؔ͢Δݚڀ ͬͺΓ"EWFSTBSJBM"UUBDL͕μϯτπͳײ͡ ݚڀ͞ΕͯΔײ ֶशσʔλΛͯ͢෮ݩ͢ΔλΠϓͷ.PEFM*OWFSTJPO"UUBDL͕Ұ൪ͦ͠͏ ʢ࣮ࡍʹ͔ͬͨ͠ʣ ߈ܸͷ͠͞ n "EWFSTBSJBM"UUBDLσʔλ͕ߴ࣍ݩʹͳΔͱෆՄආతʹੜ͡ΔͨΊ ຊ࣭తʹରࡦ͕ࠔʁ n
.PEFM&YUSBDUJPO"UUBDLΫΤϦ੍ݶ͕༗ޮʹࢥ͑Δ͕ ΫΤϦ੍ݶͷͱͰ͋ΔఔͷϞσϧෳ͕ग़དྷ͓ͯΓ ࠓޙͷಈʹ ରࡦͷ͠͞ 20
3FGFSFODF (PPEGFMMPX *+ 4IMFOT + 4[FHFEZ $ &YQMBJOJOHBOEIBSOFTTJOHBEWFSTBSJBMFYBNQMFT BS9JW
QSFQSJOU BS9JW ,VSBLJO " (PPEGFMMPX * #FOHJP 4 "EWFSTBSJBMFYBNQMFTJOUIFQIZTJDBMXPSME BS9JW QSFQSJOU BS9JW %POH : -JBP ' 1BOH 5 4V ) ;IV + )V 9 -J + #PPTUJOHBEWFSTBSJBMBUUBDLTXJUINPNFOUVN *O 1SPDFFEJOHTPGUIF*&&&DPOGFSFODFPODPNQVUFSWJTJPOBOEQBUUFSOSFDPHOJUJPO QQ .PPTBWJ%F[GPPMJ 4. 'BX[J " 'SPTTBSE 1 %FFQGPPMBTJNQMFBOEBDDVSBUFNFUIPEUPGPPMEFFQ OFVSBMOFUXPSLT*O 1SPDFFEJOHTPGUIF*&&&DPOGFSFODFPODPNQVUFSWJTJPOBOEQBUUFSOSFDPHOJUJPO QQ +BOH 6 8V 9 +IB 4 %FDFNCFS 0CKFDUJWFNFUSJDTBOEHSBEJFOUEFTDFOUBMHPSJUINTGPSBEWFSTBSJBM FYBNQMFTJONBDIJOFMFBSOJOH*O 1SPDFFEJOHTPGUIFSE"OOVBM$PNQVUFS4FDVSJUZ"QQMJDBUJPOT $POGFSFODF QQ 1BQFSOPU / .D%BOJFM 1 +IB 4 'SFESJLTPO . $FMJL ;# 4XBNJ " .BSDI 5IFMJNJUBUJPOTPG EFFQMFBSOJOHJOBEWFSTBSJBMTFUUJOHT*O *&&&&VSPQFBOTZNQPTJVNPOTFDVSJUZBOEQSJWBDZ &VSP41 QQ *&&& $BSMJOJ / 8BHOFS % .BZ 5PXBSETFWBMVBUJOHUIFSPCVTUOFTTPGOFVSBMOFUXPSLT*O JFFF TZNQPTJVNPOTFDVSJUZBOEQSJWBDZ TQ QQ *&&& $IFO 1: 4IBSNB : ;IBOH ) :J + )TJFI $+ "QSJM &BEFMBTUJDOFUBUUBDLTUPEFFQOFVSBM OFUXPSLTWJBBEWFSTBSJBMFYBNQMFT*O 5IJSUZTFDPOE"""*DPOGFSFODFPOBSUJGJDJBMJOUFMMJHFODF 21
3FGFSFODF 8BSSFO ) #P - %BXO 4 %FDJTJPO#PVOEBSZ"OBMZTJTPG"EWFSTBSJBM&YBNQMFT*OUFSOBUJPOBM $POGFSFODFPG-FBSOJOH3FQSFTFOUBUJPOT
$PSSFJB4JMWB +3 #FSSJFM 3' #BEVF $ EF4PV[B "' 0MJWFJSB4BOUPT 5 +VMZ $PQZDBUDOO 4UFBMJOHLOPXMFEHFCZQFSTVBEJOHDPOGFTTJPOXJUISBOEPNOPOMBCFMFEEBUB*O *OUFSOBUJPOBM+PJOU $POGFSFODFPO/FVSBM/FUXPSLT *+$// QQ *&&& 0SFLPOEZ 5 4DIJFMF # 'SJU[ . ,OPDLPGGOFUT4UFBMJOHGVODUJPOBMJUZPGCMBDLCPYNPEFMT *O 1SPDFFEJOHTPGUIF*&&&$POGFSFODFPO$PNQVUFS7JTJPOBOE1BUUFSO3FDPHOJUJPO QQ 3PTFOCFSH * 4IBCUBJ " 3PLBDI - &MPWJDJ : 4FQUFNCFS (FOFSJDCMBDLCPYFOEUPFOEBUUBDL BHBJOTUTUBUFPGUIFBSU"1*DBMMCBTFENBMXBSFDMBTTJGJFST*O *OUFSOBUJPOBM4ZNQPTJVNPO3FTFBSDIJO"UUBDLT *OUSVTJPOT BOE%FGFOTFT QQ 4QSJOHFS $IBN ,VTBOP , 4BLVNB + $MBTTJGJFSUP(FOFSBUPS"UUBDL&TUJNBUJPOPG5SBJOJOH%BUB%JTUSJCVUJPOGSPN $MBTTJGJFS ;IBOH : +JB 3 1FJ ) 8BOH 8 -J # 4POH % 5IFTFDSFUSFWFBMFSHFOFSBUJWFNPEFMJOWFSTJPO BUUBDLTBHBJOTUEFFQOFVSBMOFUXPSLT*O 1SPDFFEJOHTPGUIF*&&&$7'$POGFSFODFPO$PNQVUFS7JTJPOBOE 1BUUFSO3FDPHOJUJPO QQ 22