Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
機械学習とセキュリティ
Search
setten-QB
July 07, 2020
Science
8
1.9k
機械学習とセキュリティ
機械学習モデルへの攻撃とその対策についての概要
setten-QB
July 07, 2020
Tweet
Share
More Decks by setten-QB
See All by setten-QB
第4回 確率・統計の基礎勉強会
settenqb
0
160
確率・統計の基礎勉強会3
settenqb
0
250
確率・統計勉強会2
settenqb
0
150
確率・統計の基礎勉強会1
settenqb
1
250
Other Decks in Science
See All in Science
多次元展開法を用いた 多値バイクラスタリング モデルの提案
kosugitti
0
230
Factorized Diffusion: Perceptual Illusions by Noise Decomposition
tomoaki0705
0
310
All-in-One Bioinformatics Platform Realized with Snowflake ~ From In Silico Drug Discovery, Disease Variant Analysis, to Single-Cell RNA-seq
ktatsuya
0
300
眼科AIコンテスト2024_特別賞_6位Solution
pon0matsu
0
270
2024-06-16-pydata_london
sofievl
0
600
オンプレミス環境にKubernetesを構築する
koukimiura
0
110
ACL読み会2024@名大 REANO: Optimising Retrieval-Augmented Reader Models through Knowledge Graph Generation
takuma_matsubara
0
140
02_西村訓弘_プログラムディレクター_人口減少を機にひらく未来社会.pdf
sip3ristex
0
120
学術講演会中央大学学員会大分支部
tagtag
0
120
機械学習を支える連続最適化
nearme_tech
PRO
1
240
240510 COGNAC LabChat
kazh
0
180
Improving Search @scale with efficient query experimentation @BerlinBuzzwords 2024
searchhub
0
270
Featured
See All Featured
A better future with KSS
kneath
238
17k
StorybookのUI Testing Handbookを読んだ
zakiyama
28
5.5k
Building an army of robots
kneath
303
45k
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
330
21k
Agile that works and the tools we love
rasmusluckow
328
21k
YesSQL, Process and Tooling at Scale
rocio
172
14k
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
21
2.5k
Typedesign – Prime Four
hannesfritz
40
2.5k
XXLCSS - How to scale CSS and keep your sanity
sugarenia
248
1.3M
Helping Users Find Their Own Way: Creating Modern Search Experiences
danielanewman
29
2.4k
Six Lessons from altMBA
skipperchong
27
3.6k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
32
2.1k
Transcript
ػցֶशͱηΩϡϦςΟ ௨৴ࣄۀձࣾ ΄͛΄͛։ൃ෦ 2# !TFUUFO@2# %BUB4DJFODF$BGÉ!৽॓
ػցֶशºηΩϡϦςΟ Ø %PT߈ܸΛػցֶशͰݕ Ø ϚϧΣΞΛػցֶशͰݕ ػցֶशΛηΩϡϦςΟʹԠ༻ ػցֶशϞσϧࣗମͷηΩϡϦςΟ ػցֶशͰߏஙͨ͠ϞσϧʢػցֶशϞσϧʣΛΈࠐΜͩγεςϜͰ ैདྷͷγεςϜͱҟͳͬͨݻ༗ͷ߈ܸ͕ͳ͞ΕΔϦεΫ͕༗Δ ͦͷͨΊɼػցֶशϞσϧಛ༗ͷηΩϡϦςΟରࡦ͕ඞཁ
2
"EWFSTBSJBM"UUBDL ϞσϧΛὃ͢߈ܸ .PEFM&YUSBDUJPO ϞσϧΛ౪Ή߈ܸ .PEFM*OWFSTJPO ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ
None
"EWFSTBSJBM"UUBDL ܇࿅͞ΕͨػցֶशϞσϧΛὃ͢߈ܸ ݩͷը૾ ఢରతઁಈ "EWFSTBSJBM&YBNQMF ʢςφΨβϧʣ (PPEGFMMPX FUBM ΑΓҾ༻
5
ఢରతઁಈΛݟ͚ͭΔͨΊʹ argmin " , s.t. + ≠ argmin " ,
s.t. + = # ಛఆͷΫϥεʹޡྨͤ͞Δ͜ͱΛతͱͨ͠ "EWFSTBSJBM"UUBDL ޡྨͤ͞ΔΫϥεࢦఆͤͣ ͱʹ͔͘Ͳ͔͜ͷΫϥεʹޡྨͤ͞Δ͜ͱΛ తͱͨ͠"EWFSTBSJBM"UUBDL 6
දతͳ"EWFSTBSJBM"UUBDL (PPEGFMMPX FUBM !"# = + sign ∇ ℓ
, /PUBUJPO ɿઁಈڧʢͲΕ͙Β͍ઁಈΛڧ͘༩͑Δ͔Λද͢ʣ ℓɿଛࣦؔ 3FNBSL '(4.Ұͷޯ্ঢͰ࠷దԽΛऴྃ͢Δ͕ɼ͜ΕΛෳճʹ֦ுͨ͠ͷ͕#*.Ͱɼ CBMMʹऩ·ΔΑ͏ͳ੍ͷͱͰޯ্ঢΛ܁Γฦ͢ɽ '(4.#*.! ϊϧϜͰͷઁಈΛੜ͓ͯ͠Γɼ%FFQGPPM͜ͷϊϧϜΛ" ʹɼ $8# ʹͨ͠ͷͱݟΔ͜ͱ͕Ͱ͖Δɽ 7
8IJUF#PY4FUUJOHʹ͓͚Δఢରతઁಈͷݟ͚ͭํ '(4.BUUBDL (PPEGFMMPX FUBM #*. ,VSBLJO FUBM BUUBDL.*'(4.
%POHFUBM %FFQGPPM .PPTBWJ%F[GPPMJ FUBM /FXUPO'PPM +BOHFUBM +4." 1BQFSOPU FUBM (SBEJFOU #BTFE 0CKFDUJWF 'VODUJPO #BTFE $8 $BSMJOJ FUBM &"% $IFOFUBM 0QU.BSHJO 8BSSFOFUBM ˞8IJUF#PY4FUUJOHɿଛࣦؔͷޯ͕ܭࢉͰ͖ͨΓɼϞσϧͷDPOGJEFODFTDPSFΛΔ͜ͱ͕Ͱ͖Δઃఆ 8
"EWFSTBSJBM"UUBDLͷରࡦɿ"EWFSTBSJBM5SBJOJOH Ϟσϧͷֶश࣌ʹBEWFSTBSJBMFYBNQMFTͰl༧छz͓͚ͯ͠ BEWFSTBSJBMFYBNQMFTʹର͢Δϩόετੑ্͕ΔΜ͡Όͳ͍͔ʁ 9 ℓ!"# , () ≔ ℓ !"#,
!"# + 1 − ℓ , *EFB 3FTVMU n ࣮ࡍʹBEWFSTBSJBMFYBNQMFTʹର͢Δϩόετੑ্͢Δ ҰํͰʜ n ֶशʹཁ͢Δ͕࣌ؒ૿͑Δ n "EWFSTBSJBMFYBNQMFTͷϩόετੑBEWFSTBSJBMFYBNQMFTͷ࡞Γํʹґଘ͢Δ n ѱҙͷͳ͍ϊΠζ͕ͬͨը૾Λ͏·͘ྨͰ͖ͳ͘ͳΔ ͱ͍ͬͨൃੜ͢Δ
"EWFSTBSJBM"UUBDL ϞσϧΛὃ͢߈ܸ .PEFM&YUSBDUJPO ϞσϧΛ౪Ή߈ܸ .PEFM*OWFSTJPO ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ
.PEFM&YUSBDUJPOɿϞσϧΛ౪Ή & "SDIJUFDUVSF %FDJTJPO#PVOEBSZ 'VODUJPOBMJUZ ϨΠϠʔͷχϡʔϩϯͷ ͞Βʹ׆ੑԽؔͳͲͷ ϞσϧͷߏΛ౪ΉλΠϓ ϞσϧͷܾఆڥքΛ ౪ΉλΠϓ
ϞσϧʹΑΔ ೖྗͱग़ྗͷରԠؔΛ ౪ΉλΠϓ 11
.PEFM&YUSBDUJPOͷओཁͳΞϓϩʔν $ , $ $%& ' : ℝ( → ֶश
), ) )%& * +: ℝ( → ֶश 0SJHJOBM.PEFM 4VCTUJUVUF.PEFM "1*ʹΑͬͯฦ͞ΕΔ Λతมͱͯ͠ར༻͢Δ͜ͱͰཧϞσϧΛߏங͢Δɽ දతͳݚڀͱͯ͠$PSSFJB4JMWBFUBM 0SFLPOEZ FUBM ͕ڍ͛ΒΕΔɽ 12
4VCTUJUVUF.PEFMʹؔ͢Δ߈ %FGFODF 0GGFODF "1*ୟ͚ΔճΛ੍ݶ গͳ͍ԠճͰ 4VCTUJUVUF.PEFMΛߏங͢Δํ๏͕ఏҊ͞ΕΔ 0SFLPOEZ FUBM 3PTFOCFSHFUBM
13
"EWFSTBSJBM"UUBDL ϞσϧΛὃ͢߈ܸ .PEFM&YUSBDUJPO ϞσϧΛ౪Ή߈ܸ .PEFM*OWFSTJPO ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ
ʢٛͷʣ.PEFM*OWFSTJPO"UUBDL ֶशσʔλʹؔ͢ΔใΛ෮ݩ͢Δ߈ܸ 1SPQFSUZ*OGFSFODF"UUBDL .PEFM*OWFSTJPO"UUBDL దͳ ͕Ϟσϧͷֶशσʔληοτʹؚ·Ε͍ͯΔ͔ʁ Λ໌Β͔ʹ͢Δ߈ܸ ֶशσʔληοτʹؔ͢Δੑ࣭Λਪଌ͢Δ߈ܸ FH͕͍ਓυϨεΛண͍ͯΔਓ͕ ੑผྨͷϞσϧͷֶशσʔλʹؚ·Ε͍ͯΔ͔ʁ
ֶशσʔλΛ෮ݩ͢Δ߈ܸ ˞.PEFM*OWFSTJPO"UUBDLʹ.FNCFSTIJQ*OGFSFODF1SPQFSUZ*OGFSFODFΛؚΊΔ͔ʹॾઆ͋Γ 15
("/Λ༻͍ͨ.PEFM*OWFSTJPO ,VTBOP FUBM ิॿσʔληοτ ) , )%& * ,
, ∼$$( ℱ′ ֶशσʔληοτ $ , $ $%& ' , ∼$$( ℱ ΫΤϦ & ,, … * , Ԡ (& ,), … * , (FOFSBUPS Ͱ ℱ ʢͬΆ͍ͷʣΛۙࣅ αϯϓϦϯά (FOFSBUPS͔Β ֶशσʔλͬΆ͍ͷΛੜ 16
σʔλͷҰ෦͔ΒΓͷ෦Λ෮ݩ ֶशσʔλ ∈ ℝ( ͔ΒҰ෦ͷಛྔ͚ͩΛൈ͖ग़ͯ͠ ࡞ͨ͠ϕΫτϧ " ∈ ℝ-, <
͔Β ΓͷಛྔΛ෮ݩ͢Δ จͰ " ࿙Ӯͯ͠ͳ͍ηϯγςΟϒͰͳ͍ಛྔͰ ΓͷಛྔηϯγςΟϒͳಛྔͩͱఆ͍ͯ͠Δ ("/Λ༻͍ͨ.PEFM*OWFSTJPO ;IBOFUBM 17
͍ɼϜζ͘Ͷʜʁ ./*45Λֶशσʔλͱͨ͠ྨϞσϧʹରͯ͠.PEFM *OWFSTJPO"UUBDLΛߦͬͨ݁Ռ ิॿσʔλखॻ͖จࣈͷࣈͱΞϧϑΝϕοτ ࣮ࡍʹ෮ݩͯ͠Έͨ݁Ռ 18
None
ػցֶशϞσϧͷ߈ܸʹؔ͢Δݚڀ ͬͺΓ"EWFSTBSJBM"UUBDL͕μϯτπͳײ͡ ݚڀ͞ΕͯΔײ ֶशσʔλΛͯ͢෮ݩ͢ΔλΠϓͷ.PEFM*OWFSTJPO"UUBDL͕Ұ൪ͦ͠͏ ʢ࣮ࡍʹ͔ͬͨ͠ʣ ߈ܸͷ͠͞ n "EWFSTBSJBM"UUBDLσʔλ͕ߴ࣍ݩʹͳΔͱෆՄආతʹੜ͡ΔͨΊ ຊ࣭తʹରࡦ͕ࠔʁ n
.PEFM&YUSBDUJPO"UUBDLΫΤϦ੍ݶ͕༗ޮʹࢥ͑Δ͕ ΫΤϦ੍ݶͷͱͰ͋ΔఔͷϞσϧෳ͕ग़དྷ͓ͯΓ ࠓޙͷಈʹ ରࡦͷ͠͞ 20
3FGFSFODF (PPEGFMMPX *+ 4IMFOT + 4[FHFEZ $ &YQMBJOJOHBOEIBSOFTTJOHBEWFSTBSJBMFYBNQMFT BS9JW
QSFQSJOU BS9JW ,VSBLJO " (PPEGFMMPX * #FOHJP 4 "EWFSTBSJBMFYBNQMFTJOUIFQIZTJDBMXPSME BS9JW QSFQSJOU BS9JW %POH : -JBP ' 1BOH 5 4V ) ;IV + )V 9 -J + #PPTUJOHBEWFSTBSJBMBUUBDLTXJUINPNFOUVN *O 1SPDFFEJOHTPGUIF*&&&DPOGFSFODFPODPNQVUFSWJTJPOBOEQBUUFSOSFDPHOJUJPO QQ .PPTBWJ%F[GPPMJ 4. 'BX[J " 'SPTTBSE 1 %FFQGPPMBTJNQMFBOEBDDVSBUFNFUIPEUPGPPMEFFQ OFVSBMOFUXPSLT*O 1SPDFFEJOHTPGUIF*&&&DPOGFSFODFPODPNQVUFSWJTJPOBOEQBUUFSOSFDPHOJUJPO QQ +BOH 6 8V 9 +IB 4 %FDFNCFS 0CKFDUJWFNFUSJDTBOEHSBEJFOUEFTDFOUBMHPSJUINTGPSBEWFSTBSJBM FYBNQMFTJONBDIJOFMFBSOJOH*O 1SPDFFEJOHTPGUIFSE"OOVBM$PNQVUFS4FDVSJUZ"QQMJDBUJPOT $POGFSFODF QQ 1BQFSOPU / .D%BOJFM 1 +IB 4 'SFESJLTPO . $FMJL ;# 4XBNJ " .BSDI 5IFMJNJUBUJPOTPG EFFQMFBSOJOHJOBEWFSTBSJBMTFUUJOHT*O *&&&&VSPQFBOTZNQPTJVNPOTFDVSJUZBOEQSJWBDZ &VSP41 QQ *&&& $BSMJOJ / 8BHOFS % .BZ 5PXBSETFWBMVBUJOHUIFSPCVTUOFTTPGOFVSBMOFUXPSLT*O JFFF TZNQPTJVNPOTFDVSJUZBOEQSJWBDZ TQ QQ *&&& $IFO 1: 4IBSNB : ;IBOH ) :J + )TJFI $+ "QSJM &BEFMBTUJDOFUBUUBDLTUPEFFQOFVSBM OFUXPSLTWJBBEWFSTBSJBMFYBNQMFT*O 5IJSUZTFDPOE"""*DPOGFSFODFPOBSUJGJDJBMJOUFMMJHFODF 21
3FGFSFODF 8BSSFO ) #P - %BXO 4 %FDJTJPO#PVOEBSZ"OBMZTJTPG"EWFSTBSJBM&YBNQMFT*OUFSOBUJPOBM $POGFSFODFPG-FBSOJOH3FQSFTFOUBUJPOT
$PSSFJB4JMWB +3 #FSSJFM 3' #BEVF $ EF4PV[B "' 0MJWFJSB4BOUPT 5 +VMZ $PQZDBUDOO 4UFBMJOHLOPXMFEHFCZQFSTVBEJOHDPOGFTTJPOXJUISBOEPNOPOMBCFMFEEBUB*O *OUFSOBUJPOBM+PJOU $POGFSFODFPO/FVSBM/FUXPSLT *+$// QQ *&&& 0SFLPOEZ 5 4DIJFMF # 'SJU[ . ,OPDLPGGOFUT4UFBMJOHGVODUJPOBMJUZPGCMBDLCPYNPEFMT *O 1SPDFFEJOHTPGUIF*&&&$POGFSFODFPO$PNQVUFS7JTJPOBOE1BUUFSO3FDPHOJUJPO QQ 3PTFOCFSH * 4IBCUBJ " 3PLBDI - &MPWJDJ : 4FQUFNCFS (FOFSJDCMBDLCPYFOEUPFOEBUUBDL BHBJOTUTUBUFPGUIFBSU"1*DBMMCBTFENBMXBSFDMBTTJGJFST*O *OUFSOBUJPOBM4ZNQPTJVNPO3FTFBSDIJO"UUBDLT *OUSVTJPOT BOE%FGFOTFT QQ 4QSJOHFS $IBN ,VTBOP , 4BLVNB + $MBTTJGJFSUP(FOFSBUPS"UUBDL&TUJNBUJPOPG5SBJOJOH%BUB%JTUSJCVUJPOGSPN $MBTTJGJFS ;IBOH : +JB 3 1FJ ) 8BOH 8 -J # 4POH % 5IFTFDSFUSFWFBMFSHFOFSBUJWFNPEFMJOWFSTJPO BUUBDLTBHBJOTUEFFQOFVSBMOFUXPSLT*O 1SPDFFEJOHTPGUIF*&&&$7'$POGFSFODFPO$PNQVUFS7JTJPOBOE 1BUUFSO3FDPHOJUJPO QQ 22