TY - JOUR
T1 - Optimization Models and Interpretations for Adversarial Perturbations against Support Vector Machines
AU - Su, Wen
AU - Shen, Ya
AU - Cui, Chunfeng
AU - Li, Qingna
N1 - Publisher Copyright:
© World Scientific Publishing Co. & Operational Research Society of Singapore.
PY - 2026
Y1 - 2026
N2 - Adversarial perturbations have drawn great attention in various deep learning methods. However, little attention is paid to basic machine learning models such as support vector machines. In this paper, we investigate the optimization models and the interpretations for adversarial perturbations against linear support vector machines, including class-universal adversarial perturbations (cuAP) and universal adversarial perturbations (uAP). Unlike most of adversarial perturbations which are computed by iterative algorithms and cannot be interpreted very well, we derive explicit solutions for cuAP and uAP of binary case, and approximate solutions for cuAP and uAP of multiclassification case, respectively. We also obtain the upper bound of fooling rate for uAP. Such results not only increase the interpretability of these adversarial perturbations, but also provide great convenience in computation since iterative process can be avoided. Numerical results show that our method is fast and effective in calculating adversarial perturbations, based on which one can efficiently improve the robustness of the training model.
AB - Adversarial perturbations have drawn great attention in various deep learning methods. However, little attention is paid to basic machine learning models such as support vector machines. In this paper, we investigate the optimization models and the interpretations for adversarial perturbations against linear support vector machines, including class-universal adversarial perturbations (cuAP) and universal adversarial perturbations (uAP). Unlike most of adversarial perturbations which are computed by iterative algorithms and cannot be interpreted very well, we derive explicit solutions for cuAP and uAP of binary case, and approximate solutions for cuAP and uAP of multiclassification case, respectively. We also obtain the upper bound of fooling rate for uAP. Such results not only increase the interpretability of these adversarial perturbations, but also provide great convenience in computation since iterative process can be avoided. Numerical results show that our method is fast and effective in calculating adversarial perturbations, based on which one can efficiently improve the robustness of the training model.
KW - Universal adversarial perturbation
KW - class-universal adversarial perturbation
KW - linear support vector machines
KW - support vector machines
UR - https://www.scopus.com/pages/publications/105031407213
U2 - 10.1142/S0217595926500065
DO - 10.1142/S0217595926500065
M3 - Article
AN - SCOPUS:105031407213
SN - 0217-5959
JO - Asia-Pacific Journal of Operational Research
JF - Asia-Pacific Journal of Operational Research
M1 - 2650006
ER -