LanCeX: A Versatile and Lightweight Defense Method against Condensed Adversarial Attacks in Image and Audio Recognition

被引:0
|
作者
Xu, Zirui [1 ]
Yu, Fuxun [1 ]
Liu, Chenchen [2 ]
Chen, Xiang [1 ]
机构
[1] George Mason Univ, Fairfax, VA 22030 USA
[2] Univ Maryland Baltimore Cty, 1000 Hilltop Cir, Baltimore, MD 21250 USA
关键词
Convolutional Neural Networks (CNNs); physical adversarial attack; image classification; voice recognition; object detection;
D O I
10.1145/3555375
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Convolutional Neural Networks (CNNs) are widely deployed in various embedded recognition applications. However, they demonstrate a considerable vulnerability to adversarial attacks, which leverage the welldesigned perturbations to mislead the recognition results. Recently, for easier perturbation injection and higher attack effectiveness, the adversarial perturbations have been concentrated into a small area with various types and different data modalities. When defending such condensed adversarial attacks on the embedded recognition scenarios, most of the existing defense works highlight two critical issues. First, they are particularly designed for each individual condensed attack scenario, lacking enough versatility to accommodate attacks with different data modalities. Second, they rely on computation-intensive preprocessing techniques, which is impractical for time-sensitive embedded recognition scenarios. In this article, we propose LanCeXa versatile and lightweight CNN defense solution against condensed adversarial attacks. By examining the CNN's intrinsic vulnerability, we first identify the common attacking mechanism behind condensed adversarial attacks across different data modalities. Based on this mechanism, LanCeX can defend against various condensed attacks with the optimal computation workload in different recognition scenarios. Experiments show that LanCeX can achieve an average 91%, 85%, and 90% detection success rate and optimal adversarial mitigation performance in three recognition scenarios, respectively: image classification, object detection, and audio recognition. Moreover, LanCeX is at most 3x faster compared with the state-of-the-art defense methods, making it feasible to use with resource-constrained embedded systems.
引用
收藏
页数:24
相关论文
共 50 条
  • [1] Defense against Adversarial Attacks on Image Recognition Systems Using an Autoencoder
    Platonov, V. V.
    Grigorjeva, N. M.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2023, 57 (08) : 989 - 995
  • [2] Defense against Adversarial Attacks in Image Recognition Based on Multilayer Filters
    Wang, Mingde
    Liu, Zhijing
    APPLIED SCIENCES-BASEL, 2024, 14 (18):
  • [3] Defense against Adversarial Attacks on Image Recognition Systems Using an Autoencoder
    V. V. Platonov
    N. M. Grigorjeva
    Automatic Control and Computer Sciences, 2023, 57 : 989 - 995
  • [4] Defense Against Adversarial Attacks on Audio DeepFake Detection
    Kawa, Piotr
    Plata, Marcin
    Syga, Piotr
    INTERSPEECH 2023, 2023, : 5276 - 5280
  • [5] Deep Image Restoration Model: A Defense Method Against Adversarial Attacks
    Ali, Kazim
    Quershi, Adnan N.
    Bin Arifin, Ahmad Alauddin
    Bhatti, Muhammad Shahid
    Sohail, Abid
    Hassan, Rohail
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 71 (02): : 2209 - 2224
  • [6] A Defense Method Against Facial Adversarial Attacks
    Sadu, Chiranjeevi
    Das, Pradip K.
    2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 459 - 463
  • [7] Adaptive Image Reconstruction for Defense Against Adversarial Attacks
    Yang, Yanan
    Shih, Frank Y.
    Chang, I-Cheng
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2022, 36 (12)
  • [8] A Lightweight Method for Defense Graph Neural Networks Adversarial Attacks
    Qiao, Zhi
    Wu, Zhenqiang
    Chen, Jiawang
    Ren, Ping'an
    Yu, Zhiliang
    ENTROPY, 2023, 25 (01)
  • [9] A Novel Lightweight Defense Method Against Adversarial Patches-Based Attacks on Automated Vehicle Make and Model Recognition Systems
    Siddiqui, Abdul Jabbar
    Boukerche, Azzedine
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2021, 29 (04)
  • [10] A Novel Lightweight Defense Method Against Adversarial Patches-Based Attacks on Automated Vehicle Make and Model Recognition Systems
    Abdul Jabbar Siddiqui
    Azzedine Boukerche
    Journal of Network and Systems Management, 2021, 29