Toward Intelligent Detection Modelling for Adversarial Samples in Convolutional Neural Networks

被引:0
|
作者
Qiao, Zhuobiao [1 ]
Dong, Mianxiong [2 ]
Ota, Kaoru [2 ]
Wu, Jun [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Elect Informat & Elect Engn, Shanghai, Peoples R China
[2] Muroran Inst Technol, Dept Informat & Elect Engn, Muroran, Hokkaido, Japan
基金
中国国家自然科学基金;
关键词
Adversarial samples; CNN attacks and detection; Large Margin Cosine Estimate;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Deep Neural Networks (DNNs) are hierarchical nonlinear architectures that have been widely used in artificial intelligence applications. However, these models are vulnerable to adversarial perturbations which add changes slightly and are crafted explicitly to fool the model. Such attacks will cause the neural network to completely change its classification of data. Although various defense strategies have been proposed, existing defense methods have two limitations. First, the discovery success rate is not very high. Second, existing methods depend on the output of a particular layer in a specific learning structure. In this paper, we propose a powerful method for adversarial samples using Large Margin Cosine Estimate(LMCE). By iteratively calculating the large-margin cosine uncertainty estimates between the model predictions, the results can be regarded as a novel measurement of model uncertainty estimation and is available to detect adversarial samples by training using a simple machine learning algorithm. Comparing it with the way in which adversarial samples are generated, it is confirmed that this measurement can better distinguish hostile disturbances. We modeled deep neural network attacks and established defense mechanisms against various types of adversarial attacks. Classifier gets better performance than the baseline model. The approach is validated on a series of standard datasets including MNIST and CIFAR-10, outperforming previous ensemble method with strong statistical significance. Experiments indicate that our approach generalizes better across different architectures and attacks.
引用
收藏
页码:74 / 79
页数:6
相关论文
共 50 条
  • [21] Object Detection and Recognition in Remote Sensing Images by Employing a Hybrid Generative Adversarial Networks and Convolutional Neural Networks
    Deshmukh, Araddhana Arvind
    Kumari, Mamta
    Krishnaiah, V. V. Jaya Rama
    Bandhekar, Shweta
    Dharani, R.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (09) : 621 - 632
  • [22] Intelligent System for Vehicles Number Plate Detection and Recognition Using Convolutional Neural Networks
    Nur-A-Alam
    Ahsan, Mominul
    Based, Md. Abdul
    Haider, Julfikar
    TECHNOLOGIES, 2021, 9 (01)
  • [23] Adversarial Robustness of Multi-bit Convolutional Neural Networks
    Frickenstein, Lukas
    Sampath, Shambhavi Balamuthu
    Mori, Pierpaolo
    Vemparala, Manoj-Rohit
    Fasfous, Nael
    Frickenstein, Alexander
    Unger, Christian
    Passerone, Claudio
    Stechele, Walter
    INTELLIGENT SYSTEMS AND APPLICATIONS, VOL 3, INTELLISYS 2023, 2024, 824 : 157 - 174
  • [24] Adversarial Robustness of Vision Transformers Versus Convolutional Neural Networks
    Ali, Kazim
    Bhatti, Muhammad Shahid
    Saeed, Atif
    Athar, Atifa
    Al Ghamdi, Mohammed A.
    Almotiri, Sultan H.
    Akram, Samina
    IEEE ACCESS, 2024, 12 : 105281 - 105293
  • [25] A Method Generating Adversarial Mark Based on Convolutional Neural Networks
    Deng, Zhengjie
    Liu, Meijun
    Li, Xiyan
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND NETWORKS, VOL II, CENET 2023, 2024, 1126 : 447 - 456
  • [26] ShuffleDetect: Detecting Adversarial Images against Convolutional Neural Networks
    Chitic, Raluca
    Topal, Ali Osman
    Leprevost, Franck
    APPLIED SCIENCES-BASEL, 2023, 13 (06):
  • [27] Deep Convolutional Generative Adversarial Network and Convolutional Neural Network for Smoke Detection
    Yin, Hang
    Wei, Yurong
    Liu, Hedan
    Liu, Shuangyin
    Liu, Chuanyun
    Gao, Yacui
    COMPLEXITY, 2020, 2020
  • [28] Guiding the retraining of convolutional neural networks against adversarial inputs
    Duran, Francisco
    Martinez-Fernandez, Silverio
    Felderer, Michael
    Franch, Xavier
    PEERJ COMPUTER SCIENCE, 2023, 9
  • [29] Explaining Adversarial Examples by Local Properties of Convolutional Neural Networks
    Aghdam, Hamed H.
    Heravi, Elnaz J.
    Puig, Domenec
    PROCEEDINGS OF THE 12TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER VISION, IMAGING AND COMPUTER GRAPHICS THEORY AND APPLICATIONS (VISIGRAPP 2017), VOL 5, 2017, : 226 - 234
  • [30] Convolutional neural networks for radar detection
    López-Risueño, G
    Grajal, J
    Haykin, S
    Díaz-Oliver, R
    ARTIFICIAL NEURAL NETWORKS - ICANN 2002, 2002, 2415 : 1150 - 1155