MTDeep: Boosting the Security of Deep Neural Nets Against Adversarial Attacks with Moving Target Defense

被引:24
|
作者
Sengupta, Sailik [1 ]
Chakraborti, Tathagata [2 ]
Kambhampati, Subbarao [1 ]
机构
[1] Arizona State Univ, Tempe, AZ 85281 USA
[2] IBM Res, Cambridge, MA USA
来源
关键词
D O I
10.1007/978-3-030-32430-8_28
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Present attack methods can make state-of-the-art classification systems based on deep neural networks mis-classify every adversarially modified test example. The design of general defense strategies against a wide range of such attacks still remains a challenging problem. In this paper, we draw inspiration from the fields of cybersecurity and multi-agent systems and propose to leverage the concept of Moving Target Defense (MTD) in designing a meta-defense for 'boosting' the robustness of an ensemble of deep neural networks (DNNs) for visual classification tasks against such adversarial attacks. To classify an input image at test time, a constituent network is randomly selected based on a mixed policy. To obtain this policy, we formulate the interaction between a Defender (who hosts the classification networks) and their (Legitimate and Malicious) users as a Bayesian Stackelberg Game (BSG). We empirically show that our approach MTDeep, reduces misclassification on perturbed images for various datasets such as MNIST, FashionMNIST, and ImageNet while maintaining high classification accuracy on legitimate test images. We then demonstrate that our framework, being the first meta-defense technique, can be used in conjunction with any existing defense mechanism to provide more resilience against adversarial attacks that can be afforded by these defense mechanisms alone. Lastly, to quantify the increase in robustness of an ensemble-based classification system when we use MTDeep, we analyze the properties of a set of DNNs and introduce the concept of differential immunity that formalizes the notion of attack transferability.
引用
收藏
页码:479 / 491
页数:13
相关论文
共 50 条
  • [41] Efficacy of Defending Deep Neural Networks against Adversarial Attacks with Randomization
    Zhou, Yan
    Kantarcioglu, Murat
    Xi, Bowei
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS II, 2020, 11413
  • [42] Analysis of VM Migration Scheduling as Moving Target Defense against insider attacks
    Torquato, Matheus
    Maciel, Paulo
    Vieira, Marco
    36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 194 - 202
  • [43] Strategic Protection Against FDI Attacks With Moving Target Defense in Power Grids
    Zhang, Zhenyong
    Deng, Ruilong
    Cheng, Peng
    Chow, Mo-Yuen
    IEEE TRANSACTIONS ON CONTROL OF NETWORK SYSTEMS, 2022, 9 (01): : 245 - 256
  • [44] Boosting Adversarial Attacks on Neural Networks with Better Optimizer
    Yin, Heng
    Zhang, Hengwei
    Wang, Jindong
    Dou, Ruiyu
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [45] Detection of adversarial attacks against security systems based on deep learning model
    Jaber, Mohanad J.
    Jaber, Zahraa Jasim
    Obaid, Ahmed J.
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2024, 27 (05): : 1523 - 1538
  • [46] Adversarial Deep Learning approach detection and defense against DDoS attacks in SDN environments
    Novaes, Matheus P.
    Carvalho, Luiz F.
    Lloret, Jaime
    Proenca, Mario Lemes, Jr.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 125 : 156 - 167
  • [47] An Optimized Non-deep Learning Defense Against Adversarial Attacks for Pedestrian Detection
    Etehadi-Abari, Mina
    Naghsh-Nilchi, Ahmad Reza
    Hoseinnezhad, Reza
    JOURNAL OF SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY, 2025, : 763 - 777
  • [48] A Data Augmentation-Based Defense Method Against Adversarial Attacks in Neural Networks
    Zeng, Yi
    Qiu, Han
    Memmi, Gerard
    Qiu, Meikang
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2020, PT II, 2020, 12453 : 274 - 289
  • [49] Deep-Reinforcement-Learning-Based Self-Evolving Moving Target Defense Approach Against Unknown Attacks
    Cao, Yuan
    Liu, Kun
    Lin, Yeming
    Wang, Luyao
    Xia, Yuanqing
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (20): : 33027 - 33039
  • [50] The Best Defense is a Good Offense: Adversarial Augmentation against Adversarial Attacks
    Frosio, Iuri
    Kautz, Jan
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR, 2023, : 4067 - 4076