Adversarial sample detection framework based on autoencoder

被引:5
|
作者
Tong, Li [1 ]
Wang, Luo [2 ]
Li, Shen [1 ]
Zhang Pengfei [3 ]
Ju Xiaoming [3 ]
Yu TongWei [1 ]
Yang WeiDong [2 ]
机构
[1] STATE GRID LIAONING ELECT POWER SUPPLY CO LTD, Shenyang, Peoples R China
[2] NARI Grp Corp, State Grid Elect Power Res Inst, Nanjing, Peoples R China
[3] East China Normal Univ, Sch Software Engn, Shanghai, Peoples R China
关键词
Gaussian filtering; Mean filtering; Median filtering; Autoencoder integrated neural network;
D O I
10.1109/ICBASE51474.2020.00058
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Despite the great success of deep neural networks (DNN) in many tasks, they are often fooled by examples of confrontation created by adding small and purposeful distortions to natural examples. Previous research has mainly focused on improving DNN models, but either results are limited or expensive calculations are required. This paper studies an integrated feature noise reduction method: by using Gaussian filtering, mean filtering, and median filtering, the automatic encoder integrates a neural network to prevent the generation of adaptive adversarial samples. By comparing the reconstruction error of the autoencoder to detect adversarial samples, these simple strategies are not only low-cost, but also complementary to other defensive measures. In this paper, a new autoencoder is created as a modifier to make the two combine to form an adversarial The joint detection framework of the sample to achieve a high detection rate for the latest attacks. For several methods with high attack success rates, FGSM, BIM, PGD and CW attacks. For larger disturbances, the black box attacks against the MNIST data set the undetected rate of CW non-target attacks is 23%, and the detection rate of other attacks is 100%. The undetected rate of CIFAR-10 black box attacks except CW non-target attacks is 25%, and the undetected rate of other attacks is below 5%. In the case of black box attacks with small disturbances, the classification accuracy of the MNIST protected network has reached more than 90%, and the classification accuracy of the CIFAR-10 protected network has reached more than 80% in addition to the CW attack classification. The accuracy rate has also reached a high level.
引用
收藏
页码:241 / 245
页数:5
相关论文
共 50 条
  • [1] Abnormal ECG detection based on an adversarial autoencoder
    Shan, Lianfeng
    Li, Yu
    Jiang, Hua
    Zhou, Peng
    Niu, Jing
    Liu, Ran
    Wei, Yuanyuan
    Peng, Jiao
    Yu, Huizhen
    Sha, Xianzheng
    Chang, Shijie
    FRONTIERS IN PHYSIOLOGY, 2022, 13
  • [2] Wasserstein Distance Based Domain Adversarial Autoencoder for Industrial Few-sample Fault Detection
    Fang, Ruiyi
    Wang, Kai
    Yuan, Xiaofeng
    Wang, Yalin
    Yang, Chunhua
    2024 14TH ASIAN CONTROL CONFERENCE, ASCC 2024, 2024, : 1474 - 1479
  • [3] Calibrated reconstruction based adversarial autoencoder model for novelty detection
    Huang, Yi
    Li, Ying
    Jourjon, Guillaume
    Seneviratne, Suranga
    Thilakarathna, Kanchana
    Cheng, Adriel
    Webb, Darren
    Xu, Richard Yi Da
    PATTERN RECOGNITION LETTERS, 2023, 169 : 50 - 57
  • [4] Adversarial autoencoder for hyperspectral anomaly detection
    Du Q.
    Xie W.
    Cehui Xuebao/Acta Geodaetica et Cartographica Sinica, 2023, 52 (07): : 1105 - 1114
  • [5] Active Attack Detection Based on Interpretable Channel Fingerprint and Adversarial Autoencoder
    Ji, Zijie
    Yang, Binbing
    Yeoh, Phee Lep
    Zhang, Yan
    He, Zunwen
    Li, Yonghui
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 4993 - 4998
  • [6] Adversarial Autoencoder Based Feature Learning for Fault Detection in Industrial Processes
    Jang, Kyojin
    Hong, Seokyoung
    Kim, Minsu
    Na, Jonggeol
    Moon, Il
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (02) : 827 - 834
  • [7] An Anomaly Detection Framework Based on Autoencoder and Nearest Neighbor
    Guo, Jia
    Liu, Guannan
    Zuo, Yuan
    Wu, Junjie
    2018 15TH INTERNATIONAL CONFERENCE ON SERVICE SYSTEMS AND SERVICE MANAGEMENT (ICSSSM), 2018,
  • [8] Radiation Anomaly Detection Using an Adversarial Autoencoder
    Sayre, Charles
    Larson, Eric C.
    DiLiegro, Gabs
    Camp, Joseph
    Gnade, Bruce
    FIFTY-SEVENTH ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS & COMPUTERS, IEEECONF, 2023, : 1010 - 1014
  • [9] Defective Products Detection using Adversarial AutoEncoder
    Nakatsuka, Shunsuke
    Aizawa, Hiroaki
    Kato, Kunihito
    INTERNATIONAL WORKSHOP ON ADVANCED IMAGE TECHNOLOGY (IWAIT) 2019, 2019, 11049
  • [10] An adversarial sample detection method based on heterogeneous denoising
    Zhu, Lifang
    Liu, Chao
    Zhang, Zhiqiang
    Cheng, Yifan
    Jie, Biao
    Ding, Xintao
    MACHINE VISION AND APPLICATIONS, 2024, 35 (04)