Adversarial sample detection framework based on autoencoder

被引:5
|
作者
Tong, Li [1 ]
Wang, Luo [2 ]
Li, Shen [1 ]
Zhang Pengfei [3 ]
Ju Xiaoming [3 ]
Yu TongWei [1 ]
Yang WeiDong [2 ]
机构
[1] STATE GRID LIAONING ELECT POWER SUPPLY CO LTD, Shenyang, Peoples R China
[2] NARI Grp Corp, State Grid Elect Power Res Inst, Nanjing, Peoples R China
[3] East China Normal Univ, Sch Software Engn, Shanghai, Peoples R China
关键词
Gaussian filtering; Mean filtering; Median filtering; Autoencoder integrated neural network;
D O I
10.1109/ICBASE51474.2020.00058
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Despite the great success of deep neural networks (DNN) in many tasks, they are often fooled by examples of confrontation created by adding small and purposeful distortions to natural examples. Previous research has mainly focused on improving DNN models, but either results are limited or expensive calculations are required. This paper studies an integrated feature noise reduction method: by using Gaussian filtering, mean filtering, and median filtering, the automatic encoder integrates a neural network to prevent the generation of adaptive adversarial samples. By comparing the reconstruction error of the autoencoder to detect adversarial samples, these simple strategies are not only low-cost, but also complementary to other defensive measures. In this paper, a new autoencoder is created as a modifier to make the two combine to form an adversarial The joint detection framework of the sample to achieve a high detection rate for the latest attacks. For several methods with high attack success rates, FGSM, BIM, PGD and CW attacks. For larger disturbances, the black box attacks against the MNIST data set the undetected rate of CW non-target attacks is 23%, and the detection rate of other attacks is 100%. The undetected rate of CIFAR-10 black box attacks except CW non-target attacks is 25%, and the undetected rate of other attacks is below 5%. In the case of black box attacks with small disturbances, the classification accuracy of the MNIST protected network has reached more than 90%, and the classification accuracy of the CIFAR-10 protected network has reached more than 80% in addition to the CW attack classification. The accuracy rate has also reached a high level.
引用
收藏
页码:241 / 245
页数:5
相关论文
共 50 条
  • [31] Spatial Temporal Balanced Generative Adversarial AutoEncoder for Anomaly Detection
    Lei, Zheng
    Deng, Fang
    Yang, Xudong
    PROCEEDINGS OF 2019 INTERNATIONAL CONFERENCE ON IMAGE, VIDEO AND SIGNAL PROCESSING (IVSP 2019), 2019, : 1 - 7
  • [32] Adversarial Autoencoder Data Synthesis for Enhancing Machine Learning-Based Phishing Detection Algorithms
    Shirazi, Hossein
    Muramudalige, Shashika R.
    Ray, Indrakshi
    Jayasumana, Anura P.
    Wang, Haonan
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (04) : 2411 - 2422
  • [33] Image-based Process Monitoring via Adversarial Autoencoder with Applications to Rolling Defect Detection
    Yan, Hao
    Yeh, Huai-Ming
    Sergin, Nurettin
    2019 IEEE 15TH INTERNATIONAL CONFERENCE ON AUTOMATION SCIENCE AND ENGINEERING (CASE), 2019, : 311 - 316
  • [34] Widespread bathymetric outliers detection and elimination based on conditional variational autoencoder generative adversarial network
    Zhang R.
    Bian S.
    Liu Y.
    Li H.
    Cehui Xuebao/Acta Geodaetica et Cartographica Sinica, 2019, 48 (09): : 1182 - 1189
  • [35] RAIDS: Robust autoencoder-based intrusion detection system model against adversarial attacks
    Sarikaya, Alper
    Kilic, Banu Gunel
    Demirci, Mehmet
    COMPUTERS & SECURITY, 2023, 135
  • [36] Unsupervised anomalous sound detection method based on Gammatone spectrogram and adversarial autoencoder with attention mechanism
    Yan, Hao
    Zhan, Xianbiao
    Wu, Zhenghao
    Cheng, Junkai
    Wen, Liang
    Jia, Xisheng
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART E-JOURNAL OF PROCESS MECHANICAL ENGINEERING, 2024,
  • [37] Adversarial Attention-Based Variational Graph Autoencoder
    Weng, Ziqiang
    Zhang, Weiyu
    Dou, Wei
    IEEE ACCESS, 2020, 8 : 152637 - 152645
  • [38] Image scrambling adversarial autoencoder based on the asymmetric encryption
    Bao, Zhenjie
    Xue, Ru
    Jin, Yadong
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (18) : 28265 - 28301
  • [39] Image scrambling adversarial autoencoder based on the asymmetric encryption
    Zhenjie Bao
    Ru Xue
    Yadong Jin
    Multimedia Tools and Applications, 2021, 80 : 28265 - 28301
  • [40] Hyperspectral Pansharpening Based on Spectral Constrained Adversarial Autoencoder
    He, Gang
    Zhong, Jiaping
    Lei, Jie
    Li, Yunsong
    Xie, Weiying
    REMOTE SENSING, 2019, 11 (22)