Adversarial sample detection framework based on autoencoder

被引:5
|
作者
Tong, Li [1 ]
Wang, Luo [2 ]
Li, Shen [1 ]
Zhang Pengfei [3 ]
Ju Xiaoming [3 ]
Yu TongWei [1 ]
Yang WeiDong [2 ]
机构
[1] STATE GRID LIAONING ELECT POWER SUPPLY CO LTD, Shenyang, Peoples R China
[2] NARI Grp Corp, State Grid Elect Power Res Inst, Nanjing, Peoples R China
[3] East China Normal Univ, Sch Software Engn, Shanghai, Peoples R China
关键词
Gaussian filtering; Mean filtering; Median filtering; Autoencoder integrated neural network;
D O I
10.1109/ICBASE51474.2020.00058
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Despite the great success of deep neural networks (DNN) in many tasks, they are often fooled by examples of confrontation created by adding small and purposeful distortions to natural examples. Previous research has mainly focused on improving DNN models, but either results are limited or expensive calculations are required. This paper studies an integrated feature noise reduction method: by using Gaussian filtering, mean filtering, and median filtering, the automatic encoder integrates a neural network to prevent the generation of adaptive adversarial samples. By comparing the reconstruction error of the autoencoder to detect adversarial samples, these simple strategies are not only low-cost, but also complementary to other defensive measures. In this paper, a new autoencoder is created as a modifier to make the two combine to form an adversarial The joint detection framework of the sample to achieve a high detection rate for the latest attacks. For several methods with high attack success rates, FGSM, BIM, PGD and CW attacks. For larger disturbances, the black box attacks against the MNIST data set the undetected rate of CW non-target attacks is 23%, and the detection rate of other attacks is 100%. The undetected rate of CIFAR-10 black box attacks except CW non-target attacks is 25%, and the undetected rate of other attacks is below 5%. In the case of black box attacks with small disturbances, the classification accuracy of the MNIST protected network has reached more than 90%, and the classification accuracy of the CIFAR-10 protected network has reached more than 80% in addition to the CW attack classification. The accuracy rate has also reached a high level.
引用
收藏
页码:241 / 245
页数:5
相关论文
共 50 条
  • [41] Extension of M Dwarf Spectra Based on Adversarial AutoEncoder
    Wei, Jiyu
    Wang, Xingzhu
    Li, Bo
    Chen, Yuze
    Jiang, Bin
    UNIVERSE, 2021, 7 (09)
  • [42] SeqAD: An Unsupervised and Sequential Autoencoder Ensembles based Anomaly Detection Framework for KPI
    Zhao, Na
    Han, Biao
    Cai, Yang
    Su, Jinshu
    2021 IEEE/ACM 29TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2021,
  • [43] Adversarial Sample Detection with Gaussian Mixture Conditional Generative Adversarial Networks
    Zhang, Pengfei
    Ju, Xiaoming
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2021, 2021
  • [44] Evolutionary Adversarial Autoencoder for Unsupervised Anomaly Detection of Industrial Internet of Things
    Zeng, Guo-Qiang
    Yang, Yao-Wei
    Lu, Kang-Di
    Geng, Guang-Gang
    Weng, Jian
    IEEE TRANSACTIONS ON RELIABILITY, 2025,
  • [45] An LSTM-based adversarial variational autoencoder framework for self-supervised neural decoding of behavioral choices
    Salsabilian, Shiva
    Lee, Christian
    Margolis, David
    Najafizadeh, Laleh
    JOURNAL OF NEURAL ENGINEERING, 2024, 21 (03)
  • [46] Improved Phishing Detection Algorithms using Adversarial Autoencoder Synthesized Data
    Shirazi, Hossein
    Muramudalige, Shashika R.
    Ray, Indrakshi
    Jayasumana, Anura P.
    PROCEEDINGS OF THE 2020 IEEE 45TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2020), 2020, : 24 - 32
  • [47] An unsupervised adversarial autoencoder for cyber attack detection in power distribution grids
    Zideh, Mehdi Jabbari
    Khalghani, Mohammad Reza
    Solanki, Sarika Khushalani
    ELECTRIC POWER SYSTEMS RESEARCH, 2024, 232
  • [48] A Latent Feature Autoencoder via Adversarial Training for Unsupervised Anomaly Detection
    Tang, Wei
    Li, Jun
    2021 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2021, : 2718 - 2723
  • [49] An adversarial contrastive autoencoder for robust multivariate time series anomaly detection
    Yu, Jiahao
    Gao, Xin
    Zhai, Feng
    Li, Baofeng
    Xue, Bing
    Fu, Shiyuan
    Chen, Lingli
    Meng, Zhihang
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 245
  • [50] Adversarial Sample Generation for Lithography Hotspot Detection
    Sun, Shuyuan
    Jiang, Yiyang
    Yang, Fan
    Zeng, Xuan
    2022 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS 22), 2022, : 3503 - 3506