Detecting adversarial examples using image reconstruction differences

被引:0
|
作者
Jiaze Sun
Meng Yi
机构
[1] Xi’an University of Posts and Telecommunications,School of Computer Science and Technology
[2] Shaanxi Key Laboratory of Network Data Analysis and Intelligent Processing,undefined
[3] Xi’an Key Laboratory of Big Data and Intelligent Computing,undefined
来源
Soft Computing | 2023年 / 27卷
关键词
Deep neural networks; Adversarial examples; Detection; Compress and reconstruct; Image reconstruction differences; Random forest;
D O I
暂无
中图分类号
学科分类号
摘要
The adversarial examples (AEs) cause misjudgments and damage the robustness of the DNNs systems. Previous studies have defended against AEs by detecting, but it is challenging to ensure a stable and high performance of detecting AEs, while with a poor false detection. To this end, an AEs detection method named image reconstruction differences (IRD) is proposed to enhance the robustness of DNNs. Firstly, we use an end-to-end Com-Rec network to reconstruct examples with feature compression to expand the distinguishing features. Secondly, propose an image reconstruction differences based on information-theoretic VIF, structural information UQI and spectral information RASE composition to discriminate AEs. Moreover, we introduce the idea of integrated learning to form a strong random forest binary classifier to enhance the performance of detecting AEs. We further validate it through extensive experiments on the MNIST and CIFAR-10 datasets. These experiments demonstrated that the IRD effectively detected AEs and achieved a high average accuracy of 98.33%. Specifically it also performs favorably against the following methods based on Feature Squeezing, Local Intrinsic Dimensionality, Kernel Density and Network Invariance Checking with an average detection rate of 99.54% and a 1.44% average false positive rate.
引用
收藏
页码:7863 / 7877
页数:14
相关论文
共 50 条
  • [21] Adversarial Examples Improve Image Recognition
    Xie, Cihang
    Tan, Mingxing
    Gong, Boqing
    Wang, Jiang
    Yuille, Alan L.
    Le, Quoc, V
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 816 - 825
  • [22] AdvIris: a hybrid approach to detecting adversarial iris examples using wavelet transform
    Meenakshi K.
    Maragatham G.
    International Journal of Speech Technology, 2022, 25 (02) : 435 - 441
  • [23] Detecting Localized Adversarial Examples: A Generic Approach using Critical Region Analysis
    Li, Fengting
    Liu, Xuankai
    Zhang, Xiaoli
    Li, Qi
    Sun, Kun
    Li, Kang
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2021), 2021,
  • [24] Text-Defend: Detecting Adversarial Examples using Local Outlier Factor
    Omar, Marwan
    Sukthankar, Gita
    2023 IEEE 17TH INTERNATIONAL CONFERENCE ON SEMANTIC COMPUTING, ICSC, 2023, : 118 - 122
  • [25] Discriminative Manifold Learning Network using Adversarial Examples for Image Classification
    Zhang, Yuan
    Shi, Biming
    JOURNAL OF ELECTRICAL ENGINEERING & TECHNOLOGY, 2018, 13 (05) : 2099 - 2106
  • [26] Adversarial Examples Detection Using No-Reference Image Quality Features
    Akhtar, Zahid
    Monteiro, Joao
    Falk, Tiago H.
    2018 52ND ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2018, : 182 - 186
  • [27] Clustering Approach for Detecting Multiple Types of Adversarial Examples
    Choi, Seok-Hwan
    Bahk, Tae-U
    Ahn, Sungyong
    Choi, Yoon-Ho
    SENSORS, 2022, 22 (10)
  • [28] Detecting Adversarial Examples Utilizing Pixel Value Diversity
    Dong, Jinxin
    Zhou, Pingqiang
    ACM TRANSACTIONS ON DESIGN AUTOMATION OF ELECTRONIC SYSTEMS, 2024, 29 (03)
  • [29] The Odds are Odd: A Statistical Test for Detecting Adversarial Examples
    Roth, Kevin
    Kilcher, Yannic
    Hofmann, Thomas
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [30] Detecting Adversarial Examples Is (Nearly) As Hard As Classifying Them
    Tramer, Florian
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,