Similarity-driven adversarial testing of neural networks

被引:0
|
作者
Filus, Katarzyna [1 ]
Domanska, Joanna [1 ]
机构
[1] Polish Acad Sci, Inst Theoret & Appl Informat, Gliwice, Poland
关键词
Adversarial attacks; Testing; Artificial intelligence security; Convolutional Neural Networks; Object recognition;
D O I
10.1016/j.knosys.2024.112621
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Although Convolutional Neural Networks (CNNs) are among the most important algorithms of computer vision and the artificial intelligence-based systems, they are vulnerable to adversarial attacks. Such attacks can cause dangerous consequences in real-life deployments. Consequently, testing of the artificial intelligence-based systems from their perspective is crucial to reliably support human prediction and decision-making through computation techniques under varying conditions. While proposing new effective attacks is important for neural network testing, it is also crucial to design effective strategies that can be used to choose target labels for these attacks. That is why, in this paper we propose a novel similarity-driven adversarial testing methodology for target label choosing. Our motivation is that CNNs, similarly to humans, tend to make mistakes mostly among categories they perceive similar. Thus, the effort to make models predict a particular class is not equal for all classes. Motivated by this, we propose to use the most and least similar labels to the ground truth according to different similarity measures to choose the target label for an adversarial attack. They can be treated as best- and worst-case scenarios in practical and transparent testing methodologies. As similarity is one of the key components of human cognition and categorization, the approach presents a shift towards amore human- centered security testing of deep neural networks. The obtained numerical results show the superiority of the proposed methods to the existing strategies in the targeted and the non-targeted testing setups.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Search-based Similarity-driven Behavioural SPL Testing
    Devroey, Xavier
    Perrouin, Gilles
    Legay, Axel
    Schobbens, Pierre-Yves
    Heymans, Patrick
    TENTH INTERNATIONAL WORKSHOP ON VARIABILITY MODELLING OF SOFTWARE-INTENSIVE SYSTEMS (VAMOS 2016), 2016, : 89 - 96
  • [2] Similarity-driven software reuse
    Bildhauer, Daniel
    Horn, Tassilo
    Ebert, Juergen
    2009 ICSE WORKSHOP ON COMPARISON AND VERSIONING OF SOFTWARE MODELS, 2009, : 31 - 36
  • [3] An Empirical Investigation of Similarity-Driven Trust Dynamics in Social Networks
    Hayashi, Yugo
    Kryssanov, Victor
    9TH CONFERENCE ON APPLICATIONS OF SOCIAL NETWORK ANALYSIS (ASNA), 2013, 79 : 27 - 37
  • [4] Similarity-driven sampling for data mining
    Reinartz, T
    PRINCIPLES OF DATA MINING AND KNOWLEDGE DISCOVERY, 1998, 1510 : 423 - 431
  • [5] Similarity-driven flexible ligand docking
    Fradera, X
    Knegtel, RMA
    Mestres, J
    PROTEINS-STRUCTURE FUNCTION AND BIOINFORMATICS, 2000, 40 (04) : 623 - 636
  • [6] LoFT: Similarity-Driven Multiobjective Focused Library Design
    Fischer, J. Robert
    Lessel, Uta
    Rarey, Matthias
    JOURNAL OF CHEMICAL INFORMATION AND MODELING, 2010, 50 (01) : 1 - 21
  • [7] Similarity-driven flexible ligand docking.
    Mestres, J
    Fradera, X
    Knegtel, RMA
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2000, 219 : U608 - U609
  • [8] A method of similarity-driven knowledge revision for type specializations
    Morita, N
    Haraguchi, M
    Okubo, Y
    ALGORITHMIC LEARNING THEORY, PROCEEDINGS, 1999, 1720 : 194 - 205
  • [9] Similarity-driven topology finding of surface patterns for structural design
    Oval, R.
    Mesnil, R.
    Van Mele, T.
    Baverel, O.
    Block, P.
    COMPUTER-AIDED DESIGN, 2024, 176
  • [10] Similarity-Driven Semantic Role Induction via Graph Partitioning
    Lang, Joel
    Lapata, Mirella
    COMPUTATIONAL LINGUISTICS, 2014, 40 (03) : 633 - 669