Stochastic Computing as a Defence Against Adversarial Attacks

被引:0
|
作者
Neugebauer, Florian [1 ]
Vekariya, Vivek [2 ]
Polian, Ilia [1 ]
Hayes, John P. [3 ]
机构
[1] Univ Stuttgart, Inst Comp Architecture & Comp Engn, Stuttgart, Germany
[2] Fortiss GmbH, Munich, Germany
[3] Univ Michigan, Comp Engn Lab, Ann Arbor, MI 48109 USA
基金
美国国家科学基金会;
关键词
stochastic computing; neural network; adversarial attack;
D O I
10.1109/DSN-W58399.2023.00053
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Neural networks (NNs) are increasingly often employed in safety critical systems. It is therefore necessary to ensure that these NNs are robust against malicious interference in the form of adversarial attacks, which cause an NN to misclassify inputs. Many proposed defenses against such attacks incorporate randomness in order to make it harder for an attacker to find small input modifications that result in misclassification. Stochastic computing (SC) is a type of approximate computing based on pseudo-random bit-streams that has been successfully used to implement convolutional neural networks (CNNs). Some results have previously suggested that such stochastic CNNs (SCNNs) are partially robust against adversarial attacks. In this work, we will demonstrate that SCNNs do indeed possess inherent protection against some powerful adversarial attacks. Our results show that the white-box C&W attack is up to 16x less successful compared to an equivalent binary NN, and Boundary Attack even fails to generate adversarial inputs in many cases.
引用
收藏
页码:191 / 194
页数:4
相关论文
共 50 条
  • [31] On the robustness of skeleton detection against adversarial attacks
    Bai, Xiuxiu
    Yang, Ming
    Liu, Zhe
    NEURAL NETWORKS, 2020, 132 : 416 - 427
  • [32] ADVERSARIAL ATTACKS AGAINST AUDIO SURVEILLANCE SYSTEMS
    Ntalampiras, Stavros
    European Signal Processing Conference, 2022, 2022-August : 284 - 288
  • [33] A Defense Method Against Facial Adversarial Attacks
    Sadu, Chiranjeevi
    Das, Pradip K.
    2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 459 - 463
  • [34] On the Defense of Spoofing Countermeasures Against Adversarial Attacks
    Nguyen-Vu, Long
    Doan, Thien-Phuc
    Bui, Mai
    Hong, Kihun
    Jung, Souhwan
    IEEE ACCESS, 2023, 11 : 94563 - 94574
  • [35] Adversarial Sampling Attacks Against Phishing Detection
    Shirazi, Hossein
    Bezawada, Bruhadeshwar
    Ray, Indrakshi
    Anderson, Charles
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIII, 2019, 11559 : 83 - 101
  • [36] ADVERSARIAL ATTACKS AGAINST AUDIO SURVEILLANCE SYSTEMS
    Ntalampiras, Stavros
    2022 30TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO 2022), 2022, : 284 - 288
  • [37] Defense against Adversarial Attacks with an Induced Class
    Xu, Zhi
    Wang, Jun
    Pu, Jian
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [38] Robust Trajectory Prediction against Adversarial Attacks
    Cao, Yulong
    Xu, Danfei
    Weng, Xinshuo
    Mao, Z. Morley
    Anandkumar, Anima
    Xiao, Chaowei
    Pavone, Marco
    CONFERENCE ON ROBOT LEARNING, VOL 205, 2022, 205 : 128 - 137
  • [39] Adversarial Feature Selection Against Evasion Attacks
    Zhang, Fei
    Chan, Patrick P. K.
    Biggio, Battista
    Yeung, Daniel S.
    Roli, Fabio
    IEEE TRANSACTIONS ON CYBERNETICS, 2016, 46 (03) : 766 - 777
  • [40] ROBUSTNESS OF SAAK TRANSFORM AGAINST ADVERSARIAL ATTACKS
    Ramanathan, Thiyagarajan
    Manimaran, Abinaya
    You, Suya
    Kuo, C-C Jay
    2019 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2019, : 2531 - 2535