Toward Intelligent Detection Modelling for Adversarial Samples in Convolutional Neural Networks

被引:0
|
作者
Qiao, Zhuobiao [1 ]
Dong, Mianxiong [2 ]
Ota, Kaoru [2 ]
Wu, Jun [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Elect Informat & Elect Engn, Shanghai, Peoples R China
[2] Muroran Inst Technol, Dept Informat & Elect Engn, Muroran, Hokkaido, Japan
基金
中国国家自然科学基金;
关键词
Adversarial samples; CNN attacks and detection; Large Margin Cosine Estimate;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Deep Neural Networks (DNNs) are hierarchical nonlinear architectures that have been widely used in artificial intelligence applications. However, these models are vulnerable to adversarial perturbations which add changes slightly and are crafted explicitly to fool the model. Such attacks will cause the neural network to completely change its classification of data. Although various defense strategies have been proposed, existing defense methods have two limitations. First, the discovery success rate is not very high. Second, existing methods depend on the output of a particular layer in a specific learning structure. In this paper, we propose a powerful method for adversarial samples using Large Margin Cosine Estimate(LMCE). By iteratively calculating the large-margin cosine uncertainty estimates between the model predictions, the results can be regarded as a novel measurement of model uncertainty estimation and is available to detect adversarial samples by training using a simple machine learning algorithm. Comparing it with the way in which adversarial samples are generated, it is confirmed that this measurement can better distinguish hostile disturbances. We modeled deep neural network attacks and established defense mechanisms against various types of adversarial attacks. Classifier gets better performance than the baseline model. The approach is validated on a series of standard datasets including MNIST and CIFAR-10, outperforming previous ensemble method with strong statistical significance. Experiments indicate that our approach generalizes better across different architectures and attacks.
引用
收藏
页码:74 / 79
页数:6
相关论文
共 50 条
  • [31] Pedestrian detection with convolutional neural networks
    Szarvas, M
    Yoshizawa, A
    Yamamoto, M
    Ogata, J
    2005 IEEE INTELLIGENT VEHICLES SYMPOSIUM PROCEEDINGS, 2005, : 224 - 229
  • [32] Tooth Detection with Convolutional Neural Networks
    Oktay, Ayse Betul
    2017 MEDICAL TECHNOLOGIES NATIONAL CONGRESS (TIPTEKNO), 2017,
  • [33] Deep Convolutional Generative Adversarial Network and Convolutional Neural Network for Smoke Detection
    Yin, Hang
    Wei, Yurong
    Liu, Hedan
    Liu, Shuangyin
    Liu, Chuanyun
    Gao, Yacui
    Liu, Shuangyin (hdlsyxlq@126.com), 1600, Hindawi Limited (2020):
  • [34] Text detection with convolutional neural networks
    Delakis, Manolis
    Garcia, Christophe
    VISAPP 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON COMPUTER VISION THEORY AND APPLICATIONS, VOL 2, 2008, : 290 - 294
  • [35] Grape detection with convolutional neural networks
    Cecotti, Hubert
    Rivera, Agustin
    Farhadloo, Majid
    Pedroza, Miguel A.
    EXPERT SYSTEMS WITH APPLICATIONS, 2020, 159
  • [36] Adversarial Attacks with Defense Mechanisms on Convolutional Neural Networks and Recurrent Neural Networks for Malware Classification
    Alzaidy, Sharoug
    Binsalleeh, Hamad
    APPLIED SCIENCES-BASEL, 2024, 14 (04):
  • [37] Generalization of Convolutional Neural Networks for ECG Classification Using Generative Adversarial Networks
    Shaker, Abdelrahman M.
    Tantawi, Manal
    Shedeed, Howida A.
    Tolba, Mohamed F.
    IEEE ACCESS, 2020, 8 : 35592 - 35605
  • [38] Adversarial image detection in deep neural networks
    Carrara, Fabio
    Falchi, Fabrizio
    Caldelli, Roberto
    Amato, Giuseppe
    Becarelli, Rudy
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (03) : 2815 - 2835
  • [39] Adversarial image detection in deep neural networks
    Fabio Carrara
    Fabrizio Falchi
    Roberto Caldelli
    Giuseppe Amato
    Rudy Becarelli
    Multimedia Tools and Applications, 2019, 78 : 2815 - 2835
  • [40] Pavement crack detection algorithm based on generative adversarial network and convolutional neural network under small samples
    Xu, Boqiang
    Liu, Chao
    MEASUREMENT, 2022, 196