Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes

被引:3
|
作者
Zhang, Bowen [1 ]
Tondi, Benedetta [2 ]
Lv, Xixiang [1 ]
Barni, Mauro [2 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
[2] Univ Siena, Dept Informat Engn & Math, I-53100 Siena, Italy
关键词
Deep learning;
D O I
10.1155/2020/8882494
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The existence of adversarial examples and the easiness with which they can be generated raise several security concerns with regard to deep learning systems, pushing researchers to develop suitable defence mechanisms. The use of networks adopting error-correcting output codes (ECOC) has recently been proposed to counter the creation of adversarial examples in a white-box setting. In this paper, we carry out an in-depth investigation of the adversarial robustness achieved by the ECOC approach. We do so by proposing a new adversarial attack specifically designed for multilabel classification architectures, like the ECOC-based one, and by applying two existing attacks. In contrast to previous findings, our analysis reveals that ECOC-based networks can be attacked quite easily by introducing a small adversarial perturbation. Moreover, the adversarial examples can be generated in such a way to achieve high probabilities for the predicted target class, hence making it difficult to use the prediction confidence to detect them. Our findings are proven by means of experimental results obtained on MNIST, CIFAR-10, and GTSRB classification tasks.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Efficient Error-correcting Output Codes for Adversarial Learning Robustness
    Wan, Li
    Alpcan, Tansu
    Viterbo, Emanuele
    Kuijper, Margreta
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 2345 - 2350
  • [2] Quantum error-correcting output codes
    Windridge, David
    Mengoni, Riccardo
    Nagarajan, Rajagopal
    INTERNATIONAL JOURNAL OF QUANTUM INFORMATION, 2018, 16 (08)
  • [3] Deep Error-Correcting Output Codes
    Wang, Li-Na
    Wei, Hongxu
    Zheng, Yuchen
    Dong, Junyu
    Zhong, Guoqiang
    ALGORITHMS, 2023, 16 (12)
  • [4] Hierarchical error-correcting output codes based on SVDD
    Lei Lei
    Wang Xiao-dan
    Luo Xi
    Song Ya-fei
    Pattern Analysis and Applications, 2016, 19 : 163 - 171
  • [5] Recoding Error-Correcting Output Codes
    Escalera, Sergio
    Pujol, Oriol
    Radeva, Petia
    MULTIPLE CLASSIFIER SYSTEMS, PROCEEDINGS, 2009, 5519 : 11 - +
  • [6] Hierarchical error-correcting output codes based on SVDD
    Lei, Lei
    Xiao-dan, Wang
    Xi, Luo
    Ya-fei, Song
    PATTERN ANALYSIS AND APPLICATIONS, 2016, 19 (01) : 163 - 171
  • [7] Minimal design of error-correcting output codes
    Angel Bautista, Miguel
    Escalera, Sergio
    Baro, Xavier
    Radeva, Petia
    Vitria, Jordi
    Pujol, Oriol
    PATTERN RECOGNITION LETTERS, 2012, 33 (06) : 693 - 702
  • [8] Active learning with error-correcting output codes
    Gu, Shilin
    Cai, Yang
    Shan, Jincheng
    Hou, Chenping
    NEUROCOMPUTING, 2019, 364 : 182 - 191
  • [9] Error-correcting output codes based on feature space transformation
    Lei, Lei
    Wang, Xiao-Dan
    Luo, Xi
    Song, Ya-Fei
    Xue, Ai-Jun
    Kongzhi yu Juece/Control and Decision, 2015, 30 (09): : 1597 - 1602
  • [10] Error-correcting output codes based ensemble feature extraction
    Zhong, Guoqiang
    Liu, Cheng-Lin
    PATTERN RECOGNITION, 2013, 46 (04) : 1091 - 1100