TENSORSHIELD: Tensor-based Defense Against Adversarial Attacks on Images

被引:0
作者
Entezari, Negin [1 ]
Papalexakis, Evangelos E. [1 ]
机构
[1] Univ Calif Riverside, Riverside, CA 92521 USA
来源
2022 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM) | 2022年
关键词
adversarial machine learning; deep neural networks; image classification;
D O I
10.1109/MILCOM55135.2022.10017763
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent studies have demonstrated that machine learning approaches like deep neural networks (DNNs) are easily fooled by adversarial attacks. Subtle and imperceptible perturbations of the data are able to change the result of deep neural networks. Leveraging vulnerable machine learning methods raises many concerns, especially in domains where security is an important factor. Therefore, it is crucial to design defense mechanisms against adversarial attacks. For the task of image classification, unnoticeable perturbations mostly occur in the high-frequency spectrum of the image. In this paper, we utilize tensor decomposition techniques as a preprocessing step to find a low-rank approximation of images that can significantly discard high-frequency perturbations. Recently a defense framework called SHIELD [1] could "vaccinate" Convolutional Neural Networks (CNN) against adversarial examples by performing random-quality JPEG compressions on local patches of images on the ImageNet dataset. Our tensor-based defense mechanism outperforms the SLQ method from SHIELD by 14% against Fast Gradient Descent (FGSM) adversarial attacks, while maintaining comparable speed.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Automating Defense Against Adversarial Attacks: Discovery of Vulnerabilities and Application of Multi-INT Imagery to Protect Deployed Models
    Kalin, Josh D.
    Noever, David
    Ciolino, Matt
    Hambrick, Dominick
    Dozier, Gerry
    DISRUPTIVE TECHNOLOGIES IN INFORMATION SCIENCES V, 2021, 11751
  • [42] Fortifying Machine Learning-Powered Intrusion Detection: A Defense Strategy Against Adversarial Black-Box Attacks
    Pujari, Medha
    Sun, Weiqing
    PROCEEDINGS OF NINTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, VOL 5, ICICT 2024, 2024, 1000 : 655 - 671
  • [43] Robust source camera identification against adversarial attacks
    Lin, Hui
    Wo, Yan
    Wu, Yuanlu
    Meng, Ke
    Han, Guoqiang
    COMPUTERS & SECURITY, 2021, 100
  • [44] A Self Supervised Defending Mechanism Against Adversarial Iris Attacks based on Wavelet Transform
    Meenakshi, K.
    Maragatham, G.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (02) : 564 - 569
  • [45] A Moving Target Defense against Adversarial Machine Learning
    Roy, Abhishek
    Chhabra, Anshuman
    Kamhoua, Charles A.
    Mohapatra, Prasant
    SEC'19: PROCEEDINGS OF THE 4TH ACM/IEEE SYMPOSIUM ON EDGE COMPUTING, 2019, : 383 - 388
  • [46] On the Defense Against Adversarial Examples Beyond the Visible Spectrum
    Ortiz, Anthony
    Fuentes, Olac
    Rosario, Dalton
    Kiekintveld, Christopher
    2018 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2018), 2018, : 553 - 558
  • [47] Minority Reports Defense: Defending Against Adversarial Patches
    McCoyd, Michael
    Park, Won
    Chen, Steven
    Shah, Neil
    Roggenkemper, Ryan
    Hwang, Minjune
    Liu, Jason Xinyu
    Wagner, David
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2020, 2020, 12418 : 564 - 582
  • [48] Approximate Manifold Defense Against Multiple Adversarial Perturbations
    Nandy, Jay
    Hsu, Wynne
    Lee, Mong Li
    2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [49] Defense against adversarial malware using robust classifier: DAM-ROC
    Selvaganapathy, Shymala Gowri
    Sadasivam, Sudha
    SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2022, 47 (04):
  • [50] PST: a More Practical Adversarial Learning-based Defense Against Website Fingerprinting
    Jiang, Minghao
    Wang, Yong
    Gou, Gaopeng
    Cai, Wei
    Xiong, Gang
    Shi, Junzheng
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,