DunDi: Improving Robustness of Neural Networks Using Distance Metric Learning

被引:1
作者
Cui, Lei [1 ]
Xi, Rongrong [1 ]
Hao, Zhiyu [1 ]
Yu, Xuehao [2 ]
Zhang, Lei [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] State Grid Informat & Telecommun Branch, Beijing, Peoples R China
来源
COMPUTATIONAL SCIENCE - ICCS 2019, PT II | 2019年 / 11537卷
基金
北京市自然科学基金; 中国国家自然科学基金;
关键词
Robustness; Deep neural network; Metric learning;
D O I
10.1007/978-3-030-22741-8_11
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The deep neural networks (DNNs), although highly accurate, are vulnerable to adversarial attacks. A slight perturbation applied to a sample may lead to misprediction of the DNN, even it is imperceptible to humans. This defect makes the DNN lack of robustness to malicious perturbations, and thus limits their usage in many safety-critical systems. To this end, we present DunDi, a metric learning based classification model, to provide the ability to defend adversarial attacks. The key idea behind DunDi is a metric learning model which is able to pull samples of the same label together meanwhile pushing samples of different labels away. Consequently, the distance between samples and model's boundary can be enlarged accordingly, so that significant perturbations are required to fool the model. Then, based on the distance comparison, we propose a two-step classification algorithm that performs efficiently for multi-class classification. DunDi can not only build and train a new customized model but also support the incorporation of the available pre-trained neural network models to take full advantage of their capabilities. The results show that DunDi is able to defend 94.39% and 88.91% of adversarial samples generated by four state-of-the-art adversarial attacks on the MNIST dataset and CIFAR-10 dataset, without hurting classification accuracy.
引用
收藏
页码:145 / 159
页数:15
相关论文
共 50 条
[31]   ε-Weakened Robustness of Deep Neural Networks [J].
Huang, Pei ;
Yang, Yuting ;
Liu, Minghao ;
Jia, Fuqi ;
Ma, Feifei ;
Zhang, Jian .
PROCEEDINGS OF THE 31ST ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2022, 2022, :126-138
[32]   The geometry of robustness in spiking neural networks [J].
Calaim, Nuno ;
Dehmelt, Florian A. ;
Goncalves, Pedro J. ;
Machens, Christian K. .
ELIFE, 2022, 11
[33]   Stochasticity and robustness in spiking neural networks [J].
Olin-Ammentorp, Wilkie ;
Beckmann, Karsten ;
Schuman, Catherine D. ;
Plank, James S. ;
Cady, Nathaniel C. .
NEUROCOMPUTING, 2021, 419 :23-36
[34]   Quantitative Robustness Analysis of Neural Networks [J].
Downing, Mara .
PROCEEDINGS OF THE 32ND ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2023, 2023, :1527-1531
[35]   Robustness of Compressed Convolutional Neural Networks [J].
Wijayanto, Arie Wahyu ;
Jin, Choong Jun ;
Madhawa, Kaushalya ;
Murata, Tsuyoshi .
2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, :4829-4836
[36]   Parking Space Occupancy Verification Improving Robustness using a Convolutional Neural Network [J].
Jensen, Troels H. P. ;
Schmidt, Helge T. ;
Bodin, Niels D. ;
Nasrollahi, Kamal ;
Moeslund, Thomas B. .
PROCEEDINGS OF THE 12TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER VISION, IMAGING AND COMPUTER GRAPHICS THEORY AND APPLICATIONS (VISIGRAPP 2017), VOL 5, 2017, :311-318
[37]   Robustness Against Adversarial Attacks in Neural Networks Using Incremental Dissipativity [J].
Aquino, Bernardo ;
Rahnama, Arash ;
Seiler, Peter ;
Lin, Lizhen ;
Gupta, Vijay .
IEEE CONTROL SYSTEMS LETTERS, 2022, 6 :2341-2346
[38]   MGR: Metric Learning with Graph Neural Networks for Multi-behavior Recommendation [J].
Yuan, Yuan ;
Tang, Yan ;
Du, Luomin ;
Chen, Yingpei .
KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT I, 2022, 13368 :466-477
[39]   IMPROVING ROBUSTNESS OF DEEP NETWORKS USING CLUSTER-BASED ADVERSARIAL TRAINING [J].
Rasheed, Bader ;
Khan, Adil .
RUSSIAN LAW JOURNAL, 2023, 11 (09) :412-420
[40]   A Genetic Algorithm for Improving Robustness of Complex Networks [J].
Pizzuti, Clara ;
Socievole, Annalisa .
2018 IEEE 30TH INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI), 2018, :514-521