Passer à la navigation principale Passer à la recherche Passer au contenu principal

A Data Augmentation-Based Defense Method Against Adversarial Attacks in Neural Networks

  • University of California, San Diego
  • Institut Polytechnique de Paris
  • Texas AM University-Commerce

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

56 Citations (Scopus)

Résumé

Deep Neural Networks (DNNs) in Computer Vision (CV) are well-known to be vulnerable to Adversarial Examples (AEs), namely imperceptible perturbations added maliciously to cause wrong classification results. Such variability has been a potential risk for systems in real-life equipped DNNs as core components. Numerous efforts have been put into research on how to protect DNN models from being tackled by AEs. However, no previous work can efficiently reduce the effects caused by novel adversarial attacks and be compatible with real-life constraints at the same time. In this paper, we focus on developing a lightweight defense method that can efficiently invalidate full whitebox adversarial attacks with the compatibility of real-life constraints. From basic affine transformations, we integrate three transformations with randomized coefficients that fine-tuned respecting the amount of change to the defended sample. Comparing to 4 state-of-art defense methods published in top-tier AI conferences in the past two years, our method demonstrates outstanding robustness and efficiency. It is worth highlighting that, our model can withstand advanced adaptive attack, namely BPDA with 50 rounds, and still helps the target model maintain an accuracy around 80%, meanwhile constraining the attack success rate to almost zero.

langue originaleAnglais
titreAlgorithms and Architectures for Parallel Processing - 20th International Conference, ICA3PP 2020, Proceedings
rédacteurs en chefMeikang Qiu
EditeurSpringer Science and Business Media Deutschland GmbH
Pages274-289
Nombre de pages16
ISBN (imprimé)9783030602383
Les DOIs
étatPublié - 1 janv. 2020
Evénement20th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2020 - New York, États-Unis
Durée: 2 oct. 20204 oct. 2020

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12453 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence20th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2020
Pays/TerritoireÉtats-Unis
La villeNew York
période2/10/204/10/20

Empreinte digitale

Examiner les sujets de recherche de « A Data Augmentation-Based Defense Method Against Adversarial Attacks in Neural Networks ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation