arrow
返回

AdvCheck: Characterizing adversarial examples via local gradient checking

delete2024-01-01
delete0
delete
OA
AI
R
Ruoxi Chen
H
Haibo Jin
陈
陈晋音 (Jinyin Chen) *
H
Haibin Zheng
S
Shilian Zheng
X
Xiaoniu Yang
X
Xing Yang
DOI:10.1016/j.cose.2023.103540delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Deep neural networks (DNNs) are vulnerable to adversarial examples, which may lead to catastrophe in security-critical domains. Numerous detection methods are proposed to characterize the feature uniqueness of adversarial examples, or to distinguish DNN's behavior activated by the adversarial examples. Detections based on features may be compromised when faced with stronger attacks. Besides, they require a large amount of specific adversarial examples. Another mainstream, model-based detections, which characterize input properties by model behaviors, suffer from heavy computation cost. To address the issues, we introduce the concept of local gradient, and reveal that adversarial examples have a quite larger bound of local gradient than the benign ones. Inspired by the observation, we leverage local gradient for detecting adversarial examples, and propose a general framework AdvCheck. Specifically, by calculating the local gradient from a few benign examples and noise-added misclassified examples to train a detector, adversarial examples and even misclassified natural inputs can be precisely distinguished from benign ones. Through extensive experiments, we have validated the AdvCheck's superior performance to the state-of-the-art (SOTA) baselines, with detection rate (similar to x1.2) on general adversarial attacks and (similar to x1.4) on misclassified natural inputs on average, with average 1/200 time cost. We also provide interpretable results for successful detection.
Keyword:
Adversarial attack
Adversarial detection
Local gradient
Deep neural network
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

Z
zhejiang university of technology
学者数:
3.3W
论文数: 2.0W
被引数: 22
N
national university of defense technology - china
学者数:
1.8W
论文数: 1.4W
被引数: 9
引用论文

引用论文

Facial attributes: Accuracy and adversarial robustness
err2019-06-01
err32
errOAAI
errRozsa, Andras; Gunther, Manuel; Rudd, Ethan M.; Boult, Terrance E.
err分享
err收藏
Mask-guided noise restriction adversarial attacks for image classification
err2021-01-01
err13
PREAI
errDuan, Yexin; Zhou, Xingyu; Zou, Junhua; Qiu, Junyang; Zhang, Jin; Pan, Zhisong
err分享
err收藏
ImageNet Large Scale Visual Recognition ChallengeImageNet大规模视觉识别挑战
err2015-04-11
err2.7W
PREAI
errRussakovsky, Olga; Deng, Jia; Su, Hao; Krause, Jonathan; Satheesh, Sanjeev; Ma, Sean; Huang, Zhiheng; Karpathy, Andrej; Khosla, Aditya; Bernstein, Michael; Berg, Alexander C.; Fei-Fei, Li
err分享
err收藏
FineFool: A novel DNN object contour attack on image recognition based on the attention perturbation adversarial technique
err2021-05-01
err24
PREAI
errChen, Jinyin; Zheng, Haibin; Xiong, Hui; Chen, Ruoxi; Du, Tianyu; Hong, Zhen; Ji, Shouling
err分享
err收藏
学者 查看更多内容