返回
Feature autoencoder for detecting adversarial examples
DOI:10.1002/int.22889.png)
摘要
En 中文
Deep neural networks (DNNs) have gained widespread adoption in computer vision. Unfortunately, state-of-the-art DNNs are vulnerable to adversarial example (AE) attacks, where an adversary introduces imperceptible perturbations to a test example for defrauding DNNs. The obstacles have urged intensive research on improving the DNN robustness via adversarial training, that is, the clean data set is blended with adversarial examples to carry out training. However, the adversarial example attack technologies are open-ended, and the adversarial training is insufficient to focus on improving robustness performance. To circumvent this limitation, we mitigate adversarial example attacks from another perspective, which aims at detecting adversarial examples. Feature autoencoder detector (FADetector), a novel defense framework that exploits feature knowledge is proposed. One of the hallmarks of FADetector is to not involve adversarial examples to train the detector. Our extensive evaluation on MNIST and CIFAR-10 data sets demonstrates that our defense outperforms the conventional autoencoder detectors in terms of detection accuracy.
Keyword:
adversarial attack
adversarial detection
adversarial example
feature autoencoder
期刊
IF:
3.7
论文数:
3.1K
被引数:
8.1K
机构
引用论文
Hybrid sequence-based Android malware detection using natural language processing基于混合序列的自然语言处理Android恶意软件检测
Advanced variations of two-dimensional principal component analysis for face recognition
NEUROCOMPUTING
IF6.5
An empirical study of supervised email classification in Internet of Things: Practical performance and key influencing factors物联网中监督邮件分类的实证研究: 实际性能与关键影响因素

