arrow
Return

LSD: Adversarial Examples Detection Based on Label Sequences Discrepancy

delete2023-01-01
delete2
PRE
AI
张士庚 (Shigeng Zhang)
S
Shuxin Chen
C
Chengyao Hua
Z
Zhetao Li
Y
Yanchun Li *
刘璇 cover
刘璇 (Xuan Liu) *
陈凯 (Kai Chen)
L
Li, Zhankai
王伟平 (Weiping Wang)
DOI:10.1109/TIFS.2023.3304455delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural network (DNN) models have been widely used in many tasks due to their superior performance. However, DNN models are usually vulnerable to adversarial example attacks, which limits their applications in many safety-critic scenarios. How to effectively detect adversarial examples to enhance the robustness of DNN models has attracted much attention in recent years. Most adversarial example detection methods require modifying or retraining the model, which is impractical and reduces the classification accuracy of normal examples. In this paper, we propose an adversarial example detection approach that does not require modification of the DNN models and meanwhile retains the classification accuracy of normal examples. The key observation is that when we transform the input example with some operations (e.g., masking a pixel with a reference value), feed the transformed example to the target model, and use the output of the intermediate layers to predict the label of the example, the generated label sequences of adversarial examples will be extremely discrepant but the label sequences of normal examples keep nearly unchanged. Motivated by this observation, we design an approach to detect adversarial examples based on the label sequence discrepancy (LSD) of the given examples. The experimental results against five mainstream adversarial attacks on three benchmark datasets demonstrate that LSD outperforms the state-of-the-art solutions in the detection rate of adversarial examples. Moreover, LSD performs well at various confidence levels and exhibits good generalizability between different attacks.
Keywords:
Perturbation methods
Artificial neural networks
Laser beams
Face recognition
Training
Robustness
Computer science
Adversarial detection
deep learning attacks
label sequences discrepancy
activation spaces

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

C
Central South University
Scholars:
10.0W
Papers: 7.2W
Citations: 10.9W
I
institute of information engineering, cas
Scholars:
474
Papers: 466
Citations: 0
X
xiangtan university
Scholars:
1.5W
Papers: 9.1K
Citations: 8
C
chinese academy of sciences
Scholars:
56.1W
Papers: 44.8W
Citations: 704
researcher View more organizations