arrow
Return

Adversarial example detection using semantic graph matching

delete2023-07-01
delete3
PRE
AI
Y
Yuxin Gong
王莘 (Shen Wang) *
X
Xunzhi Jiang
F
Fanghui Sun
DOI:10.1016/j.asoc.2023.110317delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural networks have recently been found to be vulnerable to adversarial examples, which can deceive attacked models with high confidence. This has given rise to significant security threats and raised doubts about the reliability of deploying deep learning models in security-critical domains. Therefore, effectively dealing with various adversarial examples has become an essential but challenging requirement. Adversarial example detection can predict the existence of adversarial examples in advance. However, existing detection methods are usually restricted to specific attacks, lacking generalization and decision-making bases. In this paper, we discover that the common characteristic of adversarial examples is to alter the semantic information recognized by models, which can effectively distinguish adversarial examples and provide interpretability. Based on this perspective, we propose a semantic graph matching (SeMatch) method to execute attack-agnostic adversarial example detection. SeMatch detects adversarial examples by comparing the constructed semantic graphs with the semantic graph prototypes of their predicted classes and further corrects their classification results. Experimental results demonstrate that SeMatch can effectively detect and classify adversarial examples in several attack settings, achieving an average detection and classification accuracy of 96.01% and 89.71%, respectively. When applied to unknown attack scenarios, SeMatch is more effective and interpretable than state-of-the-art methods. & COPY; 2023 Elsevier B.V. All rights reserved.
Keywords:
Deep learning
Security
Adversarial example detection
Generalization
Decision-making bases
Interpretability
Semantic graph
Attack-agnostic

Journal

Applied Soft Computing cover
Applied Soft Computing
IF:
6.6
Papers:
1.4W
Citations:
4.8W

Organization

H
harbin institute of technology
Scholars:
8.0W
Papers: 6.6W
Citations: 66