arrow
Return

Detecting adversarial examples using image reconstruction differences

delete2023-03-17
delete3
PRE
AI
J
Jiaze Sun *
M
Meng Yi
DOI:10.1007/s00500-023-07961-zdelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The adversarial examples (AEs) cause misjudgments and damage the robustness of the DNNs systems. Previous studies have defended against AEs by detecting, but it is challenging to ensure a stable and high performance of detecting AEs, while with a poor false detection. To this end, an AEs detection method named image reconstruction differences (IRD) is proposed to enhance the robustness of DNNs. Firstly, we use an end-to-end Com-Rec network to reconstruct examples with feature compression to expand the distinguishing features. Secondly, propose an image reconstruction differences based on information-theoretic VIF, structural information UQI and spectral information RASE composition to discriminate AEs. Moreover, we introduce the idea of integrated learning to form a strong random forest binary classifier to enhance the performance of detecting AEs. We further validate it through extensive experiments on the MNIST and CIFAR-10 datasets. These experiments demonstrated that the IRD effectively detected AEs and achieved a high average accuracy of 98.33%. Specifically it also performs favorably against the following methods based on Feature Squeezing, Local Intrinsic Dimensionality, Kernel Density and Network Invariance Checking with an average detection rate of 99.54% and a 1.44% average false positive rate.
Keywords:
Deep neural networks
Adversarial examples
Detection
Compress and reconstruct
Image reconstruction differences
Random forest

Journal

Soft Computing cover
Soft Computing
IF:
2.5
Papers:
1.0W
Citations:
2.1W

Organization

No organization information available
Cited Papers

Cited Papers

Adversarial example detection for DNN models: a review and experimental comparison
err2022-01-06
err68
PREAI
errAldahdooh, Ahmed; Hamidouche, Wassim; Fezza, Sid Ahmed; Deforges, Olivier
errShare
errSave
Uncertainty estimation for stereo matching based on evidential deep learning
err2022-04-01
err120
errOAAI
errWang, Chen; Wang, Xiang; Zhang, Jiawei; Zhang, Liang; Bai, Xiao; Ning, Xin; Zhou, Jun; Hancock, Edwin
errShare
errSave
A PCR-based protocol for the generation of a recombinant West Nile virus
err2009-09-01
err0
PREAI
errAkihiko Maeda; Ryo Murata; Minoru Akiyama; Ikuo Takashima; Hiroaki Kariwa; Tomomasa Watanabe; Ichiro Kurane; Junko Maeda
errShare
errSave
The Early Cambrian Mianyang-Changning Intracratonic Sag and Its Control on Petroleum Accumulation in the Sichuan Basin, China
err2017-01-01
err0
errOAAI
errShugen Liu; Bin Deng; Luba Jansa; Yong Zhong; Wei Sun; Jinmin Song; Guozhi Wang; Juan Wu; Zhiwu Li; Yanhong Tian
errShare
errSave
Self-Supervised Deep Correlation Tracking
err2021-01-01
err222
PREAI
errYuan, Di; Chang, Xiaojun; Huang, Po-Yao; Liu, Qiao; He, Zhenyu
errShare
errSave
Dual discriminator adversarial distillation for data-free model compression
err2021-10-25
err14
PREAI
errZhao, Haoran; Sun, Xin; Dong, Junyu; Manic, Milos; Zhou, Huiyu; Yu, Hui
errShare
errSave
Adversarial Attacks and Defenses in Images, Graphs and Text: A Review
err2020-03-27
err396
errOAAI
errXu, Han; Ma, Yao; Liu, Hao-Chen; Deb, Debayan; Liu, Hui; Tang, Ji-Liang; Jain, Anil K.
errShare
errSave
researcher View more