arrow
Return

Detecting Adversarial Samples for Deep Learning Models: A Comparative Study

delete2022-01-01
delete14
PRE
AI
张士庚 (Shigeng Zhang)
S
Shuxin Chen
刘璇 cover
刘璇 (Xuan Liu) *
C
Chengyao Hua
王伟平 (Weiping Wang)
陈凯 (Kai Chen)
J
Jian Zhang *
王健行 cover
王健行 (Jianxin Wang)
DOI:10.1109/TNSE.2021.3057071delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep learning techniques such as convolutional neural networks (CNNs) have been used in a wide range of fields due to their superior performance, e.g., image classification, autonomous driving and natural language processing. However, recent progress shows that deep learning models are vulnerable to adversarial samples, which are crafted by adding small perturbations on normal samples that are imperceptible to human beings but can mislead the deep learning models to output incorrect results. Many adversarial attack models are proposed and many adversarial detection methods are developed to detect adversarial samples generated by these attack models. However, the evaluations of these detection methods are fragmented and scatter in separate literature, and the community still lacks a comprehensive understanding of the ability and performance of existing adversarial detection methods when facing different attack models on different datasets. In this paper, by using image classification as the example application scenario, we conduct a comprehensive study on the performance of five mainstream adversarial detection methods against five major attack models on four widely used benchmark datasets. We find that the detection accuracy of different methods interleaves for different attack models and dataset. Moreover, besides detection accuracy, we also evaluate the time efficiency of different detection methods. The findings reported in this paper can provide useful insights when designing systems to detect adversarial samples and act as a guideline to design new methods to detect adversarial samples.
Keywords:
Training
Neural networks
Deep learning
Detectors
Robustness
Predictive models
Safety
Adversarial detection efficiency
adversarial samples detection
deep learning attacks
image classification
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

I
IEEE Transactions on Network Science and Engineering
IF:
7.9
Papers:
2.5K
Citations:
10.0K

Organization

C
Central South University
Scholars:
10.0W
Papers: 7.2W
Citations: 10.9W
I
institute of information engineering, cas
Scholars:
474
Papers: 466
Citations: 0
C
chinese academy of sciences
Scholars:
56.2W
Papers: 44.8W
Citations: 704
researcher View more organizations