Adversarial Attack and Defense in Deep Ranking

被引:2
|
作者
Zhou, Mo [1 ]
Wang, Le [3 ,1 ]
Niu, Zhenxing [2 ]
Zhang, Qilin [3 ]
Zheng, Nanning
Hua, Gang
机构
[1] Jiaotong Univ, Inst Artificial Intelligence & Robot, Xian 710049, Peoples R China
[2] Xidian Univ, Xidian 710071, CA, Peoples R China
[3] Apple, Cupertino, CA 95014 USA
基金
国家重点研发计划;
关键词
Robustness; Perturbation methods; Glass box; Training; Face recognition; Adaptation models; Task analysis; Adversarial attack; adversarial defense; deep metric learning; deep ranking; ranking model robustness; IMAGE SIMILARITY;
D O I
10.1109/TPAMI.2024.3365699
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Network classifiers are vulnerable to adversarial attacks, where an imperceptible perturbation could result in misclassification. However, the vulnerability of DNN-based image ranking systems remains under-explored. In this paper, we propose two attacks against deep ranking systems, i.e., Candidate Attack and Query Attack, that can raise or lower the rank of chosen candidates by adversarial perturbations. Specifically, the expected ranking order is first represented as a set of inequalities. Then a triplet-like objective function is designed to obtain the optimal perturbation. Conversely, an anti-collapse triplet defense is proposed to improve the ranking model robustness against all proposed attacks, where the model learns to prevent the adversarial attack from pulling the positive and negative samples close to each other. To comprehensively measure the empirical adversarial robustness of a ranking model with our defense, we propose an empirical robustness score, which involves a set of representative attacks against ranking models. Our adversarial ranking attacks and defenses are evaluated on MNIST, Fashion-MNIST, CUB200-2011, CARS196, and Stanford Online Products datasets. Experimental results demonstrate that our attacks can effectively compromise a typical deep ranking system. Nevertheless, our defense can significantly improve the ranking system's robustness and simultaneously mitigate a wide range of attacks.
引用
收藏
页码:5306 / 5324
页数:19
相关论文
共 50 条
  • [41] Diversity Adversarial Training against Adversarial Attack on Deep Neural Networks
    Kwon, Hyun
    Lee, Jun
    SYMMETRY-BASEL, 2021, 13 (03):
  • [42] Adversarial attack defense algorithm based on convolutional neural network
    Zhang, Chengyuan
    Wang, Ping
    NEURAL COMPUTING & APPLICATIONS, 2023, 36 (17): : 9723 - 9735
  • [43] Gradient Sign Inversion: Making an Adversarial Attack a Good Defense
    Ji, Xiaojian
    Dong, Li
    Wang, Rangding
    Yan, Diqun
    Yin, Yang
    Tian, Jinyu
    2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [44] Autonomous Driving Model Defense Study on Hijacking Adversarial Attack
    Shibly, Kabid Hassan
    Hossain, Md Delwar
    Inoue, Hiroyuki
    Taenaka, Yuzo
    Kadobayashi, Youki
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2022, PT IV, 2022, 13532 : 546 - 557
  • [45] Defense Against Adversarial Attacks in Deep Learning
    Li, Yuancheng
    Wang, Yimeng
    APPLIED SCIENCES-BASEL, 2019, 9 (01):
  • [46] Adversarial Metric Attack and Defense for Person Re-Identification
    Bai, Song
    Li, Yingwei
    Zhou, Yuyin
    Li, Qizhu
    Torr, Philip H. S.
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2021, 43 (06) : 2119 - 2126
  • [47] Adversarial Sample Attack and Defense Method for Encrypted Traffic Data
    Ding, Yi
    Zhu, Guiqin
    Chen, Dajiang
    Qin, Xue
    Cao, Mingsheng
    Qin, Zhiguang
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (10) : 18024 - 18039
  • [48] Adversarial Perturbation Defense on Deep Neural Networks
    Zhang, Xingwei
    Zheng, Xiaolong
    Mao, Wenji
    ACM COMPUTING SURVEYS, 2021, 54 (08)
  • [49] Towards Robust Ensemble Defense Against Adversarial Examples Attack
    Mani, Nag
    Moh, Melody
    Moh, Teng-Sheng
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [50] Adversarial Attack and Defense for Webshell Detection on Machine Learning Models
    Zhang, Qian
    Chen, Lishen
    Yan, Qiao
    2022 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY, CYBERC, 2022, : 33 - 41