A Novel Adversarial Example Detection Method Based on Frequency Domain Reconstruction for Image Sensors

被引:0
|
作者
Huang, Shuaina [1 ,2 ,3 ]
Zhang, Zhiyong [1 ,2 ,3 ]
Song, Bin [1 ,2 ,3 ]
机构
[1] Henan Univ Sci & Technol, Informat Engn Coll, Luoyang 471023, Peoples R China
[2] Henan Univ Sci & Technol, Henan Int Joint Lab Cyberspace Secur Applicat, Luoyang 471023, Peoples R China
[3] Henan Univ Sci & Technol, Henan Intelligent Mfg Big Data Dev Innovat Lab, Luoyang 471023, Peoples R China
基金
中国国家自然科学基金;
关键词
adversarial detection; deep learning attacks; frequency domain; gradient masking; reconstruction;
D O I
10.3390/s24175507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Convolutional neural networks (CNNs) have been extensively used in numerous remote sensing image detection tasks owing to their exceptional performance. Nevertheless, CNNs are often vulnerable to adversarial examples, limiting the uses in different safety-critical scenarios. Recently, how to efficiently detect adversarial examples and improve the robustness of CNNs has drawn considerable focus. The existing adversarial example detection methods require modifying CNNs, which not only affects the model performance but also greatly enhances training cost. With the purpose of solving these problems, this study proposes a detection algorithm for adversarial examples that does not need modification of the CNN models and can simultaneously retain the classification accuracy of normal examples. Specifically, we design a method to detect adversarial examples using frequency domain reconstruction. After converting the input adversarial examples into the frequency domain by Fourier transform, the adversarial disturbance from adversarial attacks can be eliminated by modifying the frequency of the example. The inverse Fourier transform is then used to maximize the recovery of the original example. Firstly, we train a CNN to reconstruct input examples. Then, we insert Fourier transform, convolution operation, and inverse Fourier transform into the features of the input examples to automatically filter out adversarial frequencies. We refer to our proposed method as FDR (frequency domain reconstruction), which removes adversarial interference by converting input samples into frequency and reconstructing them back into the spatial domain to restore the image. In addition, we also introduce gradient masking into the proposed FDR method to enhance the detection accuracy of the model for complex adversarial examples. We conduct extensive experiments on five mainstream adversarial attacks on three benchmark datasets, and the experimental results show that FDR can outperform state-of-the-art solutions in detecting adversarial examples. Additionally, FDR does not require any modifications to the detector and can be integrated with other adversarial example detection methods to be installed in sensing devices to ensure detection safety.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Adversarial example detection by predicting adversarial noise in the frequency domain
    Seunghwan Jung
    Minyoung Chung
    Yeong-Gil Shin
    Multimedia Tools and Applications, 2023, 82 : 25235 - 25251
  • [2] Adversarial example detection by predicting adversarial noise in the frequency domain
    Jung, Seunghwan
    Chung, Minyoung
    Shin, Yeong-Gil
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 82 (16) : 25235 - 25251
  • [3] Adversarial Example Detection Method Based on Image Denoising and Image Generation
    Yang H.
    Yang F.
    Hunan Daxue Xuebao/Journal of Hunan University Natural Sciences, 2023, 50 (08): : 72 - 81
  • [4] Adversarial example defense based on image reconstruction
    Zhang, Yu
    Xu, Huan
    Pei, Chengfei
    Yang, Gaoming
    PEERJ COMPUTER SCIENCE, 2021, 7
  • [5] Image reconstruction method based on CCD calibration in frequency domain
    Xiong, Sheng-Jun
    Bin Xiangli
    He, Yang
    Zhang, Ze
    APPLIED OPTICS, 2015, 54 (14) : 4561 - 4565
  • [6] AEGuard: Image Feature-Based Independent Adversarial Example Detection Model
    Kim, Mihui
    Yun, Junhyeok
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [7] Image reconstruction based on frequency domain feature extraction for EMT
    Huang, Guoxing
    Qian, Wenqing
    Wang, Jingwen
    Lu, Weidang
    Peng, Hong
    MEASUREMENT SCIENCE AND TECHNOLOGY, 2021, 32 (10)
  • [8] Image Reconstruction by Derivatives in Frequency Domain
    Shen, J.
    MEDICAL PHYSICS, 2011, 38 (06)
  • [9] A NOVEL SHIP WAKE DETECTION METHOD OF SAR IMAGES BASED ON FREQUENCY DOMAIN
    Liu Hao Zhu Minhui (Nat. Key Lab. of Microwave Imaging Tech.
    Journal of Electronics(China), 2003, (04) : 313 - 320
  • [10] Research on Adversarial Sample Detection Method Based on Image Similarity
    Wu, Xiaoxue
    Zuo, Shuqi
    Weng, Shiyu
    Jiang, Yongkang
    Huang, Hao
    JOURNAL OF INTERNET TECHNOLOGY, 2024, 25 (01): : 147 - 155