A Novel Adversarial Example Detection Method Based on Frequency Domain Reconstruction for Image Sensors

被引:0
|
作者
Huang, Shuaina [1 ,2 ,3 ]
Zhang, Zhiyong [1 ,2 ,3 ]
Song, Bin [1 ,2 ,3 ]
机构
[1] Henan Univ Sci & Technol, Informat Engn Coll, Luoyang 471023, Peoples R China
[2] Henan Univ Sci & Technol, Henan Int Joint Lab Cyberspace Secur Applicat, Luoyang 471023, Peoples R China
[3] Henan Univ Sci & Technol, Henan Intelligent Mfg Big Data Dev Innovat Lab, Luoyang 471023, Peoples R China
基金
中国国家自然科学基金;
关键词
adversarial detection; deep learning attacks; frequency domain; gradient masking; reconstruction;
D O I
10.3390/s24175507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Convolutional neural networks (CNNs) have been extensively used in numerous remote sensing image detection tasks owing to their exceptional performance. Nevertheless, CNNs are often vulnerable to adversarial examples, limiting the uses in different safety-critical scenarios. Recently, how to efficiently detect adversarial examples and improve the robustness of CNNs has drawn considerable focus. The existing adversarial example detection methods require modifying CNNs, which not only affects the model performance but also greatly enhances training cost. With the purpose of solving these problems, this study proposes a detection algorithm for adversarial examples that does not need modification of the CNN models and can simultaneously retain the classification accuracy of normal examples. Specifically, we design a method to detect adversarial examples using frequency domain reconstruction. After converting the input adversarial examples into the frequency domain by Fourier transform, the adversarial disturbance from adversarial attacks can be eliminated by modifying the frequency of the example. The inverse Fourier transform is then used to maximize the recovery of the original example. Firstly, we train a CNN to reconstruct input examples. Then, we insert Fourier transform, convolution operation, and inverse Fourier transform into the features of the input examples to automatically filter out adversarial frequencies. We refer to our proposed method as FDR (frequency domain reconstruction), which removes adversarial interference by converting input samples into frequency and reconstructing them back into the spatial domain to restore the image. In addition, we also introduce gradient masking into the proposed FDR method to enhance the detection accuracy of the model for complex adversarial examples. We conduct extensive experiments on five mainstream adversarial attacks on three benchmark datasets, and the experimental results show that FDR can outperform state-of-the-art solutions in detecting adversarial examples. Additionally, FDR does not require any modifications to the detector and can be integrated with other adversarial example detection methods to be installed in sensing devices to ensure detection safety.
引用
收藏
页数:20
相关论文
共 50 条
  • [21] Hybrid generative adversarial network based on frequency and spatial domain for histopathological image synthesis
    Qifeng Liu
    Tao Zhou
    Chi Cheng
    Jin Ma
    Marzia Hoque Tania
    BMC Bioinformatics, 26 (1)
  • [22] A Method for Image Anomaly Detection Based on Distillation and Reconstruction
    Luo, Jiaxiang
    Zhang, Jianzhao
    SENSORS, 2023, 23 (22)
  • [23] A generalized novel image forgery detection method using generative adversarial network
    Sharma, Preeti
    Kumar, Manoj
    Sharma, Hitesh Kumar
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 83 (18) : 53549 - 53580
  • [24] A generalized novel image forgery detection method using generative adversarial network
    Preeti Sharma
    Manoj Kumar
    Hitesh Kumar Sharma
    Multimedia Tools and Applications, 2024, 83 : 53549 - 53580
  • [25] Frequency domain algebraic image reconstruction technique
    Zheng, YB
    CONFERENCE RECORD OF THE THIRTY-EIGHTH ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS & COMPUTERS, VOLS 1 AND 2, 2004, : 178 - 182
  • [26] Image Adversarial Example Generation Method Based on Adaptive Parameter Adjustable Differential Evolution
    Lin, Zhiyi
    Peng, Changgen
    Tan, Weijie
    He, Xing
    ENTROPY, 2023, 25 (03)
  • [27] Image Saliency Detection Algorithm Based on Spatial and Frequency Domain
    Sun, Xiaofei
    Pan, Wenwen
    Yuan, Wei
    Wang, Lei
    Yang, Bin
    Wang, Xia
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON VIRTUAL REALITY (ICVR 2018), 2018, : 89 - 94
  • [28] Malware detection method based on image analysis and generative adversarial networks
    Liu, Yanhua
    Li, Jiaqi
    Liu, Baoxu
    Gao, Xiaoling
    Liu, Ximeng
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (22):
  • [29] A novel Image-Data-Driven and Frequency-Based method for depression detection
    Zhao, Jian
    Zhang, Lan
    Cui, Yihai
    Shi, Jia
    He, Lang
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2023, 86
  • [30] Class Reconstruction Driven Adversarial Domain Adaptation for Hyperspectral Image Classification
    Pande, Shivam
    Banerjee, Biplab
    Pizurica, Aleksandra
    PATTERN RECOGNITION AND IMAGE ANALYSIS, PT I, 2020, 11867 : 472 - 484