A Novel Adversarial Example Detection Method Based on Frequency Domain Reconstruction for Image Sensors

被引:0
|
作者
Huang, Shuaina [1 ,2 ,3 ]
Zhang, Zhiyong [1 ,2 ,3 ]
Song, Bin [1 ,2 ,3 ]
机构
[1] Henan Univ Sci & Technol, Informat Engn Coll, Luoyang 471023, Peoples R China
[2] Henan Univ Sci & Technol, Henan Int Joint Lab Cyberspace Secur Applicat, Luoyang 471023, Peoples R China
[3] Henan Univ Sci & Technol, Henan Intelligent Mfg Big Data Dev Innovat Lab, Luoyang 471023, Peoples R China
基金
中国国家自然科学基金;
关键词
adversarial detection; deep learning attacks; frequency domain; gradient masking; reconstruction;
D O I
10.3390/s24175507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Convolutional neural networks (CNNs) have been extensively used in numerous remote sensing image detection tasks owing to their exceptional performance. Nevertheless, CNNs are often vulnerable to adversarial examples, limiting the uses in different safety-critical scenarios. Recently, how to efficiently detect adversarial examples and improve the robustness of CNNs has drawn considerable focus. The existing adversarial example detection methods require modifying CNNs, which not only affects the model performance but also greatly enhances training cost. With the purpose of solving these problems, this study proposes a detection algorithm for adversarial examples that does not need modification of the CNN models and can simultaneously retain the classification accuracy of normal examples. Specifically, we design a method to detect adversarial examples using frequency domain reconstruction. After converting the input adversarial examples into the frequency domain by Fourier transform, the adversarial disturbance from adversarial attacks can be eliminated by modifying the frequency of the example. The inverse Fourier transform is then used to maximize the recovery of the original example. Firstly, we train a CNN to reconstruct input examples. Then, we insert Fourier transform, convolution operation, and inverse Fourier transform into the features of the input examples to automatically filter out adversarial frequencies. We refer to our proposed method as FDR (frequency domain reconstruction), which removes adversarial interference by converting input samples into frequency and reconstructing them back into the spatial domain to restore the image. In addition, we also introduce gradient masking into the proposed FDR method to enhance the detection accuracy of the model for complex adversarial examples. We conduct extensive experiments on five mainstream adversarial attacks on three benchmark datasets, and the experimental results show that FDR can outperform state-of-the-art solutions in detecting adversarial examples. Additionally, FDR does not require any modifications to the detector and can be integrated with other adversarial example detection methods to be installed in sensing devices to ensure detection safety.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] An Autocorrelation-Based Radio Frequency Interference Detection and Removal Method in Azimuth-Frequency Domain for SAR Image
    Natsuaki, Ryo
    Motohka, Takeshi
    Watanabe, Manabu
    Shimada, Masanobu
    Suzuki, Shinichi
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2017, 10 (12) : 5736 - 5751
  • [32] Enhanced Iris Recognition Method by Generative Adversarial Network-Based Image Reconstruction
    Lee, Min Beom
    Kang, Jin Kyu
    Yoon, Hyo Sik
    Park, Kang Ryoung
    IEEE ACCESS, 2021, 9 : 10120 - 10135
  • [33] An Image Reconstruction Algorithm Based on Frequency Domain for Deep Subcooling of Melt Drops
    Ning, Keqing
    Su, Ze
    Zhang, Zhihao
    Kim, Gwang-jun
    JOURNAL OF INTERNET TECHNOLOGY, 2021, 22 (06): : 1273 - 1285
  • [34] An Analytical Method for Face Detection Based on Image Patterns of EEG Signals in the Time-Frequency Domain
    Kashihara, Koji
    Ito, Momoyo
    Fukumi, Minoru
    2011 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2011, : 25 - 29
  • [35] A Novel Fault Detection Method Based on Adversarial Auto-Encoder
    Wang Jian
    Han Zhiyan
    PROCEEDINGS OF THE 39TH CHINESE CONTROL CONFERENCE, 2020, : 4166 - 4170
  • [36] Adversarial example detection based on saliency map features
    Wang, Shen
    Gong, Yuxin
    APPLIED INTELLIGENCE, 2022, 52 (06) : 6262 - 6275
  • [37] Adversarial example detection based on saliency map features
    Shen Wang
    Yuxin Gong
    Applied Intelligence, 2022, 52 : 6262 - 6275
  • [38] A Novel Method for Detection of Micro-Motion Target in Image Domain
    Jia, Yong
    Kong, Lingjiang
    Yang, Xiaobo
    Wang, Kunde
    2011 IEEE RADAR CONFERENCE (RADAR), 2011, : 99 - 102
  • [39] A Visual Saliency Detection Algorithm Based on the Image Anisotropic in the Frequency Domain
    Shen Yifeng
    Niu Yifeng
    Shen Lincheng
    2014 33RD CHINESE CONTROL CONFERENCE (CCC), 2014, : 4743 - 4746
  • [40] A Comparative Study of Frequency Domain Based Approaches for Image Tamper Detection
    Sharma, Ankita
    Singh, Preety
    TENCON 2015 - 2015 IEEE REGION 10 CONFERENCE, 2015,