A Novel Adversarial Example Detection Method Based on Frequency Domain Reconstruction for Image Sensors

被引:0
|
作者
Huang, Shuaina [1 ,2 ,3 ]
Zhang, Zhiyong [1 ,2 ,3 ]
Song, Bin [1 ,2 ,3 ]
机构
[1] Henan Univ Sci & Technol, Informat Engn Coll, Luoyang 471023, Peoples R China
[2] Henan Univ Sci & Technol, Henan Int Joint Lab Cyberspace Secur Applicat, Luoyang 471023, Peoples R China
[3] Henan Univ Sci & Technol, Henan Intelligent Mfg Big Data Dev Innovat Lab, Luoyang 471023, Peoples R China
基金
中国国家自然科学基金;
关键词
adversarial detection; deep learning attacks; frequency domain; gradient masking; reconstruction;
D O I
10.3390/s24175507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Convolutional neural networks (CNNs) have been extensively used in numerous remote sensing image detection tasks owing to their exceptional performance. Nevertheless, CNNs are often vulnerable to adversarial examples, limiting the uses in different safety-critical scenarios. Recently, how to efficiently detect adversarial examples and improve the robustness of CNNs has drawn considerable focus. The existing adversarial example detection methods require modifying CNNs, which not only affects the model performance but also greatly enhances training cost. With the purpose of solving these problems, this study proposes a detection algorithm for adversarial examples that does not need modification of the CNN models and can simultaneously retain the classification accuracy of normal examples. Specifically, we design a method to detect adversarial examples using frequency domain reconstruction. After converting the input adversarial examples into the frequency domain by Fourier transform, the adversarial disturbance from adversarial attacks can be eliminated by modifying the frequency of the example. The inverse Fourier transform is then used to maximize the recovery of the original example. Firstly, we train a CNN to reconstruct input examples. Then, we insert Fourier transform, convolution operation, and inverse Fourier transform into the features of the input examples to automatically filter out adversarial frequencies. We refer to our proposed method as FDR (frequency domain reconstruction), which removes adversarial interference by converting input samples into frequency and reconstructing them back into the spatial domain to restore the image. In addition, we also introduce gradient masking into the proposed FDR method to enhance the detection accuracy of the model for complex adversarial examples. We conduct extensive experiments on five mainstream adversarial attacks on three benchmark datasets, and the experimental results show that FDR can outperform state-of-the-art solutions in detecting adversarial examples. Additionally, FDR does not require any modifications to the detector and can be integrated with other adversarial example detection methods to be installed in sensing devices to ensure detection safety.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] A Novel Medical Image Denoising Method Based on Conditional Generative Adversarial Network
    Li, Yuqin
    Zhang, Ke
    Shi, Weili
    Miao, Yu
    Jiang, Zhengang
    COMPUTATIONAL AND MATHEMATICAL METHODS IN MEDICINE, 2021, 2021
  • [42] Saliency Detection Method Based on Multiscale Analysis in Frequency Domain
    Wu Q.
    Yu Y.
    Yang J.
    Shao K.
    Kang Y.
    Jisuanji Fuzhu Sheji Yu Tuxingxue Xuebao/Journal of Computer-Aided Design and Computer Graphics, 2020, 32 (01): : 68 - 78
  • [43] Domain Specific Convolution and High Frequency Reconstruction Based Unsupervised Domain Adaptation for Medical Image Segmentation
    Hu, Shishuai
    Liao, Zehui
    Xia, Yong
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION, MICCAI 2022, PT VII, 2022, 13437 : 650 - 659
  • [44] Adversarial Example Generation Method Based on Sensitive Features
    WEN Zerui
    SHEN Zhidong
    SUN Hui
    QI Baiwen
    Wuhan University Journal of Natural Sciences, 2023, 28 (01) : 35 - 44
  • [45] Sparse perturbation based adversarial example generation method
    Ji S.-H.
    Hu L.-M.
    Zhang P.-C.
    Qi R.-Z.
    Ruan Jian Xue Bao/Journal of Software, 2023, 34 (09):
  • [46] Method for Improved Image Reconstruction in Computed Tomography and Positron Emission Tomography, Based on Compressive Sensing with Prefiltering in the Frequency Domain
    Garcia, Y.
    Franco, C.
    Miosso, C. J.
    XXVII BRAZILIAN CONGRESS ON BIOMEDICAL ENGINEERING, CBEB 2020, 2022, : 2019 - 2025
  • [47] Adversarial Example Generation Method Based on Style Transfer
    Yu, Zhcnhua
    Yin, Zheng
    Ye, Ou
    Cong, Xuya
    Hsi-An Chiao Tung Ta Hsueh/Journal of Xi'an Jiaotong University, 2024, 58 (07): : 191 - 202
  • [48] Delving into Deep Image Prior for Adversarial Defense: A Novel Reconstruction-based Defense Framework
    Ding, Li
    Wang, Yongwei
    Ding, Xin
    Yuan, Kaiwen
    Wang, Ping
    Huang, Hua
    Wang, Z. Jane
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 4564 - 4572
  • [49] A NOVEL METHOD FOR INVARIANT IMAGE RECONSTRUCTION
    Pawlak, Miroslaw
    Panesar, Gurmukh Singh
    Korytkowski, Marcin
    JOURNAL OF ARTIFICIAL INTELLIGENCE AND SOFT COMPUTING RESEARCH, 2021, 11 (01) : 69 - 80
  • [50] ADS-detector: An attention-based dual stream adversarial example detection method
    Guo, Sensen
    Li, Xiaoyu
    Zhu, Peican
    Mu, Zhiying
    KNOWLEDGE-BASED SYSTEMS, 2023, 265