An active learning framework for adversarial training of deep neural networks

被引:0
|
作者
Susmita Ghosh [1 ]
Abhiroop Chatterjee [1 ]
Lance Fiondella [2 ]
机构
[1] Jadavpur University,Department of Computer Science and Engineering
[2] University of Massachusetts,Department of Electrical and Computer Engineering
关键词
Adversarial attacks; Deep neural network; FGSM; PGD; Active learning;
D O I
10.1007/s00521-024-10851-6
中图分类号
学科分类号
摘要
This article introduces a novel approach to bolster the robustness of Deep Neural Network (DNN) models against adversarial attacks named “Targeted Adversarial Resilience Learning (TARL)”. The initial evaluation of a baseline DNN model reveals a significant accuracy decline when subjected to adversarial examples generated through techniques like FGSM, PGD, Carlini Wagner, and DeepFool attacks. To address this vulnerability, the article proposes an active learning framework, wherein the model iteratively identifies and learns from the most uncertain and misclassified instances. The key components of this approach include uncertainty estimation score in predicting the class of the input sample, selecting challenging samples based on this uncertainty score, labeling these challenging examples and augmenting them into the training set, and thereafter retraining the model with the expanded training set. The iterative active learning process, governed by parameters such as the number of iterations and batch size, demonstrates the potential to systematically enhance the resilience of DNN against adversarial threats. The proposed methodology has been investigated on several popular datasets such as the SARS-CoV-2 CT scan, MNIST, CIFAR-10, and Caltech-101, and demonstrated to be effective. Experiments illustrate that the learning framework improves the adversarial accuracies from 17.4% to 98.71% for the SARS-CoV-2 dataset, from 8.4% to 99.89% for the MNIST dataset, 1.6% to 78.84% for the CIFAR-10, and 12% to 92.92% for Caltech-101. Further, comparative analysis with several state-of-the-art methods suggests that the proposed framework offers superior defense against various attack methods and offers promising defensive mechanisms to deep neural networks.
引用
收藏
页码:6849 / 6876
页数:27
相关论文
共 50 条
  • [41] Counterfactual Domain Adversarial Training of Neural Networks
    Abdullahi, Umar, I
    Samothrakis, Spyros
    Fasli, Maria
    2017 INTERNATIONAL CONFERENCE ON THE FRONTIERS AND ADVANCES IN DATA SCIENCE (FADS), 2017, : 185 - 189
  • [42] Domain-adversarial training of neural networks
    Ganin, Yaroslav
    Ustinova, Evgeniya
    Ajakan, Hana
    Germain, Pascal
    Larochelle, Hugo
    Laviolette, François
    Marchand, Mario
    Lempitsky, Victor
    Journal of Machine Learning Research, 2016, 17
  • [43] Domain-Adversarial Training of Neural Networks
    Ganin, Yaroslav
    Ustinova, Evgeniya
    Ajakan, Hana
    Germain, Pascal
    Larochelle, Hugo
    Laviolette, Francois
    Marchand, Mario
    Lempitsky, Victor
    JOURNAL OF MACHINE LEARNING RESEARCH, 2016, 17
  • [44] Adversarial Training for Probabilistic Spiking Neural Networks
    Bagheri, Alireza
    Simeone, Osvaldo
    Rajendran, Bipin
    2018 IEEE 19TH INTERNATIONAL WORKSHOP ON SIGNAL PROCESSING ADVANCES IN WIRELESS COMMUNICATIONS (SPAWC), 2018, : 261 - 265
  • [45] Convergence of Adversarial Training in Overparametrized Neural Networks
    Gao, Ruiqi
    Cai, Tianle
    Li, Haochuan
    Wang, Liwei
    Hsieh, Cho-Jui
    Lee, Jason D.
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [46] ADVERSPARSE: AN ADVERSARIAL ATTACK FRAMEWORK FOR DEEP SPATIAL-TEMPORAL GRAPH NEURAL NETWORKS
    Li, Jiayu
    Zhang, Tianyun
    Jin, Shengmin
    Fardad, Makan
    Zafarani, Reza
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 5857 - 5861
  • [47] Solving inverse problems in stochastic models using deep neural networks and adversarial training
    Xu, Kailai
    Darve, Eric
    COMPUTER METHODS IN APPLIED MECHANICS AND ENGINEERING, 2021, 384
  • [48] A Compression-Driven Training Framework for Embedded Deep Neural Networks
    Grimaldi, Matteo
    Pugliese, Federico
    Tenace, Valerio
    Calimera, Andrea
    WORKSHOP PROCEEDINGS 2018: INTELLIGENT EMBEDDED SYSTEMS ARCHITECTURES AND APPLICATIONS (INTESA), 2018, : 45 - 50
  • [49] A Scalable GPU-enabled Framework for Training Deep Neural Networks
    Del Monte, Bonaventura
    Prodan, Radu
    2016 2ND INTERNATIONAL CONFERENCE ON GREEN HIGH PERFORMANCE COMPUTING (ICGHPC), 2016,
  • [50] AN EFFICIENT DEEP NEURAL NETWORKS TRAINING FRAMEWORK FOR ROBUST FACE RECOGNITION
    Su, Canping
    Yan, Yan
    Chen, Si
    Wang, Hanzi
    2017 24TH IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2017, : 3800 - 3804