Uncovering Hidden Vulnerabilities in Convolutional Neural Networks through Graph-based Adversarial Robustness Evaluation

被引:1
|
作者
Wang, Ke [1 ,2 ]
Chen, Zicong [1 ]
Dang, Xilin [2 ]
Fan, Xuan [1 ]
Han, Xuming [1 ]
Chen, Chien-Ming [3 ]
Ding, Weiping [4 ]
Yiu, Siu-Ming [5 ]
Weng, Jian [6 ]
机构
[1] Jinan Univ, Coll Informat & Sci, Huangpu Rd, Guangzhou 510632, Guangdong, Peoples R China
[2] Jinan Univ, Coll Cyber Secur, Engn Res Ctr Trustworthy AI, Minist Educ, Guangzhou, Peoples R China
[3] Shandong Univ Sci & Technol, Coll Comp Sci, Qingdao 266590, Shandong, Peoples R China
[4] Nantong Univ, Sch Informat Sci & Technol, Nantong 226019, Jiangshu, Peoples R China
[5] Univ Hong Kong, Dept Comp Sci, Hong Kong 00852, Peoples R China
[6] Jinan Univ, Guangdong Key Lab Data Secur & Privacy Preserving, Guangzhou 510632, Guangdong, Peoples R China
关键词
Graph of patterns; Graph distance algorithm; Adversarial robustness; Interpretable graph -based systems; Convolutional neural networks;
D O I
10.1016/j.patcog.2023.109745
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Convolutional neural networks (CNNs) are widely used for image classification, but their vulnerability to adversarial attacks poses challenges to their reliability and security. However, current adversarial robust-ness (AR) measures lack a theoretical foundation, limiting the insight into the decision process. To address this issue, we propose a new AR evaluation framework based on Graph of Patterns (GoPs) models and graph distance algorithms. Our approach provides a fine-grained analysis of AR from three perspectives, providing targeted insight into the vulnerability of CNNs. Compared to current standards, our approach is theoretically grounded and allows fine-tuning of model components without repeated attempts and validation. Our experimental results demonstrate its effectiveness in uncovering hidden vulnerabilities in CNNs and providing actionable approaches to improve their AR. Our GoPs modeling approach and graph distance algorithms can be extended to apply to other graph machine learning tasks such as Metric Learn-ing on multi-relational graphs. Overall, our framework represents significant progress in AR evaluation, providing a more interpretable, targeted, and efficient approach to assess CNN robustness in complex graph-based systems. & COPY; 2023 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Sanitizing hidden activations for improving adversarial robustness of convolutional neural networks
    Mu, Tianshi
    Lin, Kequan
    Zhang, Huabing
    Wang, Jian
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2021, 41 (02) : 3993 - 4003
  • [2] Understanding Generalization in Neural Networks for Robustness against Adversarial Vulnerabilities
    Chaudhury, Subhajit
    [J]. THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 13714 - 13715
  • [3] Adversarial Robustness in Graph-Based Neural Architecture Search for Edge AI Transportation Systems
    Xu, Peng
    Wang, Ke
    Hassan, Mohammad Mehedi
    Chen, Chien-Ming
    Lin, Weiguo
    Hassan, Md Rafiul
    Fortino, Giancarlo
    [J]. IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (08) : 8465 - 8474
  • [4] Graph-based saliency and ensembles of convolutional neural networks for glaucoma detection
    Serte, Sertan
    Serener, Ali
    [J]. IET IMAGE PROCESSING, 2021, 15 (03) : 797 - 804
  • [5] Exploring adversarial examples and adversarial robustness of convolutional neural networks by mutual information
    Zhang, Jiebao
    Qian, Wenhua
    Cao, Jinde
    Xu, Dan
    [J]. Neural Computing and Applications, 2024, 36 (23) : 14379 - 14394
  • [6] Adversarial Robustness of Multi-bit Convolutional Neural Networks
    Frickenstein, Lukas
    Sampath, Shambhavi Balamuthu
    Mori, Pierpaolo
    Vemparala, Manoj-Rohit
    Fasfous, Nael
    Frickenstein, Alexander
    Unger, Christian
    Passerone, Claudio
    Stechele, Walter
    [J]. INTELLIGENT SYSTEMS AND APPLICATIONS, VOL 3, INTELLISYS 2023, 2024, 824 : 157 - 174
  • [7] Adversarial Robustness of Vision Transformers Versus Convolutional Neural Networks
    Ali, Kazim
    Bhatti, Muhammad Shahid
    Saeed, Atif
    Athar, Atifa
    Al Ghamdi, Mohammed A.
    Almotiri, Sultan H.
    Akram, Samina
    [J]. IEEE ACCESS, 2024, 12 : 105281 - 105293
  • [8] Defect detection in cardiac SPECT using graph-based convolutional neural networks
    Spier, Nathalia
    Christoph, Rischpler
    Rupprecht, Christian
    Navab, Nassir
    Baust, Maximilian
    Nekolla, Stephan
    [J]. JOURNAL OF NUCLEAR MEDICINE, 2018, 59
  • [9] Revisiting 2D Convolutional Neural Networks for Graph-Based Applications
    Lyu, Yecheng
    Huang, Xinming
    Zhang, Ziming
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (06) : 6909 - 6922
  • [10] Uncovering hidden therapeutic indications through drug repurposing with graph neural networks and heterogeneous data
    Ayuso-Munoz, Adrian
    Prieto-Santamaria, Lucia
    Ugarte-Carro, Esther
    Serrano, Emilio
    Rodriguez-Gonzalez, Alejandro
    [J]. ARTIFICIAL INTELLIGENCE IN MEDICINE, 2023, 145