Transformer Based Defense GAN Against Palm-Vein Adversarial Attacks

被引:6
|
作者
Li, Yantao [1 ]
Ruan, Song [1 ]
Qin, Huafeng [2 ]
Deng, Shaojiang [1 ]
El-Yacoubi, Mounim A. [3 ]
机构
[1] Chongqing Univ, Coll Comp Sci, Chongqing 400044, Peoples R China
[2] Chongqing Technol & Business Univ, Sch Comp Sci & Informat Engn, Chongqing 400067, Peoples R China
[3] Inst Polytech Paris, Telecom SudParis, SAMOVAR, CNRS, F-91120 Palaiseau, France
基金
中国国家自然科学基金;
关键词
Local transformer; defense GAN; purifier; palm-vein recognition; adversarial attacks; DEEP REPRESENTATION; RECOGNITION; EXTRACTION; CURVATURE; QUALITY;
D O I
10.1109/TIFS.2023.3243782
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Vein biometrics is a high security and privacy preserving identification technology that has attracted increasing attention over the last decade. Deep neural networks (DNNs), such as convolutional neural networks (CNN), have shown strong capabilities for robust feature representation, and have achieved, as a result, state-of-the-art performance on various vision tasks. Inspired by their success, deep learning models have been widely investigated for vein recognition and have shown significant improvement of identification accuracy compared to handcrafted models. Existing deep learning models, however, are vulnerable to adversarial perturbation attacks, where thoughtfully crafted small perturbations can cause misclassification of legitimate images, degrading, thereby, the efficiency of vein recognition systems. To address this problem, we propose, in this paper, VeinGuard, a novel defense framework to defend deep learning classifiers against adversarial palm-vein image attacks, composed of a local transformer-based GAN and a purifier. VeinGuard comprises two components: a local transformer-based GAN (LTGAN) that learns the distribution of unperturbed vein images and generates high-quality palm-vein images, and a purifier consisting of a trainable residual network and of a pre-trained generator from LTGAN that automatically removes a wide variety of adversarial perturbations. The resulting clean images are fed to vein classifiers for identification, thereby avoiding adversarial attacks. We evaluate VeinGuard on three public vein datasets in terms of white-box attacks, black-box attacks, ablation experiments, and computation time. The experimental results show that VeinGuard allows filtering the perturbations and enables the classifiers to achieve state-of-the-art recognition results for different adversarial attacks.
引用
收藏
页码:1509 / 1523
页数:15
相关论文
共 50 条
  • [1] Adversarial Learning-Based Data Augmentation for Palm-Vein Identification
    Qin, Huafeng
    Xi, Haofei
    Li, Yantao
    El-Yacoubi, Mounim A.
    Wang, Jun
    Gao, Xinbo
    [J]. IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (06) : 4325 - 4341
  • [2] Cyclic Defense GAN Against Speech Adversarial Attacks
    Esmaeilpour, Mohammad
    Cardinal, Patrick
    Koerich, Alessandro Lameiras
    [J]. IEEE SIGNAL PROCESSING LETTERS, 2021, 28 : 1769 - 1773
  • [3] Securing palm-vein sensors against presentation attacks using image noise residuals
    Bhilare, Shruti
    Kanhangad, Vivek
    [J]. JOURNAL OF ELECTRONIC IMAGING, 2018, 27 (05)
  • [4] Label Enhancement-Based Multiscale Transformer for Palm-Vein Recognition
    Qin, Huafeng
    Gong, Changqing
    Li, Yantao
    Gao, Xinbo
    El-Yacoubi, Mounim A.
    [J]. IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2023, 72
  • [5] Attention Label Learning to Enhance Interactive Vein Transformer for Palm-Vein Recognition
    Qin, Huafeng
    Gong, Changqing
    Li, Yantao
    El-Yacoubi, Mounim A.
    Gao, Xinbo
    Wang, Jun
    [J]. IEEE TRANSACTIONS ON BIOMETRICS, BEHAVIOR, AND IDENTITY SCIENCE, 2024, 6 (03): : 341 - 351
  • [6] Enhancing the robustness of vision transformer defense against adversarial attacks based on squeeze-and-excitation module
    Chang, YouKang
    Zhao, Hong
    Wang, Weijie
    [J]. PEERJ COMPUTER SCIENCE, 2023, 9
  • [7] Deblurring as a Defense against Adversarial Attacks
    Duckworth, William, III
    Liao, Weixian
    Yu, Wei
    [J]. 2023 IEEE 12TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING, CLOUDNET, 2023, : 61 - 67
  • [8] Text Adversarial Purification as Defense against Adversarial Attacks
    Li, Linyang
    Song, Demin
    Qiu, Xipeng
    [J]. PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, VOL 1, 2023, : 338 - 350
  • [9] Palm-Vein Classification Based on Principal Orientation Features
    Zhou, Yujia
    Liu, Yaqin
    Feng, Qianjin
    Yang, Feng
    Huang, Jing
    Nie, Yixiao
    [J]. PLOS ONE, 2014, 9 (11):
  • [10] AdvRefactor: A Resampling-Based Defense Against Adversarial Attacks
    Jiang, Jianguo
    Li, Boquan
    Yu, Min
    Liu, Chao
    Sun, Jianguo
    Huang, Weiqing
    Lv, Zhiqiang
    [J]. ADVANCES IN MULTIMEDIA INFORMATION PROCESSING - PCM 2018, PT II, 2018, 11165 : 815 - 825