Transformer Based Defense GAN Against Palm-Vein Adversarial Attacks

被引:6
|
作者
Li, Yantao [1 ]
Ruan, Song [1 ]
Qin, Huafeng [2 ]
Deng, Shaojiang [1 ]
El-Yacoubi, Mounim A. [3 ]
机构
[1] Chongqing Univ, Coll Comp Sci, Chongqing 400044, Peoples R China
[2] Chongqing Technol & Business Univ, Sch Comp Sci & Informat Engn, Chongqing 400067, Peoples R China
[3] Inst Polytech Paris, Telecom SudParis, SAMOVAR, CNRS, F-91120 Palaiseau, France
基金
中国国家自然科学基金;
关键词
Local transformer; defense GAN; purifier; palm-vein recognition; adversarial attacks; DEEP REPRESENTATION; RECOGNITION; EXTRACTION; CURVATURE; QUALITY;
D O I
10.1109/TIFS.2023.3243782
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Vein biometrics is a high security and privacy preserving identification technology that has attracted increasing attention over the last decade. Deep neural networks (DNNs), such as convolutional neural networks (CNN), have shown strong capabilities for robust feature representation, and have achieved, as a result, state-of-the-art performance on various vision tasks. Inspired by their success, deep learning models have been widely investigated for vein recognition and have shown significant improvement of identification accuracy compared to handcrafted models. Existing deep learning models, however, are vulnerable to adversarial perturbation attacks, where thoughtfully crafted small perturbations can cause misclassification of legitimate images, degrading, thereby, the efficiency of vein recognition systems. To address this problem, we propose, in this paper, VeinGuard, a novel defense framework to defend deep learning classifiers against adversarial palm-vein image attacks, composed of a local transformer-based GAN and a purifier. VeinGuard comprises two components: a local transformer-based GAN (LTGAN) that learns the distribution of unperturbed vein images and generates high-quality palm-vein images, and a purifier consisting of a trainable residual network and of a pre-trained generator from LTGAN that automatically removes a wide variety of adversarial perturbations. The resulting clean images are fed to vein classifiers for identification, thereby avoiding adversarial attacks. We evaluate VeinGuard on three public vein datasets in terms of white-box attacks, black-box attacks, ablation experiments, and computation time. The experimental results show that VeinGuard allows filtering the perturbations and enables the classifiers to achieve state-of-the-art recognition results for different adversarial attacks.
引用
收藏
页码:1509 / 1523
页数:15
相关论文
共 50 条
  • [21] Defense Against Adversarial Attacks by Reconstructing Images
    Zhang, Shudong
    Gao, Haichang
    Rao, Qingxun
    [J]. IEEE TRANSACTIONS ON IMAGE PROCESSING, 2021, 30 : 6117 - 6129
  • [22] Defense Against Adversarial Attacks Using Feature Scattering-based Adversarial Training
    Zhang, Haichao
    Wang, Jianyu
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [23] Multi-Scale and Multi-Direction GAN for CNN-Based Single Palm-Vein Identification
    Qin, Huafeng
    El-Yacoubi, Mounim A.
    Li, Yantao
    Liu, Chongwen
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 2652 - 2666
  • [24] Defense against Adversarial Attacks in Image Recognition Based on Multilayer Filters
    Wang, Mingde
    Liu, Zhijing
    [J]. Applied Sciences (Switzerland), 2024, 14 (18):
  • [25] Sparsity-based Defense against Adversarial Attacks on Linear Classifiers
    Marzi, Zhinus
    Gopalakrishnan, Soorya
    Madhow, Upamanyu
    Pedarsani, Ramtin
    [J]. 2018 IEEE INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY (ISIT), 2018, : 31 - 35
  • [26] TENSORSHIELD: Tensor-based Defense Against Adversarial Attacks on Images
    Entezari, Negin
    Papalexakis, Evangelos E.
    [J]. 2022 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2022,
  • [27] The Best Defense is a Good Offense: Adversarial Augmentation against Adversarial Attacks
    Frosio, Iuri
    Kautz, Jan
    [J]. 2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR, 2023, : 4067 - 4076
  • [28] Defense Against Adversarial Attacks Using Topology Aligning Adversarial Training
    Kuang, Huafeng
    Liu, Hong
    Lin, Xianming
    Ji, Rongrong
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3659 - 3673
  • [29] Adaptive Image Reconstruction for Defense Against Adversarial Attacks
    Yang, Yanan
    Shih, Frank Y.
    Chang, I-Cheng
    [J]. INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2022, 36 (12)
  • [30] Detection defense against adversarial attacks with saliency map
    Ye, Dengpan
    Chen, Chuanxi
    Liu, Changrui
    Wang, Hao
    Jiang, Shunzhi
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (12) : 10193 - 10210