Transformer Based Defense GAN Against Palm-Vein Adversarial Attacks

被引:6
|
作者
Li, Yantao [1 ]
Ruan, Song [1 ]
Qin, Huafeng [2 ]
Deng, Shaojiang [1 ]
El-Yacoubi, Mounim A. [3 ]
机构
[1] Chongqing Univ, Coll Comp Sci, Chongqing 400044, Peoples R China
[2] Chongqing Technol & Business Univ, Sch Comp Sci & Informat Engn, Chongqing 400067, Peoples R China
[3] Inst Polytech Paris, Telecom SudParis, SAMOVAR, CNRS, F-91120 Palaiseau, France
基金
中国国家自然科学基金;
关键词
Local transformer; defense GAN; purifier; palm-vein recognition; adversarial attacks; DEEP REPRESENTATION; RECOGNITION; EXTRACTION; CURVATURE; QUALITY;
D O I
10.1109/TIFS.2023.3243782
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Vein biometrics is a high security and privacy preserving identification technology that has attracted increasing attention over the last decade. Deep neural networks (DNNs), such as convolutional neural networks (CNN), have shown strong capabilities for robust feature representation, and have achieved, as a result, state-of-the-art performance on various vision tasks. Inspired by their success, deep learning models have been widely investigated for vein recognition and have shown significant improvement of identification accuracy compared to handcrafted models. Existing deep learning models, however, are vulnerable to adversarial perturbation attacks, where thoughtfully crafted small perturbations can cause misclassification of legitimate images, degrading, thereby, the efficiency of vein recognition systems. To address this problem, we propose, in this paper, VeinGuard, a novel defense framework to defend deep learning classifiers against adversarial palm-vein image attacks, composed of a local transformer-based GAN and a purifier. VeinGuard comprises two components: a local transformer-based GAN (LTGAN) that learns the distribution of unperturbed vein images and generates high-quality palm-vein images, and a purifier consisting of a trainable residual network and of a pre-trained generator from LTGAN that automatically removes a wide variety of adversarial perturbations. The resulting clean images are fed to vein classifiers for identification, thereby avoiding adversarial attacks. We evaluate VeinGuard on three public vein datasets in terms of white-box attacks, black-box attacks, ablation experiments, and computation time. The experimental results show that VeinGuard allows filtering the perturbations and enables the classifiers to achieve state-of-the-art recognition results for different adversarial attacks.
引用
收藏
页码:1509 / 1523
页数:15
相关论文
共 50 条
  • [31] Defensive Bit Planes: Defense Against Adversarial Attacks
    Tripathi, Achyut Mani
    Behera, Swarup Ranjan
    Paul, Konark
    [J]. 2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [32] Deep Learning Defense Method Against Adversarial Attacks
    Wang, Ling
    Zhang, Cheng
    Liu, Jie
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2020, : 3667 - 3671
  • [33] Defense-VAE: A Fast and Accurate Defense Against Adversarial Attacks
    Li, Xiang
    Ji, Shihao
    [J]. MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2019, PT II, 2020, 1168 : 191 - 207
  • [34] A GAN-Based Defense Framework Against Model Inversion Attacks
    Gong, Xueluan
    Wang, Ziyao
    Li, Shuaike
    Chen, Yanjiao
    Wang, Qian
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 4475 - 4487
  • [35] DEFENSE AGAINST ADVERSARIAL ATTACKS ON SPOOFING COUNTERMEASURES OF ASV
    Wu, Haibin
    Liu, Songxiang
    Meng, Helen
    Lee, Hung-yi
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 6564 - 6568
  • [36] Universal Inverse Perturbation Defense Against Adversarial Attacks
    Chen, Jin-Yin
    Wu, Chang-An
    Zheng, Hai-Bin
    Wang, Wei
    Wen, Hao
    [J]. Zidonghua Xuebao/Acta Automatica Sinica, 2023, 49 (10): : 2172 - 2187
  • [37] Symmetry Defense Against CNN Adversarial Perturbation Attacks
    Lindqvist, Blerta
    [J]. INFORMATION SECURITY, ISC 2023, 2023, 14411 : 142 - 160
  • [38] GAN Against Adversarial Attacks in Radio Signal Classification
    Wang, Zhaowei
    Liu, Weicheng
    Wang, Hui-Ming
    [J]. IEEE COMMUNICATIONS LETTERS, 2022, 26 (12) : 2851 - 2854
  • [39] A Palm-vein recognition algorithm based on LPP and HM-LBP
    Guo Xiumei
    Wang Chengyi
    Zhang Ping
    [J]. 2018 2ND INTERNATIONAL WORKSHOP ON RENEWABLE ENERGY AND DEVELOPMENT (IWRED 2018), 2018, 153
  • [40] Watermarking-based Defense against Adversarial Attacks on Deep Neural Networks
    Li, Xiaoting
    Chen, Lingwei
    Zhang, Jinquan
    Larus, James
    Wu, Dinghao
    [J]. 2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,