GanDef: A GAN Based Adversarial Training Defense for Neural Network Classifier

被引:13
|
作者
Liu, Guanxiong [1 ]
Khalil, Issa [2 ]
Khreishah, Abdallah [1 ]
机构
[1] New Jersey Inst Technol, Newark, NJ 07102 USA
[2] Qatar Comp Res Inst, Doha, Qatar
关键词
Neural network classifier; Generative Adversarial Net; Adversarial training defense;
D O I
10.1007/978-3-030-22312-0_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning models, especially neural network (NN) classifiers, are widely used in many applications including natural language processing, computer vision and cybersecurity. They provide high accuracy under the assumption of attack-free scenarios. However, this assumption has been defied by the introduction of adversarial examples - carefully perturbed samples of input that are usually misclassified. Many researchers have tried to develop a defense against adversarial examples; however, we are still far from achieving that goal. In this paper, we design a Generative Adversarial Net (GAN) based adversarial training defense, dubbed GanDef, which utilizes a competition game to regulate the feature selection during the training. We analytically show that GanDef can train a classifier so it can defend against adversarial examples. Through extensive evaluation on different white-box adversarial examples, the classifier trained by GanDef shows the same level of test accuracy as those trained by state-of-the-art adversarial training defenses. More importantly, GanDef-Comb, a variant of GanDef, could utilize the discriminator to achieve a dynamic trade-off between correctly classifying original and adversarial examples. As a result, it achieves the highest overall test accuracy when the ratio of adversarial examples exceeds 41.7%.
引用
收藏
页码:19 / 32
页数:14
相关论文
共 50 条
  • [1] ZK-GanDef: A GAN based Zero Knowledge Adversarial Training Defense for Neural Networks
    Liu, Guanxiong
    Khalil, Issa
    Khreishah, Abdallah
    [J]. 2019 49TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN 2019), 2019, : 64 - 75
  • [2] Adversarial attack defense algorithm based on convolutional neural network
    Zhang, Chengyuan
    Wang, Ping
    [J]. NEURAL COMPUTING & APPLICATIONS, 2023, 36 (17): : 9723 - 9735
  • [3] NAttack! Adversarial Attacks to bypass a GAN based classifier trained to detect Network intrusion
    Piplai, Aritran
    Chukkapalli, Sai Sree Laya
    Joshi, Anupam
    [J]. 2020 IEEE 6TH INT CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY) / 6TH IEEE INT CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) / 5TH IEEE INT CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2020, : 49 - 54
  • [4] A Network Security Classifier Defense: Against Adversarial Machine Learning Attacks
    De Lucia, Michael J.
    Cotton, Chase
    [J]. PROCEEDINGS OF THE 2ND ACM WORKSHOP ON WIRELESS SECURITY AND MACHINE LEARNING, WISEML 2020, 2020, : 67 - 73
  • [5] GAN-based classifier protection against adversarial attacks
    Liu, Shuqi
    Shao, Mingwen
    Liu, Xinping
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 39 (05) : 7085 - 7095
  • [6] A novel classifier with the immune-training based wavelet neural network
    Wang, L
    Nie, YL
    Nie, WK
    Jiao, LC
    [J]. ADVANCES IN NEURAL NETWORKS - ISNN 2005, PT 2, PROCEEDINGS, 2005, 3497 : 8 - 13
  • [7] Neural Network Classifier-Based OPC With Imbalanced Training Data
    Choi, Suhyeong
    Shim, Seongbo
    Shin, Youngsoo
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2019, 38 (05) : 938 - 948
  • [8] Partial Adversarial Training for Neural Network-Based Uncertainty Quantification
    Kabir, H. M. Dipu
    Khosravi, Abbas
    Nahavandi, Saeid
    Kavousi-Fard, Abdollah
    [J]. IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2021, 5 (04): : 595 - 606
  • [9] GAN-Based Fusion Adversarial Training
    Cao, Yifan
    Lin, Ying
    Ning, Shengfu
    Pi, Huan
    Zhang, Junyuan
    Hu, Jianpeng
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2022, PT III, 2022, 13370 : 51 - 64
  • [10] RazorNet: Adversarial Training and Noise Training on a Deep Neural Network Fooled by a Shallow Neural Network
    Taheri, Shayan
    Salem, Milad
    Yuan, Jiann-Shiun
    [J]. BIG DATA AND COGNITIVE COMPUTING, 2019, 3 (03) : 1 - 17