GanDef: A GAN Based Adversarial Training Defense for Neural Network Classifier

被引:13
|
作者
Liu, Guanxiong [1 ]
Khalil, Issa [2 ]
Khreishah, Abdallah [1 ]
机构
[1] New Jersey Inst Technol, Newark, NJ 07102 USA
[2] Qatar Comp Res Inst, Doha, Qatar
关键词
Neural network classifier; Generative Adversarial Net; Adversarial training defense;
D O I
10.1007/978-3-030-22312-0_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning models, especially neural network (NN) classifiers, are widely used in many applications including natural language processing, computer vision and cybersecurity. They provide high accuracy under the assumption of attack-free scenarios. However, this assumption has been defied by the introduction of adversarial examples - carefully perturbed samples of input that are usually misclassified. Many researchers have tried to develop a defense against adversarial examples; however, we are still far from achieving that goal. In this paper, we design a Generative Adversarial Net (GAN) based adversarial training defense, dubbed GanDef, which utilizes a competition game to regulate the feature selection during the training. We analytically show that GanDef can train a classifier so it can defend against adversarial examples. Through extensive evaluation on different white-box adversarial examples, the classifier trained by GanDef shows the same level of test accuracy as those trained by state-of-the-art adversarial training defenses. More importantly, GanDef-Comb, a variant of GanDef, could utilize the discriminator to achieve a dynamic trade-off between correctly classifying original and adversarial examples. As a result, it achieves the highest overall test accuracy when the ratio of adversarial examples exceeds 41.7%.
引用
收藏
页码:19 / 32
页数:14
相关论文
共 50 条
  • [21] A neural network based plant classifier
    Moshou, D
    Vrindts, E
    De Ketelaere, B
    De Baerdemaeker, J
    Ramon, H
    [J]. COMPUTERS AND ELECTRONICS IN AGRICULTURE, 2001, 31 (01) : 5 - 16
  • [22] Design of robust hyperspectral image classifier based on adversarial training against adversarial attack
    Park, Inho
    Kim, Sungho
    [J]. Journal of Institute of Control, Robotics and Systems, 2021, 27 (06) : 389 - 400
  • [23] IoT-Based Android Malware Detection Using Graph Neural Network With Adversarial Defense
    Yumlembam, Rahul
    Issac, Biju
    Jacob, Seibu Mary
    Yang, Longzhi
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (10) : 8432 - 8444
  • [24] Adversarial Attack and Defense on Deep Neural Network-Based Voice Processing Systems: An Overview
    Chen, Xiaojiao
    Li, Sheng
    Huang, Hao
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (18):
  • [25] An Adversarial sample defense method based on multi-scale GAN
    Shao, Mingwen
    Liu, Shuqi
    Wang, Ran
    Zhang, Gaozhi
    [J]. INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2021, 12 (12) : 3437 - 3447
  • [26] An Expanded Training Set Based Validation Method to Avoid Overfitting for Neural Network Classifier
    Wang, Kai
    Yang, Jufeng
    Shi, Guangshun
    Wang, Qingren
    [J]. ICNC 2008: FOURTH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, VOL 3, PROCEEDINGS, 2008, : 83 - 87
  • [27] FPGA Adaptive Neural Network Quantization for Adversarial Image Attack Defense
    Lu, Yufeng
    Shi, Xiaokang
    Jiang, Jianan
    Deng, Hanhui
    Wang, Yanwen
    Lu, Jiwu
    Wu, Di
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, : 14017 - 14028
  • [28] An Adversarial sample defense method based on multi-scale GAN
    Mingwen Shao
    Shuqi Liu
    Ran Wang
    Gaozhi Zhang
    [J]. International Journal of Machine Learning and Cybernetics, 2021, 12 : 3437 - 3447
  • [29] Adversarial attack and training for deep neural network based power quality disturbance classification
    Zhang, Liangheng
    Jiang, Congmei
    Chai, Zhaosen
    He, Yu
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 127
  • [30] Variational Adversarial Defense: A Bayes Perspective for Adversarial Training
    Zhao, Chenglong
    Mei, Shibin
    Ni, Bingbing
    Yuan, Shengchao
    Yu, Zhenbo
    Wang, Jun
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (05) : 3047 - 3063