GanDef: A GAN Based Adversarial Training Defense for Neural Network Classifier

被引:13
|
作者
Liu, Guanxiong [1 ]
Khalil, Issa [2 ]
Khreishah, Abdallah [1 ]
机构
[1] New Jersey Inst Technol, Newark, NJ 07102 USA
[2] Qatar Comp Res Inst, Doha, Qatar
关键词
Neural network classifier; Generative Adversarial Net; Adversarial training defense;
D O I
10.1007/978-3-030-22312-0_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning models, especially neural network (NN) classifiers, are widely used in many applications including natural language processing, computer vision and cybersecurity. They provide high accuracy under the assumption of attack-free scenarios. However, this assumption has been defied by the introduction of adversarial examples - carefully perturbed samples of input that are usually misclassified. Many researchers have tried to develop a defense against adversarial examples; however, we are still far from achieving that goal. In this paper, we design a Generative Adversarial Net (GAN) based adversarial training defense, dubbed GanDef, which utilizes a competition game to regulate the feature selection during the training. We analytically show that GanDef can train a classifier so it can defend against adversarial examples. Through extensive evaluation on different white-box adversarial examples, the classifier trained by GanDef shows the same level of test accuracy as those trained by state-of-the-art adversarial training defenses. More importantly, GanDef-Comb, a variant of GanDef, could utilize the discriminator to achieve a dynamic trade-off between correctly classifying original and adversarial examples. As a result, it achieves the highest overall test accuracy when the ratio of adversarial examples exceeds 41.7%.
引用
收藏
页码:19 / 32
页数:14
相关论文
共 50 条
  • [41] Cycle-Consistent Adversarial GAN: The Integration of Adversarial Attack and Defense
    Jiang, Lingyun
    Qiao, Kai
    Qin, Ruoxi
    Wang, Linyuan
    Yu, Wanting
    Chen, Jian
    Bu, Haibing
    Yan, Bin
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2020, 2020 (2020)
  • [42] QuSecNets: Quantization-based Defense Mechanism for Securing Deep Neural Network against Adversarial Attacks
    Khalid, Faiq
    Ali, Hassan
    Tariq, Hanunad
    Hanif, Muhammad Abdullah
    Rehman, Semeen
    Ahmed, Rehan
    Shafique, Muhammad
    [J]. 2019 IEEE 25TH INTERNATIONAL SYMPOSIUM ON ON-LINE TESTING AND ROBUST SYSTEM DESIGN (IOLTS 2019), 2019, : 182 - 187
  • [43] A neural network based classifier for acute meningitis
    Revett, Kenneth
    [J]. NEUREL 2006: Eight Seminar on Neural Network Applications in Electrical Engineering, Proceedings, 2006, : 161 - 165
  • [44] A Neural-Network-Based Fault Classifier
    Gomez, Laura Rodriguez
    Wunderlich, Hans-Joachim
    [J]. 2016 IEEE 25TH ASIAN TEST SYMPOSIUM (ATS), 2016, : 144 - 149
  • [45] Collaborative-GAN: An Approach for Stabilizing the Training Process of Generative Adversarial Network
    Megahed, Mohammed
    Mohammed, Ammar
    [J]. IEEE Access, 2024, 12 : 138716 - 138735
  • [46] A Texture Fuzzy Classifier Based on the Training Set Clustering by a Self-Organizing Neural Network
    Axyonov, Sergey
    Kostin, Kirill
    Lykom, Dmitry
    [J]. ANALYSIS OF IMAGES, SOCIAL NETWORKS AND TEXTS, AIST 2015, 2015, 542 : 187 - 195
  • [47] Transformer Based Defense GAN Against Palm-Vein Adversarial Attacks
    Li, Yantao
    Ruan, Song
    Qin, Huafeng
    Deng, Shaojiang
    El-Yacoubi, Mounim A.
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 1509 - 1523
  • [48] Adversarial Defense Through Network Profiling Based Path Extraction
    Qiu, Yuxian
    Leng, Jingwen
    Guo, Cong
    Chen, Quan
    Li, Chao
    Guo, Minyi
    Zhu, Yuhao
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 4772 - 4781
  • [49] Generative adversarial network based synthetic data training model for lightweight convolutional neural networks
    Rather, Ishfaq Hussain
    Kumar, Sushil
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 83 (2) : 6249 - 6271
  • [50] Adversarial Example Defense Method Based on Inverse Perturbation Fusing Generative Adversarial Network
    Zhang, Shi-Hui
    Zhang, Xiao-Wei
    Song, Dan-Dan
    Yang, Yong-Liang
    Zuo, Dong-Xu
    [J]. Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2023, 51 (04): : 879 - 884