Mitigating Evasion Attacks to Deep Neural Networks via Region-based Classification

被引:85
|
作者
Cao, Xiaoyu [1 ]
Gong, Neil Zhenqiang [1 ]
机构
[1] Iowa State Univ, ECE Dept, Ames, IA 50011 USA
关键词
adversarial machine learning; evasion attacks; region-based classification;
D O I
10.1145/3134600.3134606
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural networks (DNNs) have transformed several artificial intelligence research areas including computer vision, speech recognition, and natural language processing. However, recent studies demonstrated that DNNs are vulnerable to adversarial manipulations at testing time. Specifically, suppose we have a testing example, whose label can be correctly predicted by a DNN classifier. An attacker can add a small carefully crafted noise to the testing example such that the DNN classifier predicts an incorrect label, where the crafted testing example is called adversarial example. Such attacks are called evasion attacks. Evasion attacks are one of the biggest challenges for deploying DNNs in safety and security critical applications such as self-driving cars. In this work, we develop new DNNs that are robust to state-of-the-art evasion attacks. Our key observation is that adversarial examples are close to the classification boundary. Therefore, we propose region-based classification to be robust to adversarial examples. Specifically, for a benign/adversarial testing example, we ensemble information in a hypercube centered at the example to predict its label. In contrast, traditional classifiers are point-based classification, i.e., given a testing example, the classifier predicts its label based on the testing example alone. Our evaluation results on MNIST and CIFAR-10 datasets demonstrate that our region-based classification can significantly mitigate evasion attacks without sacrificing classification accuracy on benign examples. Specifically, our region-based classification achieves the same classification accuracy on testing benign examples as point-based classification, but our region-based classification is significantly more robust than point-based classification to state-of-the-art evasion attacks.
引用
收藏
页码:278 / 287
页数:10
相关论文
共 50 条
  • [1] Deep Neural Networks With Region-Based Pooling Structures for Mammographic Image Classification
    Shu, Xin
    Zhang, Lei
    Wang, Zizhou
    Lv, Qing
    Yi, Zhang
    [J]. IEEE TRANSACTIONS ON MEDICAL IMAGING, 2020, 39 (06) : 2246 - 2255
  • [2] Mitigating Reverse Engineering Attacks on Deep Neural Networks
    Liu, Yuntao
    Dachman-Soled, Dana
    Srivastava, Ankur
    [J]. 2019 IEEE COMPUTER SOCIETY ANNUAL SYMPOSIUM ON VLSI (ISVLSI 2019), 2019, : 659 - 664
  • [3] Mitigating adversarial evasion attacks by deep active learning for medical image classification
    Usman Ahmed
    Jerry Chun-Wei Lin
    Gautam Srivastava
    [J]. Multimedia Tools and Applications, 2022, 81 : 41899 - 41910
  • [4] Mitigating adversarial evasion attacks by deep active learning for medical image classification
    Ahmed, Usman
    Lin, Jerry Chun-Wei
    Srivastava, Gautam
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (29) : 41899 - 41910
  • [5] AUTOMATIC RADAR-BASED GESTURE DETECTION AND CLASSIFICATION VIA A REGION-BASED DEEP CONVOLUTIONAL NEURAL NETWORK
    Sun, Yuliang
    Fei, Tai
    Gao, Shangyin
    Pohl, Nils
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 4300 - 4304
  • [6] Adversarial Evasion Attacks to Deep Neural Networks in ECR Models
    Nemoto, Shota
    Rajapaksha, Subhash
    Perouli, Despoina
    [J]. HEALTHINF: PROCEEDINGS OF THE 15TH INTERNATIONAL JOINT CONFERENCE ON BIOMEDICAL ENGINEERING SYSTEMS AND TECHNOLOGIES - VOL 5: HEALTHINF, 2021, : 135 - 141
  • [7] Plant Detection and Classification Using Fast Region-Based Convolution Neural Networks
    Lochan, Raja Naga
    Tomar, Anoop Singh
    Srinivasan, R.
    [J]. ARTIFICIAL INTELLIGENCE AND EVOLUTIONARY COMPUTATIONS IN ENGINEERING SYSTEMS, 2020, 1056 : 623 - 634
  • [8] Mitigating Adversarial Attacks for Deep Neural Networks by Input Deformation and Augmentation
    Qiu, Pengfei
    Wang, Qian
    Wang, Dongsheng
    Lyu, Yongqiang
    Lu, Zhaojun
    Qu, Gang
    [J]. 2020 25TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE, ASP-DAC 2020, 2020, : 157 - 162
  • [9] Classification of Artificial and Real Objects Using Faster Region-Based Convolutional Neural Networks
    Teegavarapu, Ritvik Sai
    Biswas, Debojit
    [J]. 2021 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI 2021), 2021,
  • [10] Improvement of region-based image coding by neural networks
    Pinho, AJ
    [J]. IEEE WORLD CONGRESS ON COMPUTATIONAL INTELLIGENCE, 1998, : 870 - 875