Mitigating Evasion Attacks to Deep Neural Networks via Region-based Classification

被引:85
|
作者
Cao, Xiaoyu [1 ]
Gong, Neil Zhenqiang [1 ]
机构
[1] Iowa State Univ, ECE Dept, Ames, IA 50011 USA
关键词
adversarial machine learning; evasion attacks; region-based classification;
D O I
10.1145/3134600.3134606
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural networks (DNNs) have transformed several artificial intelligence research areas including computer vision, speech recognition, and natural language processing. However, recent studies demonstrated that DNNs are vulnerable to adversarial manipulations at testing time. Specifically, suppose we have a testing example, whose label can be correctly predicted by a DNN classifier. An attacker can add a small carefully crafted noise to the testing example such that the DNN classifier predicts an incorrect label, where the crafted testing example is called adversarial example. Such attacks are called evasion attacks. Evasion attacks are one of the biggest challenges for deploying DNNs in safety and security critical applications such as self-driving cars. In this work, we develop new DNNs that are robust to state-of-the-art evasion attacks. Our key observation is that adversarial examples are close to the classification boundary. Therefore, we propose region-based classification to be robust to adversarial examples. Specifically, for a benign/adversarial testing example, we ensemble information in a hypercube centered at the example to predict its label. In contrast, traditional classifiers are point-based classification, i.e., given a testing example, the classifier predicts its label based on the testing example alone. Our evaluation results on MNIST and CIFAR-10 datasets demonstrate that our region-based classification can significantly mitigate evasion attacks without sacrificing classification accuracy on benign examples. Specifically, our region-based classification achieves the same classification accuracy on testing benign examples as point-based classification, but our region-based classification is significantly more robust than point-based classification to state-of-the-art evasion attacks.
引用
收藏
页码:278 / 287
页数:10
相关论文
共 50 条
  • [41] Crowd Counting in Low-Resolution Crowded Scenes Using Region-Based Deep Convolutional Neural Networks
    Saqib, Muhammad
    Khan, Sultan Daud
    Sharma, Nabin
    Blumenstein, Michael
    [J]. IEEE ACCESS, 2019, 7 : 35317 - 35329
  • [42] FENCE: Feasible Evasion Attacks on Neural Networks in Constrained Environments
    Chernikova, Alesia
    Oprea, Alina
    [J]. ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2022, 25 (04)
  • [43] Adversarial Attacks on Deep Neural Networks Based Modulation Recognition
    Liu, Mingqian
    Zhang, Zhenju
    Zhao, Nan
    Chen, Yunfei
    [J]. IEEE INFOCOM 2022 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2022,
  • [44] Aerial Scene Classification via Multilevel Fusion Based on Deep Convolutional Neural Networks
    Yu, Yunlong
    Liu, Fuxian
    [J]. IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2018, 15 (02) : 287 - 291
  • [45] A Fast Detection Method via Region-Based Fully Convolutional Neural Networks for Shield Tunnel Lining Defects
    Xue, Yadong
    Li, Yicheng
    [J]. COMPUTER-AIDED CIVIL AND INFRASTRUCTURE ENGINEERING, 2018, 33 (08) : 638 - 654
  • [46] Region-Based Split Octonion Networks with Channel Attention Module for Tuna Classification
    Jose, Jisha Anu
    Kumar, C. Sathish
    Sureshkumar, S.
    [J]. INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2022, 36 (07)
  • [47] Object-based Indoor Localization using Region-based Convolutional Neural Networks
    Li Chenning
    Yang Ting
    Zhang Qian
    Xu Haowei
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATIONS AND COMPUTING (ICSPCC), 2018,
  • [48] Region-Based Global Reasoning Networks
    Wang, Chuanming
    Fu, Huiyuan
    Ling, Charles X.
    Du, Peilun
    Ma, Huadong
    [J]. THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 12136 - 12143
  • [49] Vehicle license plate detection using region-based convolutional neural networks
    Muhammad Aasim Rafique
    Witold Pedrycz
    Moongu Jeon
    [J]. Soft Computing, 2018, 22 : 6429 - 6440
  • [50] Mitigating the Impacts of False Data Injection Attacks in Smart Grids using Deep Convolutional Neural Networks
    Ge, Qingyu
    Jiao, Chongqing
    [J]. PROCEEDINGS OF 2020 IEEE 10TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC 2020), 2020, : 174 - 177