Toward Efficiently Evaluating the Robustness of Deep Neural Networks in IoT Systems: A GAN-Based Method

被引:4
|
作者
Bai, Tao [1 ]
Zhao, Jun [1 ]
Zhu, Jinlin [2 ]
Han, Shoudong [3 ,4 ]
Chen, Jiefeng [5 ]
Li, Bo [6 ]
Kot, Alex [2 ]
机构
[1] Nanyang Technol Univ, Sch Comp Sci & Engn, Singapore 639798, Singapore
[2] Nanyang Technol Univ, Sch Elect & Elect Engn, Singapore 639798, Singapore
[3] Huazhong Univ Sci & Technol, Natl Key Lab Sci & Technol Multispectral Informat, Wuhan 430074, Peoples R China
[4] Huazhong Univ Sci & Technol, Sch Artificial Intelligence & Automat, Wuhan 430074, Peoples R China
[5] Univ Wisconsin, Dept Comp Sci, Madison, WI 53706 USA
[6] Univ Illinois, Comp Sci Dept, Urbana, IL 61801 USA
关键词
Perturbation methods; Generative adversarial networks; Generators; Neural networks; Internet of Things; Training; Optimization; Adversarial examples; deep learning; generative adversarial networks (GANs); INTERNET; SECURITY; THINGS;
D O I
10.1109/JIOT.2021.3091683
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intelligent Internet of Things (IoT) systems based on deep neural networks (DNNs) have been widely deployed in the real world. However, DNNs are found to be vulnerable to adversarial examples, which raises people's concerns about intelligent IoT systems' reliability and security. Testing and evaluating the robustness of IoT systems become necessary and essential. Recently, various attacks and strategies have been proposed, but the efficiency problem remains unsolved properly. Existing methods are either computationally extensive or time consuming, which is not applicable in practice. In this article, we propose a novel framework, called attack-inspired generative adversarial networks (AI-GAN) to generate adversarial examples conditionally. Once trained, it can generate adversarial perturbations efficiently given input images and target classes. We apply AI-GAN on different data sets in white-box settings, black-box settings, and targeted models protected by state-of-the-art defenses. Through extensive experiments, AI-GAN achieves high attack success rates, outperforming existing methods, and reduces generation time significantly. Moreover, for the first time, AI-GAN successfully scales to complex data sets, e.g., CIFAR-100 and ImageNet, with about 90% success rates among all classes.
引用
收藏
页码:1875 / 1884
页数:10
相关论文
共 50 条
  • [31] DistPrivacy: Privacy-Aware Distributed Deep Neural Networks in IoT surveillance systems
    Baccour, Emna
    Erbad, Aiman
    Mohamed, Amr
    Hamdi, Mounir
    Guizani, Mohsen
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [32] Overall evaluating method for software qualities based on neural networks
    Yang, Gen-Xing
    Gao, Da-Qi
    Song, Guo-Xin
    Huadong Ligong Daxue Xuebao /Journal of East China University of Science and Technology, 2004, 30 (03):
  • [33] Adversarial robustness in deep neural networks based on variable attributes of the stochastic ensemble model
    Qin, Ruoxi
    Wang, Linyuan
    Du, Xuehui
    Xie, Pengfei
    Chen, Xingyuan
    Yan, Bin
    FRONTIERS IN NEUROROBOTICS, 2023, 17
  • [34] OCCROB: Efficient SMT-Based Occlusion Robustness Verification of Deep Neural Networks
    Guo, Xingwu
    Zhou, Ziwei
    Zhang, Yueling
    Katz, Guy
    Zhang, Min
    TOOLS AND ALGORITHMS FOR THE CONSTRUCTION AND ANALYSIS OF SYSTEMS, PT I, TACAS 2023, 2023, 13993 : 208 - 226
  • [35] A regularization perspective based theoretical analysis for adversarial robustness of deep spiking neural networks
    Zhang, Hui
    Cheng, Jian
    Zhang, Jun
    Liu, Hongyi
    Wei, Zhihui
    NEURAL NETWORKS, 2023, 165 : 164 - 174
  • [36] Direction-of-Arrival Estimation Based on Deep Neural Networks With Robustness to Array Imperfections
    Liu, Zhang-Meng
    Zhang, Chenwei
    Yu, Philip S.
    IEEE TRANSACTIONS ON ANTENNAS AND PROPAGATION, 2018, 66 (12) : 7315 - 7327
  • [37] Deep Neural Networks for Dynamic Attribute based Encryption in IoT-Fog Environment
    Talreja, Mohit
    Taranath, M. Pruthvi
    Shanware, Hrushikesh
    Obaidat, Mohammad S.
    Rout, Rashmi Ranjan
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 5670 - 5675
  • [38] Deep Neural Network and GAN-Based Reversible Data Hiding in Encrypted Images: A Privacy-Preserving Approach
    Nalavade J.E.
    Patil A.
    Buchade A.
    Jadhav N.
    SN Computer Science, 5 (1)
  • [39] Evaluating Shallow and Deep Neural Networks for Network Intrusion Detection Systems in Cyber Security
    Vigneswaran, Rahul K.
    Vinayakumar, R.
    Soman, K. P.
    Poornachandran, Prabaharan
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [40] A graph-based interpretability method for deep neural networks
    Wang, Tao
    Zheng, Xiangwei
    Zhang, Lifeng
    Cui, Zhen
    Xu, Chunyan
    NEUROCOMPUTING, 2023, 555