TY - GEN
T1 - Efficient Defense Against Adversarial Attacks and Security Evaluation of Deep Learning System
AU - Pang, Na
AU - Hong, Sheng
AU - Pan, Yang
AU - Ji, Yuqi
N1 - Publisher Copyright:
© 2020, Springer Nature Switzerland AG.
PY - 2020
Y1 - 2020
N2 - Deep neural networks (DNNs) have achieved performance on classical artificial intelligence problems including visual recognition, natural language processing. Unfortunately, recent studies show that machine learning models are suffering from adversarial attacks, resulting in incorrect outputs in the form of purposeful distortions to inputs. For images, such subtle distortions are usually hard to be perceptible, yet they successfully fool machine learning models. In this paper, we propose a strategy, FeaturePro, for defending machine learning models against adversarial examples and evaluating the security of deep learning system. We tackle this challenge by reducing the visible feature space for adversary. By performing white-box attacks, black-box attacks, targeted attacks and non-targeted attacks, the security of deep learning algorithms which is an important indicator for evaluating artificial intelligence systems can be evaluated. We analyzed the generalization and robustness when it is composed with adversarial training. FeaturePro has efficient defense against adversarial attacks with a high accuracy and low false positive rates.
AB - Deep neural networks (DNNs) have achieved performance on classical artificial intelligence problems including visual recognition, natural language processing. Unfortunately, recent studies show that machine learning models are suffering from adversarial attacks, resulting in incorrect outputs in the form of purposeful distortions to inputs. For images, such subtle distortions are usually hard to be perceptible, yet they successfully fool machine learning models. In this paper, we propose a strategy, FeaturePro, for defending machine learning models against adversarial examples and evaluating the security of deep learning system. We tackle this challenge by reducing the visible feature space for adversary. By performing white-box attacks, black-box attacks, targeted attacks and non-targeted attacks, the security of deep learning algorithms which is an important indicator for evaluating artificial intelligence systems can be evaluated. We analyzed the generalization and robustness when it is composed with adversarial training. FeaturePro has efficient defense against adversarial attacks with a high accuracy and low false positive rates.
KW - Adversarial examples
KW - Deep learning
KW - Defense
KW - Neural networks
UR - https://www.scopus.com/pages/publications/85097182440
U2 - 10.1007/978-3-030-62460-6_53
DO - 10.1007/978-3-030-62460-6_53
M3 - 会议稿件
AN - SCOPUS:85097182440
SN - 9783030624590
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 592
EP - 602
BT - Machine Learning for Cyber Security - Third International Conference, ML4CS 2020, Proceedings
A2 - Chen, Xiaofeng
A2 - Yan, Hongyang
A2 - Yan, Qiben
A2 - Zhang, Xiangliang
PB - Springer Science and Business Media Deutschland GmbH
T2 - 3rd International Conference on Machine Learning for Cyber Security, ML4CS 2020
Y2 - 8 October 2020 through 10 October 2020
ER -