Skip to main navigation Skip to search Skip to main content

Efficient Defense Against Adversarial Attacks and Security Evaluation of Deep Learning System

  • Na Pang*
  • , Sheng Hong
  • , Yang Pan
  • , Yuqi Ji
  • *Corresponding author for this work
  • Xingtang Telecommunications Technology Co. Ltd.
  • Beijing Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deep neural networks (DNNs) have achieved performance on classical artificial intelligence problems including visual recognition, natural language processing. Unfortunately, recent studies show that machine learning models are suffering from adversarial attacks, resulting in incorrect outputs in the form of purposeful distortions to inputs. For images, such subtle distortions are usually hard to be perceptible, yet they successfully fool machine learning models. In this paper, we propose a strategy, FeaturePro, for defending machine learning models against adversarial examples and evaluating the security of deep learning system. We tackle this challenge by reducing the visible feature space for adversary. By performing white-box attacks, black-box attacks, targeted attacks and non-targeted attacks, the security of deep learning algorithms which is an important indicator for evaluating artificial intelligence systems can be evaluated. We analyzed the generalization and robustness when it is composed with adversarial training. FeaturePro has efficient defense against adversarial attacks with a high accuracy and low false positive rates.

Original languageEnglish
Title of host publicationMachine Learning for Cyber Security - Third International Conference, ML4CS 2020, Proceedings
EditorsXiaofeng Chen, Hongyang Yan, Qiben Yan, Xiangliang Zhang
PublisherSpringer Science and Business Media Deutschland GmbH
Pages592-602
Number of pages11
ISBN (Print)9783030624590
DOIs
StatePublished - 2020
Event3rd International Conference on Machine Learning for Cyber Security, ML4CS 2020 - Guangzhou, China
Duration: 8 Oct 202010 Oct 2020

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12487 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference3rd International Conference on Machine Learning for Cyber Security, ML4CS 2020
Country/TerritoryChina
CityGuangzhou
Period8/10/2010/10/20

Keywords

  • Adversarial examples
  • Deep learning
  • Defense
  • Neural networks

Fingerprint

Dive into the research topics of 'Efficient Defense Against Adversarial Attacks and Security Evaluation of Deep Learning System'. Together they form a unique fingerprint.

Cite this