A Neuro-Inspired Autoencoding Defense Against Adversarial Attacks

A Neuro-Inspired Autoencoding Defense Against Adversarial Attacks
复制标题

DOI:
10.1109/icip42928.2021.9506184
复制
发表时间:
2021-09
期刊:
2021 IEEE International Conference on Image Processing (ICIP)
影响因子:
--
通讯作者:
Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow
Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow
中科院分区:
其他
文献类型:
--
作者:
Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow

文献摘要

相似文献

深度神经网络(DNN)容易受到对抗性攻击:精心构造的图像扰动会严重损害分类准确性,同时人类无法感知。目前最有效的防御方法是使用对抗干扰的例子来训练网络。在本文中,我们研究了一种完全不同的、神经启发的防御机制,旨在在对抗性扰动到达分类器DNN之前拒绝它们,使用具有生物视觉中常见特征的编码器,然后使用解码器恢复可以与标准CNN架构级联的图像尺寸。与对抗训练不同,所有训练都基于干净的图像。我们在CFAR-10和Imagenet数据集子集上的实验显示,与最先进的对抗训练相比,性能具有竞争力,并指出自下而上的神经启发技术对设计鲁棒神经网络的承诺。
Deep Neural Networks (DNNs) are vulnerable to adversarial attacks: carefully constructed perturbations to an image can seriously impair classification accuracy, while being imperceptible to humans. The most effective current defense is to train the network using adversarially perturbed examples. In this paper, we investigate a radically different, neuro-inspired defense mechanism, aiming to reject adversarial perturbations before they reach a classifier DNN, using an encoder with characteristics commonly observed in biological vision, followed by a decoder restoring image dimensions that can be cascaded with standard CNN architectures. Unlike adversarial training, all training is based on clean images. Our experiments on the CFAR-10 and a subset of Imagenet datasets show performance competitive with state-of-the-art adversarial training, and point to the promise of bottom-up neuro-inspired techniques for the design of robust neural networks.