Towards Understanding Limitations of Pixel Discretization Against Adversarial Attacks

Towards Understanding Limitations of Pixel Discretization Against Adversarial Attacks
复制标题

DOI:
10.1109/eurosp.2019.00042
复制
发表时间:
2018-05
期刊:
2019 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
Jiefeng Chen;Xi Wu;Vaibhav Rastogi;Yingyu Liang;S. Jha
Jiefeng Chen;Xi Wu;Vaibhav Rastogi;Yingyu Liang;S. Jha
中科院分区:
其他
文献类型:
--
作者:
Jiefeng Chen;Xi Wu;Vaibhav Rastogi;Yingyu Liang;S. Jha

文献摘要

被引文献

相似文献

人工神经网络在各个领域的广泛采用导致了人们对防御对抗性攻击的兴趣越来越大。预处理防御方法,如像素离散化是特别有吸引力的,在实践中,由于其简单,低计算开销,并适用于各种系统。据观察,这些方法在MNIST等简单数据集上工作良好,但在最近提出的强大白盒攻击下,在ImageNet等更复杂的数据集上工作失败。为了了解成功的条件和改进的潜力,我们研究了像素离散化防御方法,包括考虑到被离散化的数据集的属性的更复杂的变体。我们的结果再次显示出对强攻击的抵抗力很差。我们在理论框架中分析了我们的结果,并提供了强有力的证据表明,像素离散化不太可能在所有数据集上工作,但最简单的数据集。此外,我们的论点提出的见解,为什么其他一些预处理防御可能是不安全的。
Wide adoption of artificial neural networks in various domains has led to an increasing interest in defending adversarial attacks against them. Preprocessing defense methods such as pixel discretization are particularly attractive in practice due to their simplicity, low computational overhead, and applicability to various systems. It is observed that such methods work well on simple datasets like MNIST, but break on more complicated ones like ImageNet under recently proposed strong white-box attacks. To understand the conditions for success and potentials for improvement, we study the pixel discretization defense method, including more sophisticated variants that take into account the properties of the dataset being discretized. Our results again show poor resistance against the strong attacks. We analyze our results in a theoretical framework and offer strong evidence that pixel discretization is unlikely to work on all but the simplest of the datasets. Furthermore, our arguments present insights why some other preprocessing defenses may be insecure.