Using Non-invertible Data Transformations to Build Adversary-Resistant Deep Neural Networks

Using Non-invertible Data Transformations to Build Adversary-Resistant Deep Neural Networks
复制标题

使用不可逆数据转换构建抗对手深度神经网络

DOI:
--
复制
发表时间:
2016
期刊:
arXiv.org
影响因子:
--
通讯作者:
Gang Xiong
Gang Xiong
中科院分区:
--
文献类型:
--
作者:
Qinglong Wang;Wenbo Guo;Alexander Ororbia;Xinyu Xing;Lin Lin;C. Lee Giles;Xue Liu;Peng Liu;Gang Xiong

文献摘要

被引文献

相似文献

深度神经网络已被证明在各种机器学习任务中非常有效,从改进的语音识别系统到推进自动驾驶汽车的开发。 However, despite their superior performance in many applications, these models have been recently shown to be susceptible to a particular type of attack possible through the generation of particular synthetic examples referred to as adversarial samples.这些样本是通过操纵训练数据分布中的真实示例来构建的,目的是“欺骗”原始神经模型,从而导致先前正确分类的样本被错误分类(具有高置信度)。如果要将深度神经架构应用于关键应用程序(例如网络安全领域的应用程序),那么解决这一弱点至关重要。在本文中,我们对所有神经架构中潜伏的这一基本缺陷进行了分析,以揭示先前提出的防御机制的局限性。更重要的是,我们提出了一个统一的框架,用于使用不可逆数据转换来保护深度神经模型,即利用线性和非线性降维开发两种具有对抗能力的架构。经验结果表明,与最先进的解决方案相比,我们的框架提供了更好的稳健性,同时准确性的下降可以忽略不计。
Deep neural networks have proven to be quite effective in a wide variety of machine learning tasks, ranging from improved speech recognition systems to advancing the development of autonomous vehicles. However, despite their superior performance in many applications, these models have been recently shown to be susceptible to a particular type of attack possible through the generation of particular synthetic examples referred to as adversarial samples. These samples are constructed by manipulating real examples from the training data distribution in order to “fool” the original neural model, resulting in misclassification (with high confidence) of previously correctly classified samples. Addressing this weakness is of utmost importance if deep neural architectures are to be applied to critical applications, such as those in the domain of cybersecurity. In this paper, we present an analysis of this fundamental flaw lurking in all neural architectures to uncover limitations of previously proposed defense mechanisms. More importantly, we present a unifying framework for protecting deep neural models using a non-invertible data transformation–developing two adversary-resilient architectures utilizing both linear and nonlinear dimensionality reduction. Empirical results indicate that our framework provides better robustness compared to stateof-art solutions while having negligible degradation in accuracy.