Adversarial Examples: Attacks and Defenses for Deep Learning

Adversarial Examples: Attacks and Defenses for Deep Learning
复制标题

DOI:
10.1109/tnnls.2018.2886017
复制
发表时间:
2019-09-01
影响因子:
10.4
通讯作者:
Li, Xiaolin
Li, Xiaolin
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yu, Xiaoyong;He, Pan;Li, Xiaolin

文献摘要

被引文献

相似文献

随着深度学习在广泛的应用中取得的快速进展和重大成功,深度学习正在许多安全关键环境中应用。然而,最近发现深度神经网络(DNN)容易受到被称为对抗性示例的精心设计的输入样本的影响。对抗性扰动对人类来说是不可感知的,但在测试/部署阶段很容易欺骗DNN。对抗性示例的脆弱性成为在安全关键环境中应用DNN的主要风险之一。因此,对抗性样本的攻击和防御引起了人们的极大关注。在本文中,我们回顾了DNN对抗性示例的最新研究结果,总结了生成对抗性示例的方法,并提出了这些方法的分类。根据分类法,对抗性的例子的应用程序进行了研究。我们进一步阐述对抗性例子的对策。此外,对抗性例子中的三个主要挑战和潜在的解决方案进行了讨论。
With rapid progress and significant successes in a wide spectrum of applications, deep learning is being applied in many safety-critical environments. However, deep neural networks (DNNs) have been recently found vulnerable to well-designed input samples called adversarial examples. Adversarial perturbations are imperceptible to human but can easily fool DNNs in the testing/deploying stage. The vulnerability to adversarial examples becomes one of the major risks for applying DNNs in safety-critical environments. Therefore, attacks and defenses on adversarial examples draw great attention. In this paper, we review recent findings on adversarial examples for DNNs, summarize the methods for generating adversarial examples, and propose a taxonomy of these methods. Under the taxonomy, applications for adversarial examples are investigated. We further elaborate on countermeasures for adversarial examples. In addition, three major challenges in adversarial examples and the potential solutions are discussed.