Reinforcing the Robustness of a Deep Neural Network to Adversarial Examples by Using Color Quantization of Training Image Data

Reinforcing the Robustness of a Deep Neural Network to Adversarial Examples by Using Color Quantization of Training Image Data
复制标题

DOI:
10.1109/icip.2019.8802996
复制
发表时间:
2019-09
期刊:
2019 IEEE International Conference on Image Processing (ICIP)
影响因子:
--
通讯作者:
Shuntaro Miyazato;Xueting Wang;T. Yamasaki;K. Aizawa
Shuntaro Miyazato;Xueting Wang;T. Yamasaki;K. Aizawa
中科院分区:
其他
文献类型:
--
作者:
Shuntaro Miyazato;Xueting Wang;T. Yamasaki;K. Aizawa

文献摘要

相似文献

最近的研究表明,深度卷积神经网络(DCNN)在恶意扰动的对抗性示例中存在脆弱性。特别是,黑盒攻击的参数和结构的目标模型的信息担心作为现实的威胁。为了解决这个问题,我们提出了一种方法,使用一个合奏的颜色量化的数据与损失最大化训练的模型。颜色量化可以让训练好的模型专注于学习显著的空间特征,以增强DCNN对对抗性样本的鲁棒性。该方法不需要特定的攻击算法来进行防御,能够适应黑盒攻击。我们的实验结果验证了有效性,以防止在测试精度的下降与对抗性扰动。
Recent works have shown the vulnerability of deep convolutional neural network (DCNN) to adversarial examples with malicious perturbations. In particular, Black-Box attacks without information of parameter and architectures of the target models are feared as realistic threats. To address this problem, we propose a method using an ensemble of models trained by color-quantized data with loss maximization. Color-quantization can allow the trained models to focus on learning conspicuous spatial features to enhance the robustness of DCNNs to adversarial examples. The proposed method can be adapted to Black-Box attacks with no need of particular attack algorithm for the defense. The results of our experiments validated the effectiveness for preventing decrease in the test accuracy with adversarial perturbation.