Detection Mechanisms of One-Pixel Attack

Detection Mechanisms of One-Pixel Attack
复制标题

单像素攻击检测机制

DOI:
10.1155/2021/8891204
复制
发表时间:
2021
影响因子:
--
通讯作者:
Li, Wei
Li, Wei
中科院分区:
计算机科学4区
文献类型:
--
作者:
Wang, Peng;Cai, Zhipeng;Kim, Donghyun;Li, Wei

文献摘要

被引文献

相似文献

近年来,一系列研究表明深度神经网络(DNN)容易受到对抗性攻击,并提出了许多攻击方法。在这些方法中,一种名为单像素攻击的非常狡猾的攻击类型可以通过仅修改图像的一个像素来误导DNN错误分类图像,从而对基于DNN的信息系统造成严重的安全威胁。目前还没有一种方法能够真正检测到单像素攻击,本文将填补这方面的空白。本文提出了两种检测方法,包括触发检测和候选检测。触发检测方法分析DNN模型的脆弱性,并给出被单像素攻击修改的最可疑像素。候选检测方法使用基于差分进化的启发式算法识别一组最可疑的像素。真实的数据实验表明,触发检测方法的检测成功率为9.1%,候选检测方法的检测成功率为30.1%,验证了本文方法的有效性。
In recent years, a series of researches have revealed that the Deep Neural Network (DNN) is vulnerable to adversarial attack, and a number of attack methods have been proposed. Among those methods, an extremely sly type of attack named the one‐pixel attack can mislead DNNs to misclassify an image via only modifying one pixel of the image, leading to severe security threats to DNN‐based information systems. Currently, no method can really detect the one‐pixel attack, for which the blank will be filled by this paper. This paper proposes two detection methods, including trigger detection and candidate detection. The trigger detection method analyzes the vulnerability of DNN models and gives the most suspected pixel that is modified by the one‐pixel attack. The candidate detection method identifies a set of most suspected pixels using a differential evolution‐based heuristic algorithm. The real‐data experiments show that the trigger detection method has a detection success rate of 9.1%, and the candidate detection method achieves a detection success rate of 30.1%, which can validate the effectiveness of our methods.