Defending DNN Adversarial Attacks with Pruning and Logits Augmentation

Defending DNN Adversarial Attacks with Pruning and Logits Augmentation
复制标题

DOI:
10.1109/globalsip.2018.8646578
复制
发表时间:
2018-11
期刊:
2018 IEEE Global Conference on Signal and Information Processing (GlobalSIP)
影响因子:
--
通讯作者:
Siyue Wang;Xiao Wang;Shaokai Ye;Pu Zhao;X. Lin
Siyue Wang;Xiao Wang;Shaokai Ye;Pu Zhao;X. Lin
中科院分区:
其他
文献类型:
--
作者:
Siyue Wang;Xiao Wang;Shaokai Ye;Pu Zhao;X. Lin

文献摘要

被引文献

相似文献

深度神经网络(dnn)已被证明是一种强大的模型,在许多复杂的人工智能任务中表现非常出色。然而,最近的研究发现,这些强大的模型容易受到对抗性攻击,即故意在DNN输入中添加难以察觉的扰动,很容易以极高的置信度误导DNN。在这项工作中,我们通过使用修剪方法和logits增强来增强DNN在对抗性攻击下的鲁棒性,我们实现了对对抗性示例和DNN模型压缩的有效防御。我们在白盒攻击假设下观察了对抗性攻击的防御。我们的防御机制在灰盒攻击假设下工作得更好。
Deep neural networks (DNNs) have been shown to be powerful models and perform extremely well on many complicated artificial intelligent tasks. However, recent research found that these powerful models are vulnerable to adversarial attacks, i.e., intentionally added imperceptible perturbations to DNN inputs can easily mislead the DNNs with extremely high confidence. In this work, we enhance the robustness of DNNs under adversarial attacks by using pruning method and logits augmentation, we achieve both effective defense against adversarial examples and DNN model compression. We have observed defense against adversarial attacks under the white box attack assumption. Our defense mechanisms work even better under the grey box attack assumption.