Fast Confidence Detection: One Hot Way to Detect Adversarial Attacks via Sensor Pattern Noise Fingerprinting

Fast Confidence Detection: One Hot Way to Detect Adversarial Attacks via Sensor Pattern Noise Fingerprinting
复制标题

快速置信度检测:通过传感器模式噪声指纹识别来检测对抗性攻击的一种热门方法

DOI:
10.1145/3289602.3293975
复制
发表时间:
2019
期刊:
International Symposium on Field-Programmable Gate Arrays
影响因子:
--
通讯作者:
Chen, Yiran
Chen, Yiran
中科院分区:
--
文献类型:
--
作者:
Lan, Yazhu;Guo, Qingli;Zhang, Guohe;Xu, Yuanchao;Nixon, Kent W.;Li, Hai Helen;Chen, Yiran

文献摘要

相似文献

深度神经网络(DNN)在现实世界的广泛应用中显示出惊人的成功。然而,DNN的一个令人担忧的弱点是它们容易受到对手攻击。虽然存在检测对抗性攻击的方法,但它们往往受到特定攻击类型的限制,并且向下游系统提供的信息有限。我们特别注意到,现有的对抗性检测器通常是二进制分类器,它们区分干净的或对抗性的例子。然而,检测对抗性的例子比这样的场景复杂得多。我们的主要见解是,将输入样本检测为对抗性样本的置信度概率将对系统正确采取行动抵御潜在攻击更有用。在这项工作中,我们提出了一种基于输入样本中传感器模式噪声完整性的对抗性攻击快速置信度检测方法。实验结果表明,该方法能够为大多数常见的对抗性攻击提供置信度分布模型。此外,该方法还可以根据置信度分布模型的不同性质为不同的攻击类型提供早期攻击预警。针对快速置信度检测的计算量大的问题,提出了一种基于增量式多级量化等一系列优化技术的硬件结构,并在现场可编程门阵列平台上实现了该方法,获得了29.740 IPS/W的高效率,而功耗仅为0.7626W。
Deep Neural Networks (DNNs) have shown phenomenal success in a wide range of real-world applications. However, a concerning weakness of DNNs is that they are vulnerable to adversarial attacks. Although there exist methods to detect adversarial attacks, they often suffer constraints on specific attack types and provide limited information to downstream systems. We specifically note that existing adversarial detectors are often binary classifiers, which differentiate clean or adversarial examples. However, detection of adversarial examples is much more complicated than such a scenario. Our key insight is that the confidence probability of detecting an input sample as an adversarial example will be more useful for the system to properly take action to resist potential attacks. In this work, we propose an innovative method for fast confidence detection of adversarial attacks based on integrity of sensor pattern noise embedded in input examples. Experimental results show that our proposed method is capable of providing a confidence distribution model of most of popular adversarial attacks. Furthermore, our presented method can provide early attack warning with even the attack types based on different properties of the confidence distribution models. Since fast confidence detection is a computationally heavy task, we propose an FPGA-Based hardware architecture based on a series of optimization techniques, such as incremental multi-level quantization and etc. We realize our proposed method on an FPGA platform and achieve a high efficiency of 29.740 IPS/W with a power consumption of only 0.7626W.