School of Electric Engineering and Automation, Dalian Jiaotong University, Dalian 116028, China
| Abstract: | The deep neural network has been applied well in many fields at present, but the security problem of the deep model has become increasingly prominent. Recent research shows that the neural network model will output the wrong classification by confronting samples. Therefore, confrontation samples are a major obstacle that must be overcome for the further development of deep neural networks. At present, the main task is to design an efficient and powerful defense model with strong robustness that can defend against multiple attack algorithms. This paper proposes a defense model based on multi-scale feature fusion circular confrontation generation network by combining the generation of generic adversarial networks (GAN) with existing attack algorithms. First, use the confrontation samples generated by the attack algorithm as the training samples of GAN, and use the unique network structure of CycleGan to make the reconstructed image closer to the clean image and remove potential disturbances. On the generator side, this paper uses multi feature fusion TernausNet structure to ensure that the feature information of the image can be restored as much as possible during the process of disturbance removal, and adds attention mechanism to the discriminator side to increase the receptive field, establish global dependency, and train a more robust discriminator to help GAN training through experiments on CIFAR-10 and ImageNet datasets. It is proved that after the training, the model can directly classify the original samples and confrontation samples correctly, and achieve good defense effect for all kinds of confrontation attack algorithms. Compared with the existing methods, the defense effect is good, and the robustness of the depth model is enhanced. |
| Keywords: | Confrontation Sample; Confrontation Generation Network; Multi Feature Fusion; Defense Model; Attention Mechanis |
| DOI: | 10.57237/j.se.2023.02.003 |
| [1] | CHAKRABORTY A, ALAM M, DEY V, et al. Adversarial attacks and defences: A survey [J]. 2018. |
| [2] | 张思思, 左信, 计算机学报 刘 J. 深度学习中的对抗样本问题 [J]. 2019, 42 (8): 1886-904. |
| [3] | SZEGEDY C, ZAREMBA W, SUTSKEVER I, et al. Intriguing properties of neural networks [J]. 2013. |
| [4] | GOODFELLOW I J, SHLENS J, SZEGEDY C J A P A. Explaining and harnessing adversarial examples [J]. 2014. |
| [5] | GUO C, RANA M, CISSE M, et al. Countering adversarial images using input transformations [J]. 2017. |
| [6] | HE Z, RAKIN A S, FAN D. Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack; proceedings of the Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, F, 2019 [C]. |
| [7] | LIAO F, LIANG M, DONG Y, et al. Defense against adversarial attacks using high-level representation guided denoiser; proceedings of the Proceedings of the IEEE conference on computer vision and pattern recognition, F, 2018 [C]. |
| [8] | XIE C, WANG J, ZHANG Z, et al. Mitigating adversarial effects through randomization [J]. 2017. |
| [9] | MIRZA M, OSINDERO S J A P A. Conditional generative adversarial nets [J]. 2014. |
| [10] | SHEN S, JIN G, GAO K, et al. Ape-gan: Adversarial perturbation elimination with gan [J]. 2017. |
| [11] | SAMANGOUEI P, KABKAB M, CHELLAPPA R J A P A. Defense-gan: Protecting classifiers against adversarial attacks using generative models [J]. 2018. |
| [12] | MUSTAFA A, KHAN S H, HAYAT M, et al. Image super-resolution as a defense against adversarial attacks [J]. 2019, 29: 1711-24. |
| [13] | MOOSAVI-DEZFOOLI S-M, FAWZI A, FROSSARD P. Deepfool: a simple and accurate method to fool deep neural networks; proceedings of the Proceedings of the IEEE conference on computer vision and pattern recognition, F, 2016 [C]. |
| [14] | MADRY A, MAKELOV A, SCHMIDT L, et al. Towards deep learning models resistant to adversarial attacks [J]. 2017. |
| [15] | NASEER M, KHAN S, HAYAT M, et al. A self-supervised approach for adversarial robustness; proceedings of the Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, F, 2020 [C]. |
| [16] | TRAMèR F, KURAKIN A, PAPERNOT N, et al. Ensemble adversarial training: Attacks and defenses [J]. 2017. |
| [17] | KABILAN V M, MORRIS B, NGUYEN H-P, et al. Vectordefense: Vectorization as a defense to adversarial examples [M]. Soft Computing for Biomedical Applications and Related Topics. Springer. 2021: 19-35. |
| [18] | DAS N, SHANBHOGUE M, CHEN S-T, et al. Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression [J]. 2017. |
| [19] | HINTON G, VINYALS O, DEAN J J A P A. Distilling the knowledge in a neural network [J]. 2015, 2 (7). |
| [20] | LIN Y K, WANG C F, CHANG C-Y, et al. An efficient framework for counting pedestrians crossing a line using low-cost devices: the benefits of distilling the knowledge in a neural network [J]. 2021, 80 (3): 4037-51. |
| [21] | LEE H, HAN S, LEE J J A P A. Generative adversarial trainer: Defense to adversarial perturbations with gan [J]. 2017. |
| [22] | ZHOU J, LIANG C, CHEN J. Manifold projection for adversarial defense on face recognition; proceedings of the European Conference on Computer Vision, F, 2020 [C]. Springer. |
| [23] | ZHU J, SHI L, YAN J, et al. Automix: Mixup networks for sample interpolation via cooperative barycenter learning; proceedings of the European Conference on Computer Vision, F, 2020 [C]. Springer. |
| [24] | SIMONYAN K, ZISSERMAN A J A P A. Very deep convolutional networks for large-scale image recognition [J]. 2014. |
| [25] | NeurIPS Challenge [Z]. Kaggle. 2017. |
We invite active, qualified and high profile scientists and researchers to join as Editorial Board Members.
Join UsScholars with a strong interest in reviewing are invited to join the reviewer panel to ensure the quality of the research to be published.
Join Us