跳到主要导航 跳到搜索 跳到主要内容

A detect-and-modify region-based classifier to defend evasion attacks

  • Jiawei Jiang
  • , Yongxin Zhao*
  • , Xi Wu
  • , Genwang Gou
  • *此作品的通讯作者
  • East China Normal University
  • University of Sydney

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Deep Neural Networks (DNNs) are powerful models that have achieved impressive results on image classifications. However, they are vulnerable to be attacked by adversarial examples, which are crafted to cause prediction errors in DNNs. In order to make the networks more robust and reliable, in this paper, we present an improved region-based classification to mitigate the evasion attack, which is well known to attack DNNs via generating adversarial examples. Specifically, in our framework, an image is considered as a matrix of Markov Chains and we detect possible adversarial examples according to the Image Transition Probabilities (ITPs) in Markov Chains. Furthermore, we modify the original ITPs of the detected adversarial examples by using the saliency map of ITPs, and we employ our improved region-based classification on these updated adversarial examples to get a better output prediction. Finally, our experiments illustrate that our approach reduces the test errors imposed by adversarial examples on MNIST datasets and CIFAR-10 datasets.

源语言英语
主期刊名SEKE 2020 - Proceedings of the 32nd International Conference on Software Engineering and Knowledge Engineering
出版商Knowledge Systems Institute Graduate School
19-24
页数6
ISBN(电子版)1891706500
DOI
出版状态已出版 - 2020
活动32nd International Conference on Software Engineering and Knowledge Engineering, SEKE 2020 - Pittsburgh, Virtual, 美国
期限: 9 7月 202019 7月 2020

出版系列

姓名Proceedings of the International Conference on Software Engineering and Knowledge Engineering, SEKE
PartF162440
ISSN(印刷版)2325-9000
ISSN(电子版)2325-9086

会议

会议32nd International Conference on Software Engineering and Knowledge Engineering, SEKE 2020
国家/地区美国
Pittsburgh, Virtual
时期9/07/2019/07/20

学术指纹

探究 'A detect-and-modify region-based classifier to defend evasion attacks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此