跳到主要导航 跳到搜索 跳到主要内容

Adversarial Example Defense via Perturbation Grading Strategy

  • Shaowei Zhu
  • , Wanli Lyu
  • , Bin Li
  • , Zhaoxia Yin*
  • , Bin Luo
  • *此作品的通讯作者
  • Anhui Provincial Key Laboratory of Multimodal Cognitive Computation, Anhui University
  • Shenzhen University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Deep Neural Networks have been widely used in many fields. However, studies have shown that DNNs are easily attacked by adversarial examples, which have tiny perturbations and greatly mislead the correct judgment of DNNs. Furthermore, even if malicious attackers cannot obtain all the underlying model parameters, they can use adversarial examples to attack various DNN-based task systems. Researchers have proposed various defense methods to protect DNNs, such as reducing the aggressiveness of adversarial examples by preprocessing or improving the robustness of the model by adding modules. However, some defense methods are only effective for small-scale examples or small perturbations but have limited defense effects for adversarial examples with large perturbations. This paper assigns different defense strategies to adversarial perturbations of different strengths by grading the perturbations on the input examples. Experimental results show that the proposed method effectively improves defense performance. In addition, the proposed method does not modify any task model, which can be used as a preprocessing module, which significantly reduces the deployment cost in practical applications.

源语言英语
主期刊名Digital Multimedia Communications - The 9th International Forum, IFTC 2022, Revised Selected Papers
编辑Guangtao Zhai, Jun Zhou, Hua Yang, Xiaokang Yang, Jia Wang, Ping An
出版商Springer Science and Business Media Deutschland GmbH
407-420
页数14
ISBN(印刷版)9789819908554
DOI
出版状态已出版 - 2023
活动9th International Forum on Digital Multimedia Communication, IFTC 2022 - Shanghai, 中国
期限: 9 12月 20229 12月 2022

出版系列

姓名Communications in Computer and Information Science
1766 CCIS
ISSN(印刷版)1865-0929
ISSN(电子版)1865-0937

会议

会议9th International Forum on Digital Multimedia Communication, IFTC 2022
国家/地区中国
Shanghai
时期9/12/229/12/22

指纹

探究 'Adversarial Example Defense via Perturbation Grading Strategy' 的科研主题。它们共同构成独一无二的指纹。

引用此