跳到主要导航 跳到搜索 跳到主要内容

Toward Evaluating the Reliability of Deep-Neural-Network-Based IoT Devices

  • Mingyuan Fan
  • , Yang Liu
  • , Cen Chen
  • , Shengxing Yu
  • , Wenzhong Guo*
  • , Li Wang
  • , Ximeng Liu*
  • *此作品的通讯作者
  • Fuzhou University
  • Xidian University
  • School of Cyber Engineering, Xidian University
  • Peking University
  • Ant Group

科研成果: 期刊稿件文章同行评审

摘要

Nowadays, the impressive performance of deep neural networks (DNNs) greatly advances the development of Internet of Things (IoT) in diverse scenarios. However, the exceptional vulnerability of DNNs to adversarial attack leads IoT devices to be exposed to potential security issues. Up to now, since adversarial training empirically remains robust against gradient-based adversarial attacks, it is believed to be the most effective defense method. In this article, we find that adversarial examples generated by gradient-based adversarial attacks tend to be less imperceptible induced by the gradient-based optimization methods (adopted in the attacks) being difficult on searching the most effective adversarial examples (i.e., the global extreme points), which may lead to an inaccurate estimation for the effectiveness of the adversarial training. To overcome the inherent defect of gradient-based adversarial attacks, we propose a novel adversarial attack named nongradient attack (NGA), of which search strategy is effective but no longer depends on gradients to enhance the threat of adversarial examples. In detail, NGA first initializes the adversarial examples outside, rather than inside, of decision boundary to make them misclassified by the model and then, under without violation of misclassified condition, adjusts the adversarial examples toward the crafted direction to close the original examples. Extensive experiments show that NGA significantly outperforms the state-of-the-art adversarial attacks on attack success rate (ASR) by 2%-7%. Moreover, we propose a new evaluation metric, i.e., composite criterion (CC) based on both ASR and accuracy, to better measure the effectiveness of adversarial training. In the experiments, CC has shown to be a more comprehensive yet appropriate evaluation metric.

源语言英语
页(从-至)17002-17013
页数12
期刊IEEE Internet of Things Journal
9
18
DOI
出版状态已出版 - 15 9月 2022

学术指纹

探究 'Toward Evaluating the Reliability of Deep-Neural-Network-Based IoT Devices' 的科研主题。它们共同构成独一无二的学术指纹。

引用此