节点文献

基于冗余信息压缩的深度学习对抗样本防御方案

Information redundancy compression for adversarial defense

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 许笑陈奕君冯诗羽谢理哲曹玖新胡轶宁

【Author】 Xu Xiao;Chen Yijun;Feng Shiyu;Xie Lizhe;Cao jiuxin;Hu Yining;School of Cyber Science and Engineering, Southeast University;School of Computer Science and Engineering, Southeast University;Institute of Stomatology, Nanjing Medical University;Jiangsu Key Laboratory of Oral Diseases Research;Jiangsu Key Laboratory of Computer Networking Technology;Cyberspace International Governance Research Institute (Southeast University);

【机构】 东南大学网络空间安全学院东南大学计算机科学与工程学院南京医科大学口腔医学院江苏省口腔疾病研究重点实验室江苏省计算机网络技术重点实验室网络空间国际治理研究基地(东南大学)

【摘要】 近年来,研究者们发现基于神经网络的深度学习系统存在安全隐患,添加了细微扰动的输入样本,可能会使模型失效,这类样本被称为对抗样本。文章提出了冗余信息压缩方案,可以有效地抵御对抗样本攻击。该方案将图像随机压缩与多尺寸缩放集成策略相结合,对图像信息进行选择性压缩处理,有效减少冗余信息,消除了附加扰动。方案的优势体现在三个方面:(1)针对预处理环节,易于实施;(2)实现了随机化和集成策略;(3)与其他对抗样本防御方法兼容。实验结果表明,面对多种先进的对抗样本攻击,与其他预处理防御方案相比,冗余信息压缩防御方案在多个基础模型上都有更出色的防御表现,同时对模型在干净图像上的分类能力影响较小。

【Abstract】 In recent years,neural networks have been found vulnerable to subtle input perturbations which lead to completely preposterous outputs.These samples which make model invalidate are called adversarial samples.This paper proposes Information Redundant Compression(IRC) to counter the adversarial attacks.IRC combines random image compression with integrated multi-scale scaling to selectively compress image information.IRC effectively reduces redundant information and eliminates additional perturbations in image.The advantages of IRC:(1) Pre-processing aspect of deep learning system.(2) Combining randomization and integration strategy.(3) Compatible with other defense methods.Evaluated by many advanced adversarial attacks,IRC has the best defense performance compared to other pre-processing defense schemes,while having little impact on the classification ability of model.

  • 【文献出处】 网络空间安全 ,Cyberspace Security , 编辑部邮箱 ,2020年08期
  • 【分类号】TP391.41;TP18
  • 【被引频次】3
  • 【下载频次】203
节点文献中: