Resisting Deep Learning Models Against Adversarial Attack Transferability via Feature Randomization

对抗制 计算机科学 可转让性 人工智能 机器学习 深度学习 稳健性(进化) 分类器(UML) 对抗性机器学习 生物化学 基因 罗伊特 化学
作者
Ehsan Nowroozi,Mohammadreza Mohammadi,Pargol Golmohammadi,Yassine Mekdad,Mauro Conti,A. Selcuk Uluagac
出处
期刊:IEEE Transactions on Services Computing [Institute of Electrical and Electronics Engineers]
卷期号:17 (1): 18-29 被引量:7
标识
DOI:10.1109/tsc.2023.3329081
摘要

In the past decades, the rise of artificial intelligence has given us the capabilities to solve the most challenging problems in our day-to-day lives, such as cancer prediction and autonomous navigation. However, these applications might not be reliable if not secured against adversarial attacks. In addition, recent works demonstrated that some adversarial examples are transferable across different models. Therefore, it is crucial to avoid such transferability via robust models that resist adversarial manipulations. In this paper, we propose a feature randomization-based approach that resists eight adversarial attacks targeting deep learning models in the testing phase. Our novel approach consists of changing the training strategy in the target network classifier and selecting random feature samples. We consider the attacker with a Limited-Knowledge and Semi-Knowledge conditions to undertake the most prevalent types of adversarial attacks. We evaluate the robustness of our approach using the well-known UNSW-NB15 datasets that include realistic and synthetic attacks. Afterward, we demonstrate that our strategy outperforms the existing state-of-the-art approach, such as the Most Powerful Attack, which consists of fine-tuning the network model against specific adversarial attacks. Further, we demonstrate the practicality of our approach using the VIPPrint dataset through a comprehensive set of experiments. Finally, our experimental results show that our methodology can secure the target network and resists adversarial attack transferability by over 60%.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
落寞平蝶完成签到,获得积分10
刚刚
充电宝应助爱听歌迎夏采纳,获得10
1秒前
Ccc发布了新的文献求助10
3秒前
3秒前
ggy发布了新的文献求助10
4秒前
jdio完成签到,获得积分10
6秒前
刘刘刘完成签到,获得积分10
7秒前
宴之敖者发布了新的文献求助10
8秒前
9秒前
充电宝应助白枫采纳,获得10
9秒前
Wendy完成签到 ,获得积分10
10秒前
12秒前
楠楠完成签到,获得积分10
12秒前
12秒前
星辰大海应助阔达的翎采纳,获得10
12秒前
13秒前
zz发布了新的文献求助10
14秒前
找找找完成签到 ,获得积分10
14秒前
小刘发布了新的文献求助10
14秒前
王祥瑞完成签到,获得积分10
15秒前
白枫完成签到,获得积分10
16秒前
HuiLang应助ggy采纳,获得10
16秒前
CodeCraft应助小刘采纳,获得10
19秒前
19秒前
TT001完成签到,获得积分10
19秒前
19秒前
芜茗发布了新的文献求助10
19秒前
Owen应助伍志伟采纳,获得10
21秒前
Akim应助阿锐采纳,获得10
21秒前
闫111完成签到,获得积分20
22秒前
合适的曼安完成签到 ,获得积分10
22秒前
23秒前
Sula37发布了新的文献求助10
23秒前
帅气的涵山关注了科研通微信公众号
23秒前
ggy发布了新的文献求助10
24秒前
qianlailai发布了新的文献求助10
25秒前
斯文败类应助Ccc采纳,获得10
26秒前
27秒前
28秒前
29秒前
高分求助中
Principles of Economics, 11th Edition 10000
Prescott's Microbiology: 2026 Release ISE 10000
University Physics with Modern Physics, 16th edition 10000
Cronologia da história de Macau 5000
Environmental Leverage in Times of Climate Crisis: Product Standards, Carbon Border Measures and Preferential Trade Agreements 1000
Interactions of Vowel Quality and Prosody in East Slavic 1000
Matrix Methods in Data Mining and Pattern Recognition 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7158082
求助须知:如何正确求助?哪些是违规求助? 8802220
关于积分的说明 18601311
捐赠科研通 6760146
什么是DOI,文献DOI怎么找? 3162234
关于科研通互助平台的介绍 2297577
邀请新用户注册赠送积分活动 2136854