Reference : ShuffleDetect: Detecting Adversarial Images against Convolutional Neural Networks
Scientific journals : Article
Engineering, computing & technology : Computer science
Computational Sciences
http://hdl.handle.net/10993/55236
ShuffleDetect: Detecting Adversarial Images against Convolutional Neural Networks
English
Chitic, Ioana Raluca mailto [University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS) >]
Topal, Ali Osman mailto [University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS) >]
Leprevost, Franck mailto [University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS) >]
22-Mar-2023
Applied Sciences
MDPI
13
6
Computing and Artificial Intelligence
4068
Yes
International
2076-3417
Basel
Switzerland
[en] Adversarial Attacks Detection ; Evolutionary Algorithm ; Convolutional Neural Networks ; Security
[en] Recently, convolutional neural networks (CNNs) have become the main drivers in many image recognition applications. However, they are vulnerable to adversarial attacks, which can lead to disastrous consequences. This paper introduces ShuffleDetect as a new and efficient unsupervised method for the detection of adversarial images against trained convolutional neural networks. Its main feature is to split an input image into non-overlapping patches, then swap the patches according to permutations, and count the number of permutations for which the CNN classifies the unshuffled input image and the shuffled image into different categories. The image is declared adversarial if and only if the proportion of such permutations exceeds a certain threshold value. A series of 8 targeted or untargeted attacks was applied on 10 diverse and state-of-the-art ImageNet-trained CNNs, leading to 9500 relevant clean and adversarial images. We assessed the performance of ShuffleDetect intrinsically and compared it with another detector. Experiments show that ShuffleDetect is an easy-to-implement, very fast, and near memory-free detector that achieves high detection rates and low false positive rates.
University of Luxembourg: High Performance Computing - ULHPC
Researchers ; Professionals ; Students ; General public
http://hdl.handle.net/10993/55236
10.3390/app13064068
https://www.mdpi.com/2076-3417/13/6/4068

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
applsci-13-04068-v2 (2).pdfPublisher postprint4.87 MBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.