Adversarial image detection in deep neural networks

被引:27
作者
Carrara, Fabio [1 ]
Falchi, Fabrizio [1 ]
Caldelli, Roberto [2 ]
Amato, Giuseppe [1 ]
Becarelli, Rudy [2 ]
机构
[1] CNR, ISTI, Via G Moruzzi 1, Pisa, Italy
[2] Univ Florence, CNIT Res Unit, MICC, Viale Morgagni 65, Florence, Italy
关键词
Adversarial images detection; Deep convolutional neural network; Machine learning security;
D O I
10.1007/s11042-018-5853-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural networks are more and more pervading many computer vision applications and in particular image classification. Notwithstanding that, recent works have demonstrated that it is quite easy to create adversarial examples, i.e., images malevolently modified to cause deep neural networks to fail. Such images contain changes unnoticeable to the human eye but sufficient to mislead the network. This represents a serious threat for machine learning methods. In this paper, we investigate the robustness of the representations learned by the fooled neural network, analyzing the activations of its hidden layers. Specifically, we tested scoring approaches used for kNN classification, in order to distinguish between correctly classified authentic images and adversarial examples. These scores are obtained searching only between the very same images used for training the network. The results show that hidden layers activations can be used to reveal incorrect classifications caused by adversarial attacks.
引用
收藏
页码:2815 / 2835
页数:21
相关论文
共 47 条
  • [1] Deep learning for decentralized parking lot occupancy detection
    Amato, Giuseppe
    Carrara, Fabio
    Falchi, Fabrizio
    Gennaro, Claudio
    Meghini, Carlo
    Vairo, Claudio
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2017, 72 : 327 - 334
  • [2] YFCC100M-HNfc6: A Large-Scale Deep Features Benchmark for Similarity Search
    Amato, Giuseppe
    Falchi, Fabrizio
    Gennaro, Claudio
    Rabitti, Fausto
    [J]. SIMILARITY SEARCH AND APPLICATIONS, SISAP 2016, 2016, 9939 : 196 - 209
  • [3] Localization of JPEG double compression through multi-domain convolutional neural networks
    Amerini, Irene
    Uricchio, Tiberio
    Ballan, Lamberto
    Caldelli, Roberto
    [J]. 2017 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW), 2017, : 1865 - 1871
  • [4] [Anonymous], 2015, ICLR
  • [5] [Anonymous], PROC CVPR IEEE
  • [6] [Anonymous], 2016, ARXIV161109312
  • [7] [Anonymous], 2015, DEEP LEARNING NATURE, DOI [10.1038/nature14539, DOI 10.1038/NATURE14539]
  • [8] [Anonymous], SING CYB SEC C SG CR
  • [9] [Anonymous], ARXIV160607287
  • [10] [Anonymous], PROC CVPR IEEE