DP2Net: Defense Against Adversarial Examples by Detecting Perturbed Pixels
At a glance
- Citations
- 0
- References
- 30
- Comments
- 0
Abstract
Deep neural network technology is becoming more and more powerful, and its technical performance is obvious to all. However, the emergence of adversarial samples has raised concerns about the security of deep neural networks. In this paper, we first propose a beam search-based approach to define, search, and classify the perturbed pixels in the perturbed samples, and then propose a deep neural network model based on semantic segmentation network, which can do pixel-level detection distribution perturbation classification and classify the perturbed samples with normal samples based on the perturbation compared to previous work. The experiments are based on MNIST and CIFAR-10 datasets, and the three image classification network models are attacked by two perturbation attack algorithms to generate several perturbation samples, which are mixed with normal samples as the training and test sets of this perturbation detection network. The experimental results show that using this network as a predecessor model can effectively detect the scrambled pixels and make sample classification, thus playing a defensive role and effectively improving the model’s robustness and security.
Publication details
- DOI
- 10.1109/icsip55141.2022.9886169
- OpenAlex
- W4296441440
- Document type
- conference-paper
- Language
- EN
- Source
- 2022 7th International Conference on Signal and Image Processing (ICSIP)
- Last metadata update
Comments
Log in to join the discussion.