Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Adversarial Examples Detection in Features Distance Spaces

Contributo in Atti di convegno
Data di Pubblicazione:
2019
Abstract:
Maliciously manipulated inputs for attacking machine learning methods -- in particular deep neural networks -- are emerging as a relevant issue for the security of recent artificial intelligence technologies, especially in computer vision. In this paper, we focus on attacks targeting image classifiers implemented with deep neural networks, and we propose a method for detecting adversarial images which focuses on the trajectory of internal representations (i.e. hidden layers neurons activation, also known as deep features) from the very first, up?to the last. We argue that the representations of adversarial inputs follow a different evolution with respect to genuine inputs, and we define a distance-based embedding of features to efficiently encode this information. We train an LSTM network that analyzes the sequence of deep features embedded in a distance space to detect adversarial examples. The results of our preliminary experiments are encouraging: our detection scheme is able to detect adversarial inputs targeted to the ResNet-50 classifier pre-trained on the ILSVRC'12 dataset and generated by a variety of crafting algorithms.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
deep learning; adversarial machine learning
Elenco autori:
Carrara, Fabio; Amato, Giuseppe; Falchi, Fabrizio
Autori di Ateneo:
AMATO GIUSEPPE
CARRARA FABIO
FALCHI FABRIZIO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/388146
Link al Full Text:
https://iris.cnr.it//retrieve/handle/20.500.14243/388146/70830/prod_402662-doc_140034.pdf
Titolo del libro:
Computer Vision - ECCV 2018 Workshops. ECCV 2018
  • Dati Generali

Dati Generali

URL

https://link.springer.com/chapter/10.1007/978-3-030-11012-3_26
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)