paper-with-me

홈 › Papers

DoPa: A Comprehensive CNN Detection Methodology against Physical Adversarial Attacks

2019-05-21 · Zirui Xu, Fuxun Yu, Xiang Chen

Recently, Convolutional Neural Networks (CNNs) demonstrate a considerable vulnerability to adversarial attacks, which can be easily misled by adversarial perturbations. With more aggressive methods proposed, adversarial attacks can be also applied to the physical world, causing practical issues to various CNN powered applications. To secure CNNs, adversarial attack detection is considered as the most critical approach. However, most existing works focus on superficial patterns and merely search a particular method to differentiate the adversarial inputs and natural inputs, ignoring the analysis of CNN inner vulnerability. Therefore, they can only target to specific physical adversarial attacks, lacking expected versatility to different attacks. To address this issue, we propose DoPa -- a comprehensive CNN detection methodology for various physical adversarial attacks. By interpreting the CNN's vulnerability, we find that non-semantic adversarial perturbations can activate CNN with significantly abnormal activations and even overwhelm other semantic input patterns' activations. Therefore, we add a self-verification stage to analyze the semantics of distinguished activation patterns, which improves the CNN recognition process. We apply such a detection methodology into both image and audio CNN recognition scenarios. Experiments show that DoPa can achieve an average rate of 90% success for image attack detection and 92% success for audio attack detection. Announcement:[The original DoPa draft on arXiv was modified and submitted to a conference already, while this short abstract was submitted only for a presentation at the KDD 2019 AIoT Workshop.]

📄 PDF Abstract BibTeX arXiv:1905.08790

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackAdversarial Attack Detection

Similar Papers 제목 키워드 기반

LanCe: A Comprehensive and Lightweight CNN Defense Methodology against Physical Adversarial Attacks on Embedded Multimedia Applications

2019-10-17 · Zirui Xu, Fuxun Yu, Xiang Chen

Recently, adversarial attacks can be applied to the physical world, causing practical issues to various Convolutional Neural Networks (CNNs) powered applications. Most existing physical adversarial attack defense works o…

Adversarial Attack

Phasic dopamine release identification using ensemble of AlexNet

2020-06-03 · Luca Patarnello, Marco Celin, Loris Nanni

Dopamine (DA) is an organic chemical that influences several parts of behaviour and physical functions. Fast-scan cyclic voltammetry (FSCV) is a technique used for in vivo phasic dopamine release measurements. The analys…

Toward a closed-loop subcutaneous delivery of L-DOPA

2016-08-24

L-DOPA has been the gold standard treatment for Parkinson's disease since 50 years. Being the direct biochemical precursor of dopamine, L-DOPA is effectively converted in the brain, but two major phenomena reduce its the…

Dopamine: Differentially Private Federated Learning on Medical Data

2021-01-27 · Mohammad Malekzadeh, Burak Hasircioglu, Nitish Mital, Kunal Katarya 외

While rich medical datasets are hosted in hospitals distributed across the world, concerns on patients' privacy is a barrier against using such data to train deep neural networks (DNNs) for medical diagnostics. We propos…

Federated Learning

Comparative analysis of computational approaches for predicting Transthyretin transcription activators and human dopamine D1 receptor antagonists

2025-06-01 · Mariya L. Ivanova, Nicola Russo, Konstantin Nikolic

The study expands the application of scikit-learn-based machine learning (ML) to the prediction of small biomolecule functionalities based on Carbon 13 isotope (13C) NMR spectroscopy data derived from Simplified Molecula…