paper-with-me

Papers

TamperNN: Efficient Tampering Detection of Deployed Neural Nets

2019-03-01 · Erwan Le Merrer, Gilles Tredan

Neural networks are powering the deployment of embedded devices and Internet of Things. Applications range from personal assistants to critical ones such as self-driving cars. It has been shown recently that models obtained from neural nets can be trojaned ; an attacker can then trigger an arbitrary model behavior facing crafted inputs. This has a critical impact on the security and reliability of those deployed devices. We introduce novel algorithms to detect the tampering with deployed models, classifiers in particular. In the remote interaction setup we consider, the proposed strategy is to identify markers of the model input space that are likely to change class if the model is attacked, allowing a user to detect a possible tampering. This setup makes our proposal compatible with a wide range of scenarios, such as embedded models, or models exposed through prediction APIs. We experiment those tampering detection algorithms on the canonical MNIST dataset, over three different types of neural nets, and facing five different attacks (trojaning, quantization, fine-tuning, compression and watermarking). We then validate over five large models (VGG16, VGG19, ResNet, MobileNet, DenseNet) with a state of the art dataset (VGGFace2), and report results demonstrating the possibility of an efficient detection of model tampering.

📄 PDF Abstract BibTeX arXiv:1903.00317

Code (0)

등록된 구현이 없습니다.

Tasks

QuantizationSelf-Driving Cars

Methods 이 논문이 사용한 방법론

Average Pooling 설명 없음
Global Average Pooling Global Average Pooling is a pooling operation designed to replace fully connected layers in classical CNNs. The idea is to generate one feature map for each corresponding…
1x1 Convolution A 1 x 1 Convolution is a convolution with some special properties in that it can be used for dimensionality reduction,…
ReLU How Do I Communicate to Expedia? How Do I Communicate to Expedia? – Call ☎️ +1-(888) 829 (0881) or +1-805-330-4056 or +1-805-330-4056 for Live Support & Special Travel…
Batch Normalization 설명 없음
Bottleneck Residual Block A Bottleneck Residual Block is a variant of the residual block that utilises 1x1 convolutions to create a bottleneck. The…
Max Pooling Max Pooling is a pooling operation that calculates the maximum value for patches of a feature map, and uses it to create a downsampled (pooled) feature map. It is usually…
Kaiming Initialization 설명 없음

Similar Papers 제목 키워드 기반

Deep Multi-scale Discriminative Networks for Double JPEG Compression Forensics

2019-04-04 · Cheng Deng, Zhao Li, Xinbo Gao, DaCheng Tao

As JPEG is the most widely used image format, the importance of tampering detection for JPEG images in blind forensics is self-evident. In this area, extracting effective statistical characteristics from a JPEG image for…

General Classification

Datasets, Clues and State-of-the-Arts for Multimedia Forensics: An Extensive Review

2024-01-13 · Ankit Yadav, Dinesh Kumar Vishwakarma

With the large chunks of social media data being created daily and the parallel rise of realistic multimedia tampering methods, detecting and localising tampering in images and videos has become essential. This survey fo…

DeepFake DetectionDeep LearningFace Swapping

TAMPAR: Visual Tampering Detection for Parcel Logistics in Postal Supply Chains

2023-11-06 · Alexander Naumann, Felix Hertlein, Laura Dörr, Kai Furmans

Due to the steadily rising amount of valuable goods in supply chains, tampering detection for parcels is becoming increasingly important. In this work, we focus on the use-case last-mile delivery, where only a single RGB…

Change DetectionKeypoint Detection

A Survey of Feature Types and Their Contributions for Camera Tampering Detection

2023-10-11 · Pranav Mantini, Shishir K. Shah

Camera tamper detection is the ability to detect unauthorized and unintentional alterations in surveillance cameras by analyzing the video. Camera tampering can occur due to natural events or it can be caused intentional…

Change DetectionTime SeriesTime Series Analysis

A Novel Region Duplication Detection Algorithm Based on Hybrid Approach

2022-04-10 · Kshipra Tatkare, Manoj Devare

The digital images from various sources are ubiquitous due to easy availability of high bandwidth Internet. Digital images are easy to tamper with good or bad intentions. Non-availability of pre-embedded information in d…