Skip to main navigation Skip to search Skip to main content

Defending against sparse adversarial attacks using impulsive noise reduction filters

  • Silesian University of Technology
  • Warsaw University of Technology
  • Exida

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Citations (Scopus)

Abstract

Deep Neural Networks (DNNs) have been deployed in many real-world applications in various domains, both industry and academic, and have proven to deliver outstanding performance. However, DNNs are vulnerable to adversarial attacks, that are small perturbations embedded in an image. As a result, introduction of DNNs into safety-critical systems, such as autonomous vehicles, unmanned aerial vehicles or healthcare devices, would introduce very high risk of limiting their capabilities to recognize and interpret the environment in which they are used and therefore would lead to devastating consequences. Thus, robustness enhancement of DNNs by development of defense mechanisms is a matter of the utmost importance. In this paper, we evaluated a set of state-of-the-art denoising filters designed for impulsive noise removal as defensive solutions. The proposed methods are applied as a pre-processing step, in which the adversarial patterns in the source image are removed before performing classification task. As a result, the pre-processing defense block can be easily integrated with any type of classifier, without any knowledge about utilized training procedures or internal architecture of the model. Moreover, the evaluated filtering methods can be considered as universal defensive techniques, as they are completely unrelated with the internal aspects of the selected attack and can be applied against any type of adversarial threats. The experimental results obtained on German Traffic Sign Recognition Benchmark (GTSRB) have proven that the denoising filters provide high robustness against sparse adversarial attacks and do not significantly decrease the classification performance on non-altered data.

Original languageEnglish
Title of host publicationReal-Time Image Processing and Deep Learning 2021
EditorsNasser Kehtarnavaz, Matthias F. Carlsohn
PublisherSPIE
ISBN (Electronic)9781510643093
DOIs
Publication statusPublished - 2021
EventReal-Time Image Processing and Deep Learning 2021 - Virtual, Online, United States
Duration: 12 Apr 202116 Apr 2021

Publication series

NameProceedings of SPIE - The International Society for Optical Engineering
Volume11736
ISSN (Print)0277-786X
ISSN (Electronic)1996-756X

Conference

ConferenceReal-Time Image Processing and Deep Learning 2021
Country/TerritoryUnited States
CityVirtual, Online
Period12/04/2116/04/21

Keywords

  • Adversarial attacks
  • Deep learning
  • Evolutionary algorithms
  • Image denoising
  • Impulsive noise
  • Neural networks
  • Safety
  • Sparse adversarial attacks

ASJC Scopus subject areas

  • Electronic, Optical and Magnetic Materials
  • Instrumentation
  • Condensed Matter Physics
  • Computer Science Applications
  • Applied Mathematics
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Defending against sparse adversarial attacks using impulsive noise reduction filters'. Together they form a unique fingerprint.

Cite this