Detection of adversarial attacks based on differences in image entropy

Citations

WEB OF SCIENCE

9
Citations

SCOPUS

13

초록

Although deep neural networks (DNNs) have achieved high performance across various applications, they are often deceived by adversarial examples generated by adding small perturbations. To combat adversarial attacks, many detection methods have been proposed, including feature squeezing and trapdoor. However, these methods rely on the output of DNNs or involve training a separate network to detect adversarial examples, which leads to high computational costs and low efficiency. In this study, we propose a simple and effective approach called the entropy-based detector (EBD) to protect DNNs from various adversarial attacks. EBD detects adversarial examples by comparing the difference in entropy between the input sample before and after bit depth reduction. We show that EBD can detect over 98% of the adversarial examples generated by attacks using fast-gradient sign method, basic iterative method, momentum iterative method, DeepFool and CW attacks when the false positive rate is 2.5% for CIFAR-10 and ImageNet datasets.

키워드

Adversarial attackAdversarial defenseAdversarial examplesDeep neural networkImage entropy
제목
Detection of adversarial attacks based on differences in image entropy
저자
Ryu, GwonsangChoi, Daeseon
DOI
10.1007/s10207-023-00735-6
발행일
2024-02
유형
Article
저널명
International Journal of Information Security
23
1
페이지
299 ~ 314