Flow-Pronged Defense Against Adversarial Examples.

Shenghong He,Chao Yi,Zongheng,Yunyun Dong
DOI: https://doi.org/10.1109/aiam54119.2021.00059
2021-01-01
Abstract:Recent studies have shown that deep neural networks are susceptible to interference from adversarial examples. Adversarial examples are adding imperceptible noise to the data. Currently, there are many types of adversarial examples in image classification, and these adversarial examples can easily lead to DNN misclassification. Therefore, it is essential to design AEs detection methods to allow them to be rejected. In the paper, we propose Flow-Pronged Defense (FPD) for adversarial examples, which is a framework for protecting neural network classification models from adversarial examples. FPD does not need to modify the protected classifier, which includes a FLOW model and a residual network classifier. The Flow model transforms the adversarial examples so that the classifier can better classify the adversarial examples and clean examples. The residual network strengthens the difference between disturbance and clean data through cross-layer connections. Compared with the state-of-the-art method, many experiments show that FPD has higher accuracy and generalization ability.
What problem does this paper attempt to address?