Defending Against Adversarial Attacks Using Digital Image Processing

Yuyang Xiao,Xiaoyan Deng,Zhuliang Yu
DOI: https://doi.org/10.1088/1742-6596/2577/1/012016
2023-01-01
Journal of Physics Conference Series
Abstract:Abstract The rapidly maturing deep neural networks are used in self-driving cars, facial recognition payment, security, and other aspects, and are crucial to how we conduct our daily lives. However, past research has shown that adversarial attacks pose a significant danger to deep learning. This paper proposes a defense based on digital image processing to protect the handwritten digit recognition model from adversarial attacks. This method can defend against adversarial attacks simply and effectively using spatial filtering and thresholding for image pre-processing to remove adversarial perturbations. The experimental findings on the MNIST data set show that this technique can increase the average accuracy of the model against adversarial samples to 91.20%.
What problem does this paper attempt to address?