Automating defense against adversarial attacks: discovery of vulnerabilities and application of multi-INT imagery to protect deployed models

Josh Kalin,David Noever,Matt Ciolino,Dominick Hambrick,Gerry Dozier,Josh D. Kalin
DOI: https://doi.org/10.1117/12.2587646
2021-04-12
Abstract:Image classification is a common step in image recognition for machine learning in overhead applications. When applying popular model architectures like MobileNetV2, known vulnerabilities expose the model to counter-attacks, either mislabeling a known class or altering box location. This work proposes an automated approach to defend these models. We evaluate the use of multi-spectral images to combat adversarial attacks. The original contribution demonstrates the attack, proposes a remedy, and automates some key outcomes for protecting the model’s predictions against adversaries. Similar to defending cyber-networks, we combine techniques from both offensive (“red team”) and defensive (“blue team”) approaches, thus generating a hybrid protective outcome (“green team”). For machine learning, we demonstrate these methods with 3-color channels plus infrared. The outcome uncovers vulnerabilities and corrects them with supplemental data inputs commonly found in overhead cases particularly.
What problem does this paper attempt to address?