跳至主導覽 跳至搜尋 跳過主要內容

A Robust Countermeasures for Poisoning Attacks on Deep Neural Networks of Computer Interaction Systems

研究成果: Article同行評審

4   !!Link opens in a new tab 引文 斯高帕斯(Scopus)

摘要

In recent years, human–computer interactions have begun to apply deep neural networks (DNNs), known as deep learning, to make them work more friendly. Nowadays, adversarial example attacks, poisoning attacks, and backdoor attacks are the typical attack examples for DNNs. In this paper, we focus on poisoning attacks and analyze three poisoning attacks on DNNs. We develop a countermeasure for poisoning attacks, which is Data Washing, an algorithm based on a denoising autoencoder. It can effectively alleviate the damages inflicted upon datasets caused by poisoning attacks. Furthermore, we also propose the Integrated Detection Algorithm (IDA) to detect various types of attacks. In our experiments, for Paralysis Attacks, Data Washing represents a significant improvement (0.5384) over accuracy increment, and can help IDA detect those attacks, while for Target Attacks, Data Washing makes it so that the false positive rate is reduced to just 1% and IDA can have a high accuracy detection rate of greater than 99%.

原文English
文章編號7753
期刊Applied Sciences (Switzerland)
12
發行號15
DOIs
出版狀態Published - 2022 8月

All Science Journal Classification (ASJC) codes

  • 一般材料科學
  • 儀器
  • 一般工程
  • 製程化學與技術
  • 電腦科學應用
  • 流體流動和轉移過程

指紋

深入研究「A Robust Countermeasures for Poisoning Attacks on Deep Neural Networks of Computer Interaction Systems」主題。共同形成了獨特的指紋。

引用此