Towards A Guided Perturbation for Privacy Protection through Detecting Adversarial Examples with Provable Accuracy and Precision
Ying Lin, Yanzhen Qu, Zhiyuan Zhang, Haorong Su · 2019
In this paper, we aim to demonstrate a practical mechanism to determine the boundary which can guide the design and implementation of privacy protection through perturbation. We have leveraged the strategy of detecting adversarial examples through a set of detection methods to find the "blind corners" of detection, and use them as the guidance of design and implementation of perturbation for privacy protection. To ensure the confidence of this approach, we have created a detection mechanism which has a very high accuracy and precision. First we use a classical statistical method to detect most of adversarial examples. Then, in considering that small examples sets will impact the confidence of statistical tests, we applied second detection method to discover the adversarial examples escaped from the first round detection by comparing similarity of the loss curves of training on the original data and tested data. Experiment results have shown that our enhanced detection mechanism not only extends the capability of detecting more adversarial examples in a much broad scope of perturbation, but also provides us the set of boundaries, represented by the values of a set of thresholds of exploring the "blind corners" of the detection methods, which can be practically used to effectively direct the design and implementation of perturbation for privacy protection. This is also the main contribution of this paper.