Defense Mechanism against Adversarial Attacks Based on Chaotic Map Encryption

Ping Wang, Qianyu Wang, Yuting Zhang, Yifan Wu · Journal of Physics Conference Series · 2021

During recent years, image classification through DNN has been applied to various fields, including payment security and image search. DNN in image classification is effective and convenient, yet susceptible to perturbations: non-targeted and targeted adversarial attacks against neural networks, such as FGSM and BIM respectively, exert modifications that are unrecognizable to naked eyes to image inputs, and will probably result in wrong classifications. To ensure the degree of safety of DNN image classification, researchers have been dedicated to the study of defense mechanisms to diminish or even eliminate the effects brought by adversarial attacks. Our proposed approach, aims at increasing the classifier's resistance to perturbations by adding a pseudo-random matrix key generated by Logistic Chaos. Our defense mechanism with Logistic Chaos-generated secret random key utilized 1 key with mere 3 elements and is of high generality. We show empirically that our approach is efficient against most attacks.

Read the paper · More papers on PaperTik