A Defense Method Against Facial Adversarial Attacks

Chiranjeevi Sadu, Pradip K. Das · TENCON 2021 - 2021 IEEE Region 10 Conference (TENCON) · 2021

Machine Learning (ML) models have impressively performed on perceptual tasks over the past few years. However, these models remain vulnerable to adversarial attacks. An adversarial attack modifies an input by adding small perturbations to cause classifier misclassification. Although many efforts have been spent on training robust forensic models against this type of attack, the mitigation of adversarial attacks and defense against such attacks remain an active problem. We propose a defense method in forensics that mainly focuses on face adversarial attacks detection. The proposed defense method is based on the Private Fast Gradient Sign Method (P-FGSM) and Weighted Local Magnitude Pattern (WLMP) features. Face adversarial attacks are generated based on P-FGSM and extracted WLMP features are provided to Support Vector Machines (SVM) for detection of face adversarial images from the original face images. The proposed defense method is evaluated on a real-world dataset and results show that it detects the adversarial images from the original dataset with an accuracy of 98.75%.

Read the paper · More papers on PaperTik