On a Detection Method of Adversarial Samples for Deep Neural Networks
Felix Govaers, Paul M. Baggenstoss · 2021 IEEE 24th International Conference on Information Fusion (FUSION) · 2021
Data-driven classification based on deep learning provides overwhelming results in various applications. However, such neural networks are easily mislead by malicious attacks, if the parameters are known to an attacker. Though the perturbations of such adversarial examples added to the data are so small that the human eye hardly sees it, neural networks provide false results with very high probability. In this paper, we show that generative methods can well be used to visualize the effect to an human operator. By means of the generated samples, an automated detector can be constructed. The performance of such a detector is evaluated for three different architectures.1