A Model robustness optimization method based on adversarial sample detection

Jiaze Sun, Siyuan Long, Xianyan Ma, Y.C. Tang · 2022

Deep neural networks are extremely vulnerable due to the existence of adversarial samples. It is a challenging problem to optimize the robustness of the model to protect deep neural networks from the threat of adversarial samples. To improve the model robustness, an integrated detection model of adversarial samples is designed to detect the existence of adversarial samples, which consists of a multi-classification detector and five single-classification detectors to perform double-layer detection of adversarial samples and intercept the adversarial samples finally sent to the image classification model. The detection experiments were conducted on the CIFAR-10 dataset for the adversarial samples generated by five attack algorithms: FGSM, BIM, DeepFool, JSMA, and C&W, and the detection success rate for all types of adversarial samples reached over 98.96%. After that, secondary attack experiments were conducted on the model, and the detection success rate of the model for the second attack adversarial samples reached over 92.36%. It provides an efficient and robust optimization method for deep neural network models in adversarial environments.

Read the paper · More papers on PaperTik