Defending against Adversarial Attacks using Digital Image Processing
Yuyang Xiao, Xiaoyan Deng, Zhuliang Yu · Journal of Physics Conference Series · 2023
Abstract The rapidly maturing deep neural networks are used in self-driving cars, facial recognition payment, security, and other aspects, and are crucial to how we conduct our daily lives. However, past research has shown that adversarial attacks pose a significant danger to deep learning. This paper proposes a defense based on digital image processing to protect the handwritten digit recognition model from adversarial attacks. This method can defend against adversarial attacks simply and effectively using spatial filtering and thresholding for image pre-processing to remove adversarial perturbations. The experimental findings on the MNIST data set show that this technique can increase the average accuracy of the model against adversarial samples to 91.20%.