Adversarial Attacks and Defenses in Deep Neural Networks

Sunil Anasuri · International Journal of Artificial Intelligence Data Science and Machine Learning · 2022

The Deep Neural Networks (DNNs) have transformed a lot of fields such as computer vision, speech recognition, and natural language processing. Nevertheless, they are notoriously susceptible to adversarial attacks malicious inputs that can trick DNNs into giving wrong predictions that are imperceptibly wrong to a human observer. This weakness is of major concern, particularly in safety-sensitive exertions, like autonomous driving, medical diagnosis, and biometric verification. Today, this paper will discuss the adversarial attack ground and related defense mechanisms . An overview of adversarial attacks The overview of adversarial attacks covers why adversarial attacks? which includes, white-box attack, black-box attack, and transfer-based attack with their respective mechanisms composed of Fast Gradient Sign Method (FGSM), Projected Gradient Descent (PGD), Carlini-Wagner (CW), and DeepFool mechanisms. Subsequently, we observe the scope of defenses adversarial training, defensive distillation, input preprocessing, gradient masking. A comprehensive literature review presents historical evolutions and achievements in both attack generation and policies of mitigation. Methodology In the methodology section, an approach to testing adversarial robustness is presented with a standardized framework in terms of reproducibility and benchmark datasets like MNIST, CIFAR-10, ImageNet. We provide the outcomes of the comparative experiments in diverse threat models as well as implications of the research. Lastly, the paper gives a glimpse of the future of adversarial research and the importance of adaptable, strong, and interpretable models. The knowledge generated through our contribution synthesizes the preexisting ones and provides a basis on which strict and safe DNN systems can be developed

Read the paper · More papers on PaperTik