Friend-safe evasion attack: An adversarial example that is correctly recognized by a friendly classifier. Issue 78 (September 2018)
- Record Type:
- Journal Article
- Title:
- Friend-safe evasion attack: An adversarial example that is correctly recognized by a friendly classifier. Issue 78 (September 2018)
- Main Title:
- Friend-safe evasion attack: An adversarial example that is correctly recognized by a friendly classifier
- Authors:
- Kwon, Hyun
Kim, Yongchul
Park, Ki-Woong
Yoon, Hyunsoo
Choi, Daeseon - Abstract:
- Abstract: Deep neural networks (DNNs) have been applied in several useful services, such as image recognition, intrusion detection, and pattern analysis of machine learning tasks. Recently proposed adversarial examples-slightly modified data that lead to incorrect classification-are a severe threat to the security of DNNs. In some situations, however, an adversarial example might be useful, such as when deceiving an enemy classifier on the battlefield. In such a scenario, it is necessary that a friendly classifier not be deceived. In this paper, we propose a friend-safe adversarial example, meaning that the friendly machine can classify the adversarial example correctly. To produce such examples, a transformation is carried out to minimize the probability of incorrect classification by the friend and that of correct classification by the adversary. We suggest two configurations for the scheme: targeted and untargeted class attacks. We performed experiments with this scheme using the MNIST and CIFAR10 datasets. Our proposed method shows a 100% attack success rate and 100% friend accuracy with only a small distortion: 2.18 and 1.54 for the two respective MNIST configurations, and 49.02 and 27.61 for the two respective CIFAR10 configurations. Additionally, we propose a new covert channel scheme and a mixed battlefield application for consideration in further applications.
- Is Part Of:
- Computers & security. Issue 78(2018)
- Journal:
- Computers & security
- Issue:
- Issue 78(2018)
- Issue Display:
- Volume 78, Issue 78 (2018)
- Year:
- 2018
- Volume:
- 78
- Issue:
- 78
- Issue Sort Value:
- 2018-0078-0078-0000
- Page Start:
- 380
- Page End:
- 397
- Publication Date:
- 2018-09
- Subjects:
- Deep Neural Network -- Evasion Attack -- Adversarial Example -- Covert Channel -- Machine Learning
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2018.07.015 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 10941.xml