Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective
arXiv:2009.03728 · doi:10.1145/3485133
Abstract
Deep Learning algorithms have achieved the state-of-the-art performance for Image Classification and have been used even in security-critical applications, such as biometric recognition systems and self-driving cars. However, recent works have shown those algorithms, which can even surpass the human capabilities, are vulnerable to adversarial examples. In Computer Vision, adversarial examples are images containing subtle perturbations generated by malicious optimization algorithms in order to fool classifiers. As an attempt to mitigate these vulnerabilities, numerous countermeasures have been constantly proposed in literature. Nevertheless, devising an efficient defense mechanism has proven to be a difficult task, since many approaches have already shown to be ineffective to adaptive attackers. Thus, this self-containing paper aims to provide all readerships with a review of the latest research progress on Adversarial Machine Learning in Image Classification, however with a defender's perspective. Here, novel taxonomies for categorizing adversarial attacks and defenses are introduced and discussions about the existence of adversarial examples are provided. Further, in contrast to exisiting surveys, it is also given relevant guidance that should be taken into consideration by researchers when devising and evaluating defenses. Finally, based on the reviewed literature, it is discussed some promising paths for future research.
References in corpus (26)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Deep Learning in Neural Networks: An Overview
- Distilling the Knowledge in a Neural Network
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Evasion Attacks against Machine Learning at Test Time
- Delving into Transferable Adversarial Examples and Black-box Attacks
- On Evaluating Adversarial Robustness
- The Space of Transferable Adversarial Examples
- Countering Adversarial Images using Input Transformations
- Spatially Transformed Adversarial Examples
- Adversarial Transformation Networks: Learning to Generate Adversarial Examples
- On Detecting Adversarial Perturbations
- Houdini: Fooling Deep Structured Prediction Models
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- Early Methods for Detecting Adversarial Images
- UPSET and ANGRI : Breaking High Performance Image Classifiers
- Neural SDE: Stabilizing Neural ODE Networks with Stochastic Noise
- APE-GAN: Adversarial Perturbation Elimination with GAN
- POBA-GA: Perturbation Optimized Black-Box Adversarial Attacks via Genetic Algorithm
- ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation
- Adversarial Examples in Modern Machine Learning: A Review
- Defensive Quantization: When Efficiency Meets Robustness
- Adversarial Neural Network Inversion via Auxiliary Knowledge Alignment
- Robustness to Adversarial Examples through an Ensemble of Specialists
- ReabsNet: Detecting and Revising Adversarial Examples
- Adversarial Robustness of Stabilized NeuralODEs Might be from Obfuscated Gradients
Cited by in corpus (7)
- Adversarial attacks and defenses in explainable artificial intelligence: A survey
- Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art
- Tarallo: Evading Behavioral Malware Detectors in the Problem Space
- EnTri: Ensemble Learning with Tri-level Representations for Explainable Scene Recognition
- Sticky Fingers: Resilience of Satellite Fingerprinting against Jamming Attacks
- Guiding the retraining of convolutional neural networks against adversarial inputs
- DDSA: Dual-Domain Strategic Attack for Spatial-Temporal Efficiency in Adversarial Robustness Testing