Adversarial Attacks Against Deep Generative Models on Data: A Survey
arXiv:2112.00247 · doi:10.1109/TKDE.2021.3130903
Abstract
Deep generative models have gained much attention given their ability to generate data for applications as varied as healthcare to financial technology to surveillance, and many more - the most popular models being generative adversarial networks and variational auto-encoders. Yet, as with all machine learning models, ever is the concern over security breaches and privacy leaks and deep generative models are no exception. These models have advanced so rapidly in recent years that work on their security is still in its infancy. In an attempt to audit the current and future threats against these models, and to provide a roadmap for defense preparations in the short term, we prepared this comprehensive and specialized survey on the security and privacy preservation of GANs and VAEs. Our focus is on the inner connection between attacks and model architectures and, more specifically, on five components of deep generative models: the training data, the latent code, the generators/decoders of GANs/ VAEs, the discriminators/encoders of GANs/ VAEs, and the generated data. For each model, component and attack, we review the current research progress and identify the key challenges. The paper concludes with a discussion of possible future attacks and research directions in the field.
To be published in IEEE Transactions on Knowledge and Data Engineering
References in corpus (19)
- Conditional Generative Adversarial Nets
- Explaining and Harnessing Adversarial Examples
- The Effectiveness of Data Augmentation in Image Classification using Deep Learning
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Evasion Attacks against Machine Learning at Test Time
- Generating Videos with Scene Dynamics
- Poisoning Attacks against Support Vector Machines
- Towards the Science of Security and Privacy in Machine Learning
- More Than Privacy: Applying Differential Privacy in Key Areas of Artificial Intelligence
- Generative Poisoning Attack Method Against Neural Networks
- When Machine Learning Meets Privacy: A Survey and Outlook
- Adversarial Images for Variational Autoencoders
- FedGAN: Federated Generative Adversarial Networks for Distributed Data
- Object Hider: Adversarial Patch Attack Against Object Detectors
- Training Federated GANs with Theoretical Guarantees: A Universal Aggregation Approach
- Federated AI lets a team imagine together: Federated Learning of GANs
- Model Extraction and Defenses on Generative Adversarial Networks
- Double Backpropagation for Training Autoencoders against Adversarial Attack
- Protecting Intellectual Property of Generative Adversarial Networks from Ambiguity Attack