| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Primerjava metod napada na globoke nevronske mreže z nasprotniškimi primeri in pristopov k zaščiti pred njimi : magistrsko delo
Authors:ID Novak, Robi (Author)
ID Strnad, Damjan (Mentor) More about this mentor... New window
ID Kohek, Štefan (Comentor)
Files:.pdf MAG_Novak_Robi_2022.pdf (45,09 MB)
MD5: 28C564F58929C619AB04F9248269DE43
PID: 20.500.12556/dkum/18fb69ad-f246-4f6c-ab25-74d37deb8427
 
.zip MAG_Novak_Robi_2022.zip (65,17 KB)
MD5: 6458198C3B151733A1B0D41545B0815D
PID: 20.500.12556/dkum/bc3554d7-9a44-4d7d-a231-477d4932cab3
 
Language:Slovenian
Work type:Master's thesis/paper
Typology:2.09 - Master's Thesis
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:Globoke nevronske mreže imajo ranljivosti, kot so nasprotniški primeri - neopazne namerne popačitve vhodnih podatkov, ki povzročijo neželeno spremembo izhoda. Ker so nasprotniški primeri prenosljivi, lahko popačitev tvorimo v scenariju črne škatle, brez da bi poznali strukturo ali uteži napadene mreže. V našem delu primerjamo več pristopov k napadu in zaščiti. Robustnost modela ovrednotimo glede na prepričanost v napačno klasifikacijo ter glede na statistično porazdelitev amplitud nasprotniških popačitev. Rezultati kažejo, da so amplitude uspešnih napadov tipično za en velikostni razred višje, če je napad izveden po scenariju črne škatle. Robustnost modela je odvisna od klasifikacijskega problema, arhitekture mreže ter pristopa k zaščiti. Za najbolj učinkovita napada sta se v scenariju bele škatle izkazala napada BIM in MI-FGSM, v scenariju črne škatle pa napada MI-FGSM in FGSM. Najučinkovitejša pristopa k zaščiti sta bila diskretizacija ter virtualno nasprotniško učenje. Pokazali smo tudi, da moramo za verodostojen preizkus učinkovitosti nasprotniškega učenja uporabiti napad, ki ni bil uporabljen v procesu učenja.
Keywords:globoko učenje, nasprotniški primeri, nevronske mreže, strojno učenje
Place of publishing:Maribor
Place of performance:Maribor
Publisher:[R. Novak]
Year of publishing:2022
Number of pages:1 spletni vir (1 datoteka PDF (XI, 76 f.))
PID:20.500.12556/DKUM-81921 New window
UDC:004.85:004.032.26(043.2)
COBISS.SI-ID:116049411 New window
Publication date in DKUM:06.07.2022
Views:1087
Downloads:194
Metadata:XML DC-XML DC-RDF
Categories:KTFMB - FERI
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:18.06.2022

Secondary language

Language:English
Title:Comparing adversarial example attacks on deep neural networks and defensive approaches
Abstract:Deep neural networks suffer from unique vulnerabilities, such as adversarial examples - unobservable perturbations of input data that cause an unwanted change of the output. Adversarial examples are transferrable, which allows us to form an adversarial perturbation in the black-box scenario, without knowing the structure or weights of the attacked network. In our work, we compare various attacks and defensive approaches. We evaluate model robustness based on its confidence in the incorrect classification and the statistical distribution of adversarial perturbation amplitudes. Experiments show an order of magnitude increase in perturbation amplitudes when the black-box scenario is used. Model robustness varies depending on the classification problem, network architecture and defensive approach. According to our results, BIM and MI-FGSM are the most effective attacks in the white-box scenario, and MI-FGSM and FGSM in the black-box scenario. The most effective defenses were discretization and virtual adversarial training. Additionally, we have shown that a valid test of adversarial training requires the use of an attack that was not used during training.
Keywords:deep learning, adversarial examples, neural networks, machine learning


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica