arXiv:2409.19619cs.CVcs.AI2024-09被引 2

提出可区分恶意与偶然噪声的通用检测模型,提升图像安全防御能力。

Discerning the Chaos: Detecting Adversarial Perturbations while Disentangling Intentional from Unintentional Noises

  • 基于改进视觉变换器设计检测网络,结合最大均值差异与中心损失
  • 在多个数据集上对对抗攻击和随机噪声均有超过90%的检测准确率
  • 适合需要高鲁棒性的图像识别系统部署,如人脸识别与身份验证

深度学习模型在人脸属性识别等任务中易受对抗噪声和非故意噪声(如高斯噪声、椒盐噪声)干扰。本文提出CIAI——一种基于改进视觉变换器的类无关对抗意图检测网络,配备专用检测层。CIAI采用结合最大均值差异(MMD)与中心损失(Center Loss)的新损失函数,可不依赖图像类别,同时检测有意(如FGSM、PGD、DeepFool)与无意噪声。模型采用多阶段训练策略,并引入意图分析机制增强安全性。实验在CelebA、CelebA-HQ、LFW、AgeDB和CIFAR-10数据集上验证性能,结果表明其对多种扰动均具有高检测能力。

原文摘要 · Abstract (English)

Deep learning models, such as those used for face recognition and attribute prediction, are susceptible to manipulations like adversarial noise and unintentional noise, including Gaussian and impulse noise. This paper introduces CIAI, a Class-Independent Adversarial Intent detection network built on a modified vision transformer with detection layers. CIAI employs a novel loss function that combines Maximum Mean Discrepancy and Center Loss to detect both intentional (adversarial attacks) and unintentional noise, regardless of the image class. It is trained in a multi-step fashion. We also introduce the aspect of intent during detection that can act as an added layer of security. We further showcase the performance of our proposed detector on CelebA, CelebA-HQ, LFW, AgeDB, and CIFAR-10 datasets. Our detector is able to detect both intentional (like FGSM, PGD, and DeepFool) and unintentional (like Gaussian and Salt & Pepper noises) perturbations.

对抗检测视觉变换器图像安全噪声分类

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。