针对边缘神经网络推理中的隐蔽误分类攻击,提出噪声感知检测方法。
Noise-Aware Misclassification Attack Detection in Collaborative DNN Inference
- 用变分自编码器捕捉对抗干扰引起的异常特征
- 在真实噪声环境下实现最高90%的检测准确率(AUROC)
- 适合关注边缘AI安全、对抗攻击防御的研究者
协同式目标分类深度神经网络(DNN)通过将部分处理数据卸载至远程边缘服务器完成端到端推理,正成为边缘AI的关键技术。然而,这种边缘卸载易受恶意数据注入攻击,导致难以察觉的隐蔽误分类,尤其在环境噪声存在时更难检测。本文提出一种半灰箱、噪声感知的异常检测框架,基于变分自编码器(VAE)捕捉由对抗操纵引发的偏差。该框架引入鲁棒的噪声感知特征,表征环境噪声的典型行为,从而提升检测精度并降低误报率。在多个主流物体分类DNN上的评估表明,该方法在真实噪声条件下具有优异鲁棒性,不同DNN配置下最高达90% AUROC;但当特征相似性高或噪声水平过高时仍存在局限。
原文摘要 · Abstract (English)
Collaborative inference of object classification Deep neural Networks (DNNs) where resource-constrained end-devices offload partially processed data to remote edge servers to complete end-to-end processing, is becoming a key enabler of edge-AI. However, such edge-offloading is vulnerable to malicious data injections leading to stealthy misclassifications that are tricky to detect, especially in the presence of environmental noise. In this paper, we propose a semi-gray-box and noise- aware anomaly detection framework fueled by a variational autoencoder (VAE) to capture deviations caused by adversarial manipulation. The proposed framework incorporates a robust noise-aware feature that captures the characteristic behavior of environmental noise to improve detection accuracy while reducing false alarm rates. Our evaluation with popular object classification DNNs demonstrate the robustness of the proposed detection (up to 90% AUROC across DNN configurations) under realistic noisy conditions while revealing limitations caused by feature similarity and elevated noise levels.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。