

연합인증 가입 기관의 연구자들은 소속기관의 인증정보(ID와 암호)를 이용해 다른 대학, 연구기관, 서비스 공급자의 다양한 온라인 자원과 연구 데이터를 이용할 수 있습니다.

이는 여행자가 자국에서 발행 받은 여권으로 세계 각국을 자유롭게 여행할 수 있는 것과 같습니다.

연합인증으로 이용이 가능한 서비스는 NTIS, DataON, Edison, Kafe, Webinar 등이 있습니다.

한번의 인증절차만으로 연합인증 가입 서비스에 추가 로그인 없이 이용이 가능합니다.

다만, 연합인증을 위해서는 최초 1회만 인증 절차가 필요합니다. (회원이 아닐 경우 회원 가입이 필요합니다.)

연합인증 절차는 다음과 같습니다.

ScienceON에 로그인 → 연합인증 서비스 접속 → 로그인 (본인 확인 또는 회원가입) → 서비스 이용

그 이후에는
ScienceON 로그인 → 연합인증 서비스 접속 → 서비스 이용

연합인증을 활용하시면 KISTI가 제공하는 다양한 서비스를 편리하게 이용하실 수 있습니다.

[국내논문] 딥러닝 모델에 대한 적대적 사례 기술 동향 원문보기

情報保護學會誌 = KIISC review, v.31 no.2, 2021년, pp.5 - 12  

권현 (육군사관학교 전자공학과) ,  김용철 (육군사관학교 전자공학과)

AI-Helper 아이콘AI-Helper

이미지 인식, 음성 인식, 텍스트 인식 등에서 딥러닝 모델이 좋은 성능을 보여주고 있다. 하지만 이러한 딥러닝 모델은 적대적 사례에 대하여 취약점을 갖고 있다. 적대적 사례는 원본 데이터에 최적의 노이즈를 추가하여 생성되며 사람이 보기에는 문제가 없지만 딥러닝 모델에 의해서 잘못 오인식되는 데이터를 의미한다. 적대적 사례에 대한 연구는 인공지능 분야와 보안 분야에서 관심을 받고 있으며 이미지, 음성, 텍스트 등으로 다양하게 연구가 진행 되고 있다. 이 연구에서는 적대적 사례에 대한 전반적인 기술 동향에 대해서 살펴보고자 한다.

AI 본문요약
AI-Helper 아이콘 AI-Helper

문제 정의

  • 본 연구에서는 적대적 사례에 관련한 연구내용의 정리와 향후 연구에 대한 내용을 다룬다. 2장에서는 이미지 기반의 적대적 사례에 대한 연구를 소개하고 3장에서는 다양한 도메인에서의 적대적 사례에 대한 연구를 다룬다.
  • 이 연구에서는 적대적 사례의 공격과 방어 그리고 적용할 수 있는 도메인에 대해서 적대적 사례의 기술동향을 살펴보았다. 전반적으로 적대적 공격이 방어에 비해서 좀 더 유리한 특징이 있지만 점차적으로 적대적 사례에 대한 방어기법에 대한 연구 필요성이 강조되고 있다.
본문요약 정보가 도움이 되었나요?

참고문헌 (50)

  1. Liu, Weibo, et al. "A survey of deep neural network architectures and their applications." Neurocomputing 234 (2017): 11-26. 

  2. Parvathy, Velmurugan Subbiah, Sivakumar Pothiraj, and Jenyfal Sampson. "Optimal Deep Neural Network model based multimodality fused medical image classification." Physical Communication 41 (2020): 101119. 

  3. Jahangir, Rashid, et al. "Text-independent speaker identification through feature fusion and deep neural network." IEEE Access 8 (2020): 32187-32202. 

  4. Xue, Mingfu, et al. "Machine learning security: Threats, countermeasures, and evaluations." IEEE Access 8 (2020): 74720-74742. 

  5. Yang, Chaofei, et al. "Generative poisoning attack method against neural networks." arXiv preprint arXiv:1703.01340 (2017). 

  6. Kwon, Hyun, Hyunsoo Yoon, and Ki-Woong Park. "Multi-targeted backdoor: Indentifying backdoor attack for multiple deep neural networks." IEICE Transactions on Information and Systems 103.4 (2020): 883-887. 

  7. Akhtar, Naveed, and Ajmal Mian. "Threat of adversarial attacks on deep learning in computer vision: A survey." Ieee Access 6 (2018): 14410-14430. 

  8. Szegedy, Christian, et al. "Intriguing properties of neural networks." arXiv preprint arXiv:1312.6199 (2013). 

  9. Carlini, Nicholas, et al. "Provably minimally-distorted adversarial examples." arXiv preprint arXiv:1709.10207 (2017). 

  10. Athalye, Anish, and Nicholas Carlini. "On the robustness of the cvpr 2018 white-box adversarial example defenses." arXiv preprint arXiv:1804.03286 (2018). 

  11. Jiang, Linxi, et al. "Black-box adversarial attacks on video recognition models." Proceedings of the 27th ACM International Conference on Multimedia. 2019. 

  12. Zhao, Yuhang, et al. "An Universal Perturbation Generator for Black-Box Attacks Against Object Detectors." International Conference on Smart Computing and Communication. Springer, Cham, 2019. 

  13. Huang, Qian, et al. "Enhancing adversarial example transferability with an intermediate level attack." Proceedings of the IEEE/CVF International Conference on Computer Vision. 2019. 

  14. Kwon, Hyun, et al. "Advanced ensemble adversarial example on unknown deep neural network classifiers." IEICE TRANSACTIONS on Information and Systems 101.10 (2018): 2485-2500. 

  15. Hang, Jie, et al. "Ensemble adversarial black-box attacks against deep learning systems." Pattern Recognition 101 (2020): 107184. 

  16. Papernot, Nicolas, et al. "Practical black-box attacks against machine learning." Proceedings of the 2017 ACM on Asia conference on computer and communications security. 2017. 

  17. Kwon, Hyun, et al. "Multi-targeted adversarial example in evasion attack on deep neural network." IEEE Access 6 (2018): 46084-46096. 

  18. Carlini, Nicholas, and David Wagner. "Audio adversarial examples: Targeted attacks on speech-to-text." 2018 IEEE Security and Privacy Workshops (SPW). IEEE, 2018. 

  19. Wu, Aming, et al. "Untargeted adversarial attack via expanding the semantic gap." 2019 IEEE International Conference on Multimedia and Expo (ICME). IEEE, 2019. 

  20. Kwon, Hyun, et al. "Random untargeted adversarial example on deep neural network." Symmetry 10.12 (2018): 738. 

  21. Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. CoRR, abs/1412.6572, 2014 

  22. Moosavi-Dezfooli, Seyed-Mohsen, Alhussein Fawzi, and Pascal Frossard. "Deepfool: a simple and accurate method to fool deep neural networks." Proceedings of the IEEE conference on computer vision and pattern recognition. 2016. 

  23. Papernot, Nicolas, et al. "The limitations of deep learning in adversarial settings." 2016 IEEE European symposium on security and privacy (EuroS&P). IEEE, 2016. 

  24. Carlini, Nicholas, and David Wagner. "Towards evaluating the robustness of neural networks." 2017 ieee symposium on security and privacy (sp). IEEE, 2017. 

  25. Su, Jiawei, Danilo Vasconcellos Vargas, and Kouichi Sakurai. "One pixel attack for fooling deep neural networks." IEEE Transactions on Evolutionary Computation 23.5 (2019): 828-841. 

  26. He, Warren, Bo Li, and Dawn Song. "Decision boundary analysis of adversarial examples." International Conference on Learning Representations. 2018. 

  27. Athalye, Anish, Nicholas Carlini, and David Wagner. "Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples." International Conference on Machine Learning. PMLR, 2018. 

  28. Tramer, Florian, et al. "On adaptive attacks to adversarial example defenses." arXiv preprint arXiv:2002.08347 (2020). 

  29. Kwon, Hyun, Hyunsoo Yoon, and Ki-Woong Park. "Acoustic-decoy: Detection of adversarial examples through audio modification on speech recognition system." Neurocomputing 417 (2020): 357-370. 

  30. Kwon, Hyun, and Jun Lee. "AdvGuard: Fortifying Deep Neural Networks against Optimized Adversarial Example Attack." IEEE Access (2020). 

  31. Kwon, Hyun, et al. "Classification score approach for detecting adversarial example in deep neural network." Multimedia Tools and Applications (2020): 1-22. 

  32. Liang, Bin, et al. "Detecting adversarial image examples in deep neural networks with adaptive noise reduction." IEEE Transactions on Dependable and Secure Computing (2018). 

  33. Papernot, Nicolas, et al. "Distillation as a defense to adversarial perturbations against deep neural networks." 2016 IEEE symposium on security and privacy (SP). IEEE, 2016. 

  34. Samangouei, Pouya, Maya Kabkab, and Rama Chellappa. "Defense-gan: Protecting classifiers against adversarial attacks using generative models." arXiv preprint arXiv:1805.06605 (2018). 

  35. Meng, Dongyu, and Hao Chen. "Magnet: a two-pronged defense against adversarial examples." Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. 2017. 

  36. Xu, Weilin, David Evans, and Yanjun Qi. "Feature squeezing: Detecting adversarial examples in deep neural networks." arXiv preprint arXiv:1704.01155 (2017). 

  37. Tramer, Florian, et al. "Ensemble adversarial training: Attacks and defenses." arXiv preprint arXiv:1705.07204 (2017). 

  38. Kwon, Hyun, and Jun Lee. "Diversity Adversarial Training against Adversarial Attack on Deep Neural Networks." Symmetry 13.3 (2021): 428. 

  39. Shumailov, Ilia, et al. "Towards certifiable adversarial sample detection." Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security. 2020. 

  40. Carlini, Nicholas, and David Wagner. "Adversarial examples are not easily detected: Bypassing ten detection methods." Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. 2017. 

  41. Kwon, Hyun, et al. "Selective audio adversarial example in evasion attack on speech recognition system." IEEE Transactions on Information Forensics and Security 15 (2019): 526-538. 

  42. Kwon, Hyun, Hyunsoo Yoon, and Ki-Woong Park. "Robust CAPTCHA Image Generation Enhanced with Adversarial Example Methods." IEICE TRANSACTIONS on Information and Systems 103.4 (2020): 879-882. 

  43. Carlini, Nicholas, and David Wagner. "Audio adversarial examples: Targeted attacks on speech-to-text." 2018 IEEE Security and Privacy Workshops (SPW). IEEE, 2018. 

  44. Kwon, Hyun, Hyunsoo Yoon, and Ki-Woong Park. "POSTER: Detecting audio adversarial example through audio modification." Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. 2019. 

  45. Zhang, Guoming, et al. "Dolphinattack: Inaudible voice commands." Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 2017. 

  46. Carlini, Nicholas, et al. "Hidden voice commands." 25th {USENIX} Security Symposium ({USENIX} Security 16). 2016. 

  47. Garg, Siddhant, and Goutham Ramakrishnan. "Bae: Bert-based adversarial examples for text classification." arXiv preprint arXiv:2004.01970 (2020). 

  48. Jin, Di, et al. "Is bert really robust? a strong baseline for natural language attack on text classification and entailment." Proceedings of the AAAI conference on artificial intelligence. Vol. 34. No. 05. 2020. 

  49. Finlayson, Samuel G., et al. "Adversarial attacks against medical deep learning systems." arXiv preprint arXiv:1804.05296 (2018). 

  50. Ozbulak, Utku, Arnout Van Messem, and Wesley De Neve. "Impact of adversarial examples on deep learning models for biomedical image segmentation." International Conference on Medical Image Computing and Computer-Assisted Intervention. Springer, Cham, 2019. 

저자의 다른 논문 :

관련 콘텐츠

저작권 관리 안내
섹션별 컨텐츠 바로가기

AI-Helper ※ AI-Helper는 오픈소스 모델을 사용합니다.

AI-Helper 아이콘
안녕하세요, AI-Helper입니다. 좌측 "선택된 텍스트"에서 텍스트를 선택하여 요약, 번역, 용어설명을 실행하세요.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.

선택된 텍스트
