错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A composite manifold learning approach with traditional methods for gradient-based and patch-based adversarial attack detection

  • Khushabu Agrawal,
  • Charul Bhatnagar

摘要

Face recognition models that utilize deep learning techniques can be easily targeted by adversarial attacks. In order to detect these attacks, the majority of detection methods focus on enhancing the resilience of recognition models against adversarial perturbations. Nevertheless, these methods have limited capabilities in terms of generalization. Consequently, they remain susceptible to adversarial attacks that have not been previously encountered. On the other hand, deep learning models exhibit considerable robustness against typical perturbations. In the paper, we have proposed a composite manifold learning approach with traditional techniques(CMLAT) detector to detect gradient-based and patch-based adversarial attack detection. The geometrical representation differs from the original input images, thus, we introduce a feature-based embedding that relies on measuring geodesic distances using the isomap manifold learning. This embedding enables us to encode the dissimilarities between adversarial and genuine inputs efficiently. Our training involves a support vector machine classifier that examines the sequence of deep features represented in a distance-based space to identify and classify adversarial images. We have achieved a significant milestone by developing an adversarial face detection system that exclusively utilizes original faces and their adversarial faces and can effectively handle previously unseen attack techniques. The experiment has been conducted on the Labeled Faces in the Wild (LFW) dataset with four gradient-based and patch-based attacks. This experiment confirms that the CMLAT detector is effective and generalizes against various adversarial attacks that were not previously encountered.