Approach to Detecting Attacks against Machine Learning Systems with a Generative Adversarial Network
摘要
Abstract
Attacks on machine learning systems are increasingly becoming a factor reducing the effectiveness of these systems and compromising their safety. This work assesses existing attacks on machine learning systems and identifies classes of attacks that are especially relevant and dangerous for these systems. Based on an analysis of potential countermeasures against attacks on machine learning systems, a new approach to protecting these systems is proposed, based on the simultaneous use of Neural Cleanse technology, JPEG compression technology, and a generative adversarial network. An experimental evaluation of the proposed approach, made on the basis of a data set with road signs, showed its fairly high efficiency.