Netinfo Security ›› 2019, Vol. 19 ›› Issue (9): 66-70.doi: 10.3969/j.issn.1671-1122.2019.09.014

• Orginal Article • Previous Articles     Next Articles

Research on Defense Technology of Adversarial Attacks Based on Adversarial Training and VAE-repairing

Min GUO, Yingming ZENG, Ran YU, Zhaoxiong WU   

  1. Beijing Institute of Computer Technology and Applications, Beijing 100854, China
  • Received:2019-07-15 Online:2019-09-10 Published:2020-05-11

Abstract:

The artificial intelligence system is facing the threat of adversarial attacks from the physical world. The artificial intelligence algorithm is very sensitive to the attacks. Taking the target recognition as an example, the attacker adds a very small disturbance to the sample data, then the target recognition accuracy reduces or even the result of recognition can be targeted induced. How to effectively resist the threat of adversarial examples has become a research hotspot in the industry. This paper focuses on the security reinforcement model based on stochastic adversarial training and the adversarial examples repair technology based on variational self-encoder. The pre-active reinforcement and after-active repair are carried out in response to the adversarial attacks, combined with the concept of “active + passive”, which achieves the security enhancement of artificial intelligence algorithm, and ensures that artificial intelligence technology can be applied safely and reliably.

Key words: artificial intelligence, security enhancement, adversarial training, adversarial perturbations clearance

CLC Number: