| 本文已被:浏览 3160次 下载 6090次 |
 码上扫一扫! |
|
|
| 图像对抗样本检测综述 |
|
周涛1,2, 甘燃1,2, 徐东伟1,2, 王竟亦3, 宣琦1,2
|
|
1.浙江工业大学 网络空间安全研究院, 浙江 杭州 310023;2.浙江工业大学 信息工程学院, 浙江 杭州 310023;3.浙江大学 控制科学与工程学院, 浙江 杭州 310058
|
|
| 摘要: |
| 深度神经网络是人工智能领域的一项重要技术, 它被广泛应用于各种图像分类任务. 但是, 现有的研究表明深度神经网络存在安全漏洞, 容易受到对抗样本的攻击, 而目前并没有研究针对图像对抗样本检测进行体系化分析. 为了提高深度神经网络的安全性, 针对现有的研究工作, 全面地介绍图像分类领域的对抗样本检测方法. 首先根据检测器的构建方式将检测方法分为有监督检测与无监督检测, 然后根据其检测原理进行子类划分. 最后总结对抗样本检测领域存在的问题, 在泛化性和轻量化等方面提出建议与展望, 旨在为人工智能安全研究提供帮助. |
| 关键词: 深度神经网络 对抗样本检测 人工智能安全 图像分类 |
| DOI:10.13328/j.cnki.jos.006834 |
| 分类号: |
| 基金项目:浙江省重点研发计划(2022C01018); 国家自然科学基金(U21B2001, 62102359) |
|
| Survey on Adversarial Example Detection of Images |
|
ZHOU Tao1,2, GAN Ran1,2, XU Dong-Wei1,2, WANG Jing-Yi3, XUAN Qi1,2
|
|
1.Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China;2.College of Information Engineering, Zhejiang University of Technology, Hangzhou 310023, China;3.College of Control Science and Engineering, Zhejiang University, Hangzhou 310058, China
|
| Abstract: |
| As an important technology in the field of artificial intelligence (AI), deep neural networks are widely used in various image classification tasks. However, existing studies have shown that deep neural networks have security vulnerabilities and are vulnerable to adversarial examples. At present, there is no research on the systematic analysis of adversarial example detection of images. To improve the security of deep neural networks, this study, based on the existing research work, comprehensively introduces adversarial example detection methods in the field of image classification. First, the detection methods are divided into supervised detection and unsupervised detection by the construction method of the detector, which are then classified into subclasses according to detection principles. Finally, the study summarizes the problems in adversarial example detection and provides suggestions and an outlook in terms of generalization and lightweight, aiming to assist in AI security research. |
| Key words: deep neural network (DNN) adversarial example detection AI security image classification |