Defending from physically-realizable adversarial attacks through internal over-activation analysis

Brau F.;
2023-01-01

Abstract

This work presents Z-Mask, an effective and deterministic strategy to improve the adversarial robustness of convolutional networks against physically-realizable adversarial attacks. The presented defense relies on specific Z-score analysis performed on the internal network features to detect and mask the pixels corresponding to adversarial objects in the input image. To this end, spatially contiguous activations are examined in shallow and deep layers to suggest potential adversarial regions. Such proposals are then aggregated through a multi-thresholding mechanism. The effectiveness of Z-Mask is evaluated with an extensive set of experiments carried out on models for semantic segmentation and object detection. The evaluation is performed with both digital patches added to the input images and printed patches in the real world. The results confirm that Z-Mask outperforms the state-of-the-art methods in terms of detection accuracy and overall performance of the networks under attack. Furthermore, Z-Mask preserves its robustness against defense-aware attacks, making it suitable for safe and secure AI applications.
2023
Inglese
Proceedings of the 37th AAAI Conference on Artificial Intelligence, AAAI 2023
978-1-57735-880-0
AAAI Press
Washington, DC
STATI UNITI D'AMERICA
37
15064
15072
9
https://ojs.aaai.org/index.php/AAAI/article/view/26758
37th AAAI Conference on Artificial Intelligence, AAAI 2023
Esperti anonimi
2023
Washington, DC, USA
scientifica
Artificial intelligence; Chemical activation; Network security; Object detection; Semantic Segmentation; Semantics; Convolutional networks; Deep layer; Deterministics; Input image; Internal network; Network features; Semantic segmentation; Shallowest layers; Thresholding; Z-score analysis; Activation analysis
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Rossolini, G.; Nesti, F.; Brau, F.; Biondi, A.; Buttazzo, G.
273
5
4.1 Contributo in Atti di convegno
reserved
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
26758-Article Text-30821-1-2-20230626 (1).pdf

Solo gestori archivio

Type: versione editoriale
Size 9.43 MB
Format Adobe PDF
9.43 MB Adobe PDF & nbsp; View / Open   Request a copy

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie