Back to Search Start Over

Dual-Domain-Based Adversarial Defense With Conditional VAE and Bayesian Network

Authors :
Guohao Peng
Danwei Wang
Jinlin Zhu
Source :
IEEE Transactions on Industrial Informatics. 17:596-605
Publication Year :
2021
Publisher :
Institute of Electrical and Electronics Engineers (IEEE), 2021.

Abstract

Adversarial examples can be imperceptible to human eyes but can easily fool deep models. Such intrigue property has raised security issues for real-world industrial deep learning systems. To combat those malicious attacks, a novel defense strategy has been proposed based on the conditional variational autoencoder (CVAE) and Bayesian network (BN). The main contribution lies in the provided systematic dual-domain-based defense framework, which covers three modules named detection, diagnosis, and recovery. Specifically, the CVAE is first introduced for latent- and residual-domain generation. Subsequently, a composite and hierarchical BN detector is proposed to conduct the adversary detection through feature validation and output justification. Afterwards, a diagnosis strategy has been constructed for residual domain and different attacks can be evaluated in the unified framework. Finally, a two-step recovery mechanism is established on the CVAE that can effectively restore the feature representations and the network predictions from various adversaries. The feasibility of the entire defense diagram has been extensively demonstrated on three real-world recognition problems.

Details

ISSN :
19410050 and 15513203
Volume :
17
Database :
OpenAIRE
Journal :
IEEE Transactions on Industrial Informatics
Accession number :
edsair.doi...........d60d7c53402506560ae68aa0bb93b2fc
Full Text :
https://doi.org/10.1109/tii.2020.2964154