vix.ing · top · new · best · stats · spec

When Not to Classify: Detection of Reverse Engineering Attacks on DNN Image Classifiers

2018/10/31 by Yujia Wang, Wang, Yujia, David J. Miller +3
Biochemistry, Genetics and Molecular Biology · Computer Science · Engineering · #Adversarial Robustness in Machine Learning #Bacillus and Francisella bacterial research #Computer Vision and Pattern Recognition (cs.CV) #FOS: Computer and information sciences #Integrated Circuits and Semiconductor Failure Analysis #Machine Learning (cs.LG) #Machine Learning (stat.ML)

paper · pdf · doi:10.48550/arxiv.1811.02658

openalex publication_date 2018/10/31 · openalex created_date 2018/11/16 · openalex updated_date 2026/07/28

Abstract

This paper addresses detection of a reverse engineering (RE) attack targeting a deep neural network (DNN) image classifier; by querying, RE's aim is to discover the classifier's decision rule. RE can enable test-time evasion attacks, which require knowledge of the classifier. Recently, we proposed a quite effective approach (ADA) to detect test-time evasion attacks. In this paper, we extend ADA to detect RE attacks (ADA-RE). We demonstrate our method is successful in detecting "stealthy" RE attacks before they learn enough to launch effective test-time evasion attacks.

Related