vix.ing · top · new · best · stats · spec

MTDeep: Boosting the Security of Deep Neural Nets Against Adversarial\n Attacks with Moving Target Defense

2017/05/19 by Sailik Sengupta, Sengupta, Sailik, Tathagata Chakraborti +3 · 1 citation
Biochemistry, Genetics and Molecular Biology · Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Bacillus and Francisella bacterial research #Computer Science and Game Theory (cs.GT) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG)

paper · pdf · doi:10.48550/arxiv.1705.07213

openalex publication_date 2017/05/19 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Present attack methods can make state-of-the-art classification systems based\non deep neural networks misclassify every adversarially modified test example.\nThe design of general defense strategies against a wide range of such attacks\nstill remains a challenging problem. In this paper, we draw inspiration from\nthe fields of cybersecurity and multi-agent systems and propose to leverage the\nconcept of Moving Target Defense (MTD) in designing a meta-defense for\n'boosting' the robustness of an ensemble of deep neural networks (DNNs) for\nvisual classification tasks against such adversarial attacks. To classify an\ninput image, a trained network is picked randomly from this set of networks by\nformulating the interaction between a Defender (who hosts the classification\nnetworks) and their (Legitimate and Malicious) users as a Bayesian Stackelberg\nGame (BSG). We empirically show that this approach, MTDeep, reduces\nmisclassification on perturbed images in various datasets such as MNIST,\nFashionMNIST, and ImageNet while maintaining high classification accuracy on\nlegitimate test images. We then demonstrate that our framework, being the first\nmeta-defense technique, can be used in conjunction with any existing defense\nmechanism to provide more resilience against adversarial attacks that can be\nafforded by these defense mechanisms. Lastly, to quantify the increase in\nrobustness of an ensemble-based classification system when we use MTDeep, we\nanalyze the properties of a set of DNNs and introduce the concept of\ndifferential immunity that formalizes the notion of attack transferability.\n

Cited by

Related