Defend against adversarial samples by using perceptual hash

9Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Image classifiers that based on Deep Neural Networks (DNNs) have been proved to be easily fooled by well-designed perturbations. Previous defense methods have the limitations of requiring expensive computation or reducing the accuracy of the image classifiers. In this paper, we propose a novel defense method which based on perceptual hash. Our main goal is to destroy the process of perturbations generation by comparing the similarities of images thus achieve the purpose of defense. To verify our idea, we defended against two main attack methods (a white-box attack and a black-box attack) in different DNN-based image classifiers and show that, after using our defense method, the attack-success-rate for all DNN-based image classifiers decreases significantly. More specifically, for the white-box attack, the attack-success-rate is reduced by an average of 36.3%. For the black-box attack, the average attack-success-rate of targeted attack and non-targeted attack has been reduced by 72.8% and 76.7% respectively. The proposed method is a simple and effective defense method and provides a new way to defend against adversarial samples.

Cite

CITATION STYLE

APA

Liu, C., Ye, D., Shang, Y., Jiang, S., Li, S., Mei, Y., & Wang, L. (2020). Defend against adversarial samples by using perceptual hash. Computers, Materials and Continua, 62(3), 1365–1386. https://doi.org/10.32604/cmc.2020.07421

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free