SlideShare a Scribd company logo
Mitigating Evasion Attacks to Deep Neural
Networks via Region-based Classification
Xiaoyu Cao, Neil Zhenqiang Gong
1
Security is a Big Challenge for Deploying
Deep Neural Networks
2
• Evasion Attacks
• Perturbation is added to the input at test time to fool the classifiers.
* Image from Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. ICLR 2015.
Existing Defenses
3
• New methods to train neural networks
• Sacrifice classification accuracy on benign examples.
• Detecting adversarial examples
• Need human to manually process the detected adversarial
examples. No benefit of automatic decision makings.
Understanding Adversarial Examples
4
𝑅𝑖
𝑅𝑡
Classification
boundary of true
class 𝒊 and target
class 𝒕
Design Region-based Classification
5
Input Output
5
… …
0
5
…
0
0
Ensemble
Experimental Results
6
TABLE : Classification accuracy on benign examples and robustness to targeted
CW attacks on (𝑎)MNIST dataset (𝑏) CIFAR-10 dataset.
(𝑎)
(𝑏)

More Related Content

PDF
Battista Biggio @ S+SSPR2014, Joensuu, Finland -- Poisoning Complete-Linkage ...
PDF
Adversarial ML - Part 2.pdf
PDF
CEHS 2016 Poster
PDF
Dnasec
PDF
Adversarial ML - Part 1.pdf
PDF
The DETER Project: Advancing the Science of Cyber Security Experimentation an...
PDF
Battista Biggio @ AISec 2013 - Is Data Clustering in Adversarial Settings Sec...
PDF
The DETER Project: Towards Structural Advances in Experimental Cybersecurity ...
Battista Biggio @ S+SSPR2014, Joensuu, Finland -- Poisoning Complete-Linkage ...
Adversarial ML - Part 2.pdf
CEHS 2016 Poster
Dnasec
Adversarial ML - Part 1.pdf
The DETER Project: Advancing the Science of Cyber Security Experimentation an...
Battista Biggio @ AISec 2013 - Is Data Clustering in Adversarial Settings Sec...
The DETER Project: Towards Structural Advances in Experimental Cybersecurity ...

Similar to 2019 Triangle Machine Learning Day - Mitigating Evasion Attacks to Deep Neural Networks via Region-based Classification - Xiaoyu Cao, September 20, 2019 (20)

PPTX
Tricking a DNN with adversarial examples
PDF
Research of adversarial example on a deep neural network
PDF
Detecting adversarials examples attacks to deep neural networks
PDF
Robustness of Deep Neural Networks on White-box Attacks and Defense Strategie...
PPTX
Defending deep learning from adversarial attacks
PPTX
Adversarial robustness using clever hans
PDF
Universal Adversarial Perturbation
PPTX
A Survey on Security and Privacy of Machine Learning
PDF
DEF CON 24 - Clarence Chio - machine duping 101
PPTX
slides_security_and_privacy_in_machine_learning.pptx
PPTX
Fast Gradient Sign Method (FGSM)___.pptx
PDF
Security of Machine Learning
PDF
005 20151130 adversary_networks
PDF
Immunizing Image Classifiers Against Localized Adversary Attacks
PDF
Immunizing Image Classifiers Against Localized Adversary Attacks
PDF
Adversarial examples in deep learning (Gregory Chatel)
PDF
Security and Privacy of Machine Learning
PDF
Generative Adversarial Networks (GANs) at the Data Science Meetup Luxembourg ...
PDF
Ensembles of Many Diverse Weak Defenses can be Strong: Defending Deep Neural ...
PDF
BOOSTING ADVERSARIAL ATTACKS WITH MOMENTUM - Tianyu Pang and Chao Du, THU - D...
Tricking a DNN with adversarial examples
Research of adversarial example on a deep neural network
Detecting adversarials examples attacks to deep neural networks
Robustness of Deep Neural Networks on White-box Attacks and Defense Strategie...
Defending deep learning from adversarial attacks
Adversarial robustness using clever hans
Universal Adversarial Perturbation
A Survey on Security and Privacy of Machine Learning
DEF CON 24 - Clarence Chio - machine duping 101
slides_security_and_privacy_in_machine_learning.pptx
Fast Gradient Sign Method (FGSM)___.pptx
Security of Machine Learning
005 20151130 adversary_networks
Immunizing Image Classifiers Against Localized Adversary Attacks
Immunizing Image Classifiers Against Localized Adversary Attacks
Adversarial examples in deep learning (Gregory Chatel)
Security and Privacy of Machine Learning
Generative Adversarial Networks (GANs) at the Data Science Meetup Luxembourg ...
Ensembles of Many Diverse Weak Defenses can be Strong: Defending Deep Neural ...
BOOSTING ADVERSARIAL ATTACKS WITH MOMENTUM - Tianyu Pang and Chao Du, THU - D...
Ad

More from The Statistical and Applied Mathematical Sciences Institute (20)

PDF
Causal Inference Opening Workshop - Latent Variable Models, Causal Inference,...
PDF
2019 Fall Series: Special Guest Lecture - 0-1 Phase Transitions in High Dimen...
PDF
Causal Inference Opening Workshop - Causal Discovery in Neuroimaging Data - F...
PDF
Causal Inference Opening Workshop - Smooth Extensions to BART for Heterogeneo...
PDF
Causal Inference Opening Workshop - A Bracketing Relationship between Differe...
PDF
Causal Inference Opening Workshop - Testing Weak Nulls in Matched Observation...
PPTX
Causal Inference Opening Workshop - Difference-in-differences: more than meet...
PDF
Causal Inference Opening Workshop - New Statistical Learning Methods for Esti...
PDF
Causal Inference Opening Workshop - Bipartite Causal Inference with Interfere...
PPTX
Causal Inference Opening Workshop - Bridging the Gap Between Causal Literatur...
PDF
Causal Inference Opening Workshop - Some Applications of Reinforcement Learni...
PDF
Causal Inference Opening Workshop - Bracketing Bounds for Differences-in-Diff...
PDF
Causal Inference Opening Workshop - Assisting the Impact of State Polcies: Br...
PDF
Causal Inference Opening Workshop - Experimenting in Equilibrium - Stefan Wag...
PDF
Causal Inference Opening Workshop - Targeted Learning for Causal Inference Ba...
PDF
Causal Inference Opening Workshop - Bayesian Nonparametric Models for Treatme...
PPTX
2019 Fall Series: Special Guest Lecture - Adversarial Risk Analysis of the Ge...
PPTX
2019 Fall Series: Professional Development, Writing Academic Papers…What Work...
PDF
2019 GDRR: Blockchain Data Analytics - Machine Learning in/for Blockchain: Fu...
PDF
2019 GDRR: Blockchain Data Analytics - QuTrack: Model Life Cycle Management f...
Causal Inference Opening Workshop - Latent Variable Models, Causal Inference,...
2019 Fall Series: Special Guest Lecture - 0-1 Phase Transitions in High Dimen...
Causal Inference Opening Workshop - Causal Discovery in Neuroimaging Data - F...
Causal Inference Opening Workshop - Smooth Extensions to BART for Heterogeneo...
Causal Inference Opening Workshop - A Bracketing Relationship between Differe...
Causal Inference Opening Workshop - Testing Weak Nulls in Matched Observation...
Causal Inference Opening Workshop - Difference-in-differences: more than meet...
Causal Inference Opening Workshop - New Statistical Learning Methods for Esti...
Causal Inference Opening Workshop - Bipartite Causal Inference with Interfere...
Causal Inference Opening Workshop - Bridging the Gap Between Causal Literatur...
Causal Inference Opening Workshop - Some Applications of Reinforcement Learni...
Causal Inference Opening Workshop - Bracketing Bounds for Differences-in-Diff...
Causal Inference Opening Workshop - Assisting the Impact of State Polcies: Br...
Causal Inference Opening Workshop - Experimenting in Equilibrium - Stefan Wag...
Causal Inference Opening Workshop - Targeted Learning for Causal Inference Ba...
Causal Inference Opening Workshop - Bayesian Nonparametric Models for Treatme...
2019 Fall Series: Special Guest Lecture - Adversarial Risk Analysis of the Ge...
2019 Fall Series: Professional Development, Writing Academic Papers…What Work...
2019 GDRR: Blockchain Data Analytics - Machine Learning in/for Blockchain: Fu...
2019 GDRR: Blockchain Data Analytics - QuTrack: Model Life Cycle Management f...
Ad

Recently uploaded (20)

PDF
Computing-Curriculum for Schools in Ghana
PDF
01-Introduction-to-Information-Management.pdf
PPTX
GDM (1) (1).pptx small presentation for students
PDF
Pre independence Education in Inndia.pdf
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PDF
O7-L3 Supply Chain Operations - ICLT Program
PDF
Insiders guide to clinical Medicine.pdf
PDF
Anesthesia in Laparoscopic Surgery in India
PPTX
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
PPTX
master seminar digital applications in india
PPTX
Cell Structure & Organelles in detailed.
PPTX
Renaissance Architecture: A Journey from Faith to Humanism
PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PPTX
Microbial diseases, their pathogenesis and prophylaxis
PDF
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PPTX
Final Presentation General Medicine 03-08-2024.pptx
PDF
Microbial disease of the cardiovascular and lymphatic systems
PDF
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
PPTX
PPH.pptx obstetrics and gynecology in nursing
PDF
VCE English Exam - Section C Student Revision Booklet
Computing-Curriculum for Schools in Ghana
01-Introduction-to-Information-Management.pdf
GDM (1) (1).pptx small presentation for students
Pre independence Education in Inndia.pdf
O5-L3 Freight Transport Ops (International) V1.pdf
O7-L3 Supply Chain Operations - ICLT Program
Insiders guide to clinical Medicine.pdf
Anesthesia in Laparoscopic Surgery in India
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
master seminar digital applications in india
Cell Structure & Organelles in detailed.
Renaissance Architecture: A Journey from Faith to Humanism
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
Microbial diseases, their pathogenesis and prophylaxis
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
Final Presentation General Medicine 03-08-2024.pptx
Microbial disease of the cardiovascular and lymphatic systems
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
PPH.pptx obstetrics and gynecology in nursing
VCE English Exam - Section C Student Revision Booklet

2019 Triangle Machine Learning Day - Mitigating Evasion Attacks to Deep Neural Networks via Region-based Classification - Xiaoyu Cao, September 20, 2019