Skip to main navigation Skip to search Skip to main content

DAMAD: Database, Attack, and Model Agnostic Adversarial Perturbation Detector

  • Indraprastha Institute of Information Technology Delhi
  • IBM
  • Indian Institute of Technology Jodhpur

Research output: Contribution to journalArticlepeer-review

18 Scopus citations

Abstract

Adversarial perturbations have demonstrated the vulnerabilities of deep learning algorithms to adversarial attacks. Existing adversary detection algorithms attempt to detect the singularities; however, they are in general, loss-function, database, or model dependent. To mitigate this limitation, we propose DAMAD - a generalized perturbation detection algorithm which is agnostic to model architecture, training data set, and loss function used during training. The proposed adversarial perturbation detection algorithm is based on the fusion of autoencoder embedding and statistical texture features extracted from convolutional neural networks. The performance of DAMAD is evaluated on the challenging scenarios of cross-database, cross-attack, and cross-architecture training and testing along with traditional evaluation of testing on the same database with known attack and model. Comparison with state-of-the-art perturbation detection algorithms showcase the effectiveness of the proposed algorithm on six databases: ImageNet, CIFAR-10, Multi-PIE, MEDS, point and shoot challenge (PaSC), and MNIST. Performance evaluation with nearly a quarter of a million adversarial and original images and comparison with recent algorithms show the effectiveness of the proposed algorithm.

Original languageEnglish
Pages (from-to)3277-3289
Number of pages13
JournalIEEE Transactions on Neural Networks and Learning Systems
Volume33
Issue number8
DOIs
StatePublished - Aug 1 2022

Keywords

  • Adversarial examples
  • adversarial perturbation
  • attack agnostic
  • cross-attack
  • cross-database
  • cross-model
  • database agnostic
  • model agnostic

Fingerprint

Dive into the research topics of 'DAMAD: Database, Attack, and Model Agnostic Adversarial Perturbation Detector'. Together they form a unique fingerprint.

Cite this