基于多任务一致性的对抗攻击检测
Multi-Task Consistency-based Detection of Adversarial Attacks
AI总结:
针对自动驾驶中DNNs易受对抗攻击且现有防御成本高的问题,提出基于多任务视觉任务输出一致性的高效检测方案,在BDD100k数据集上对PGD攻击的ROC-AUC达99.9%。
AI中文摘要:
深度神经网络(DNNs)已成功部署在众多视觉感知系统中,但其易受对抗攻击影响的特性引发了对实际应用的担忧,尤其在自动驾驶场景下。现有防御方法往往成本效率低下,难以在资源受限的应用中部署。本研究提出一种高效且有效的对抗攻击检测方案,利用复杂视觉系统内的多任务感知能力,通过不同视觉任务(如目标检测与实例分割)的推理输出之间的不一致性来检测对抗扰动。为此,我们开发了一致性得分指标以衡量视觉任务间的不一致性,还设计了一种方法来选择最佳模型对以有效检测不一致性。最后,我们在BDD100k验证数据集上,针对多种视觉模型的PGD攻击对该防御方法进行了评估,实验结果显示,在考虑的攻击者模型下,该防御方法达到了99.9%的ROC-AUC检测性能。
英文摘要:
Deep Neural Networks (DNNs) have found successful deployment in numerous vision perception systems. However, their susceptibility to adversarial attacks has prompted concerns regarding their practical applications, specifically in the context of autonomous driving. Existing defenses often suffer from cost inefficiency, rendering their deployment impractical for resource-constrained applications. In this work, we propose an efficient and effective adversarial attack detection scheme leveraging the multi-task perception within a complex vision system. Adversarial perturbations are detected by the inconsistencies between the inference outputs of multiple vision tasks, e.g., object detection and instance segmentation. To this end, we developed a consistency score metric to measure the inconsistency between vision tasks. Next, we designed an approach to select the best model pairs for detecting inconsistencies effectively. Finally, we evaluated our defense against PGD attacks across multiple vision models on the BDD100k validation dataset. The experimental results demonstrated that our defense achieved a ROC-AUC performance of 99.9% detection within the considered attacker model.