SPN dash: Fast detection of adversarial attacks on mobile via sensor pattern noise fingerprinting

Published

Conference Paper

© 2018 ACM. A concerning weakness of deep neural networks is their susceptibility to adversarial attacks. While methods exist to detect these attacks, they incur significant drawbacks, ignoring external features which could aid in the task of attack detection. In this work, we propose SPN Dash, a method for detection of adversarial attacks based on integrity of sensor pattern noise embedded in submitted images. Through experiment, we show that our SPN Dash method is capable of detecting the addition of adversarial noise with up to 94% accuracy for images of size 256×256. Analysis shows that SPN Dash is robust to image scaling techniques, as well as a small amount of image compression. This performance is on par with state of the art neural network-based detectors, while incurring an order of magnitude less computational and memory overhead.

Full Text

Duke Authors

Cited Authors

  • Nixon, KW; Mao, J; Shen, J; Yang, H; Li, HH; Chen, Y

Published Date

  • November 5, 2018

Published In

International Standard Serial Number (ISSN)

  • 1092-3152

International Standard Book Number 13 (ISBN-13)

  • 9781450359504

Digital Object Identifier (DOI)

  • 10.1145/3240765.3240851

Citation Source

  • Scopus