Skip to main content

Markov Chain Based Efficient Defense Against Adversarial Examples in Computer Vision

Publication ,  Journal Article
Zhou, Y; Hu, X; Wang, L; Duan, S; Chen, Y
Published in: IEEE Access
January 1, 2019

Adversarial examples are the inputs to machine learning models that result in erroneous outputs, which are usually generated from normal inputs via subtle modification and seem to remain unchanged to human observers. They have severely threatened the applications of machine learning, especially in the areas with high-security requirements. Unfortunately, for this issue, there is neither unambiguous interpretation about the causes nor almighty defenses in spite of the increasing attention and discussions. Based on the distinguished statistical feature of Markov chain, an effective defense method is proposed in this paper by exploring the differences in the probability distributions of adjacent pixels between normal images and adversarial examples. Specifically, the concept of overall probability value (OPV) is defined to estimate the modification to an input, which can be used to preliminarily determine whether the input is an adversarial example or not. Furthermore, by calculating the OPV of an input and modifying its pixel value to destroy the potential adversarial characteristics, the proposed method can efficiently purify adversarial examples. A series of experiments demonstrate the effectiveness of the defense method. When facing various attacks, it obtains excellent performance with accuracy over 92% for MNIST and 70% for ImageNet.

Duke Scholars

Published In

IEEE Access

DOI

EISSN

2169-3536

Publication Date

January 1, 2019

Volume

7

Start / End Page

5695 / 5706

Related Subject Headings

  • 46 Information and computing sciences
  • 40 Engineering
  • 10 Technology
  • 09 Engineering
  • 08 Information and Computing Sciences
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Zhou, Y., Hu, X., Wang, L., Duan, S., & Chen, Y. (2019). Markov Chain Based Efficient Defense Against Adversarial Examples in Computer Vision. IEEE Access, 7, 5695–5706. https://doi.org/10.1109/ACCESS.2018.2889409
Zhou, Y., X. Hu, L. Wang, S. Duan, and Y. Chen. “Markov Chain Based Efficient Defense Against Adversarial Examples in Computer Vision.” IEEE Access 7 (January 1, 2019): 5695–5706. https://doi.org/10.1109/ACCESS.2018.2889409.
Zhou Y, Hu X, Wang L, Duan S, Chen Y. Markov Chain Based Efficient Defense Against Adversarial Examples in Computer Vision. IEEE Access. 2019 Jan 1;7:5695–706.
Zhou, Y., et al. “Markov Chain Based Efficient Defense Against Adversarial Examples in Computer Vision.” IEEE Access, vol. 7, Jan. 2019, pp. 5695–706. Scopus, doi:10.1109/ACCESS.2018.2889409.
Zhou Y, Hu X, Wang L, Duan S, Chen Y. Markov Chain Based Efficient Defense Against Adversarial Examples in Computer Vision. IEEE Access. 2019 Jan 1;7:5695–5706.

Published In

IEEE Access

DOI

EISSN

2169-3536

Publication Date

January 1, 2019

Volume

7

Start / End Page

5695 / 5706

Related Subject Headings

  • 46 Information and computing sciences
  • 40 Engineering
  • 10 Technology
  • 09 Engineering
  • 08 Information and Computing Sciences