• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. SpectralDefense: Detecting Adversarial Attacks on CNNs in the Fourier Domain
 
  • Details
  • Full
Options
2021
Conference Paper
Title

SpectralDefense: Detecting Adversarial Attacks on CNNs in the Fourier Domain

Abstract
Despite the success of convolutional neural networks (CNNs) in many computer vision and image analysis tasks, they remain vulnerable against so-called adversarial attacks: Small, crafted perturbations in the input images can lead to false predictions. A possible defense is to detect adversarial examples. In this work, we show how analysis in the Fourier domain of input images and feature maps can be used to distinguish benign test samples from adversarial images. We propose two novel detection methods: Our first method employs the magnitude spectrum of the input images to detect an adversarial attack. This simple and robust classifier can successfully detect adversarial perturbations of three commonly used attack methods. The second method builds upon the first and additionally extracts the phase of Fourier coefficients of feature-maps at different layers of the network. With this extension, we are able to improve adversarial detection rates compared to state-of-the-art detectors on five different attack methods. The code for the methods proposed in the paper is available at github.com/paulaharder/SpectralAdversarialDefense.
Author(s)
Harder, Paula  
Fraunhofer-Institut für Techno- und Wirtschaftsmathematik ITWM  
Pfreundt, Franz-Josef  
Fraunhofer-Institut für Techno- und Wirtschaftsmathematik ITWM  
Keuper, Margret
Data and Web Science Group, University of Mannheim
Keuper, Janis
Institute for Machine Learning and Analytics (IMLA), Offenburg University; Fraunhofer-Institut für Techno- und Wirtschaftsmathematik ITWM
Mainwork
International Joint Conference on Neural Networks, IJCNN 2021. Proceedings  
Conference
International Joint Conference on Neural Networks (IJCNN) 2021  
Open Access
DOI
10.1109/IJCNN52387.2021.9533442
Additional full text version
Landing Page
Language
English
Fraunhofer-Institut für Techno- und Wirtschaftsmathematik ITWM  
Keyword(s)
  • adversarial attacks

  • adversarial detection

  • image classification

  • convolutional neural network

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024