• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Rectifying adversarial inputs using XAI techniques
 
  • Details
  • Full
Options
2022
Conference Paper
Title

Rectifying adversarial inputs using XAI techniques

Abstract
With deep neural networks (DNNs) involved in more and more decision making processes, critical security problems can occur when DNNs give wrong predictions. This can be enforced with so-called adversarial attacks. These attacks modify the input in such a way that they are able to fool a neural network into a false classification, while the changes remain imperceptible to a human observer. Even for very specialized AI systems, adversarial attacks are still hardly detectable. The current state-of-the-art adversarial defenses can be classified into two categories: pro-active defense and passive defense, both unsuitable for quick rectifications: Pro-active defense methods aim to correct the input data to classify the adversarial samples correctly, while reducing the accuracy of ordinary samples. Passive defense methods, on the other hand, aim to filter out and discard the adversarial samples. Neither of the defense mechanisms is suitable for the setup of autonomous driving: when an input has to be classified, we can neither discard the input nor have the time to go for computationally expensive corrections. This motivates our method based on explainable artificial intelligence (XAI) for the correction of adversarial samples. We used two XAI interpretation methods to correct adversarial samples. We experimentally compared this approach with baseline methods. Our analysis shows that our proposed method outperforms the state-of-the-art approaches.
Author(s)
Kao, Ching-Yu Franziska
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Chen, Junhao
Markert, Karla
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Böttinger, Konstantin  
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Mainwork
30th European Signal Processing Conference, EUSIPCO 2022. Proceedings  
Conference
European Signal Processing Conference 2022  
DOI
10.23919/EUSIPCO55093.2022.9909699
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Keyword(s)
  • adversarial defense

  • deep learning

  • explainable AI

  • neural networks

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024