Skip to main navigation Skip to search Skip to main content

PDAAA: progressive defense against adversarial attacks for Deep Learning-as-a-Service in Internet of Things

Ling Wang, Cheng Zhang, Zejian Luo, Chenguang Liu, Xi Zheng

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

Nowadays, Deep Learning-as-a-Service can be deployed in the Internet of Things (IoT) to provide smart services and sensor data processing. However, recent research has revealed that some Deep Neural Networks (DNN) can be easily misled by adding relatively small but adversarial perturbations to the input (e.g., pixel mutation in input images). One challenge in defending DNN against these attacks is to efficiently identify and filtering out the adversarial pixels. The state-of-the-art defense strategies with good robustness often require additional model training for specific attacks. To reduce the computational cost without loss of generality, we present a defense strategy called a progressive defense against adversarial attacks (PDAAA) for efficiently and effectively filtering out the adversarial pixel mutations, which could mislead the neural network towards erroneous outputs, without a-priori knowledge about the attack type. We evaluated our progressive defense strategy against various attack methods on two well-known datasets. Experimental result shows it outperforms the state-of-the-art methods (Adversarial-PGD, Adversarial-Network, and Adversarial-Dual-Network) with dramatically reduced computation cost.
Original languageEnglish
Title of host publicationProceedings - 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021
EditorsLiang Zhao, Neeraj Kumar, Robert C. Hsu, Deqing Zou
Place of PublicationPiscataway, NJ
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages879-886
Number of pages8
ISBN (Electronic)9781665416580
DOIs
Publication statusPublished - 2021
Event20th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021 - Shenyang, China
Duration: 20 Oct 202122 Oct 2022

Publication series

NameIEEE International Conference on Trust Security and Privacy in Computing and Communications
PublisherIEEE COMPUTER SOC
ISSN (Print)2324-898X

Conference

Conference20th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021
Country/TerritoryChina
CityShenyang
Period20/10/2122/10/22

Keywords

  • Internet-of-things
  • Deep Learning
  • Adversarial Attack
  • Progressive Defense

Fingerprint

Dive into the research topics of 'PDAAA: progressive defense against adversarial attacks for Deep Learning-as-a-Service in Internet of Things'. Together they form a unique fingerprint.

Cite this