4.6 Article

CuRTAIL: ChaRacterizing and Thwarting AdversarIal Deep Learning

Journal

Publisher

IEEE COMPUTER SOC
DOI: 10.1109/TDSC.2020.3024191

Keywords

Machine learning; Robustness; Computational modeling; Redundancy; Hardware; Machine learning algorithms; Deep learning; model reliability; adversarial samples; white-box attacks

Funding

  1. ARO [W911NF1910317]
  2. SRC-Auto Grant [2019-AU-2899]
  3. U.S. Department of Defense (DOD) [W911NF1910317] Funding Source: U.S. Department of Defense (DOD)

Ask authors/readers for more resources

CuRTAIL is a novel end-to-end computing framework designed to prevent adversarial attacks and has shown effectiveness against adversarial samples. The framework employs an unsupervised approach to validate the legitimacy of input samples, ensuring effective defense against generic attacks.
Recent advances in adversarial Deep Learning (DL) have opened up a new and largely unexplored surface for malicious attacks jeopardizing the integrity of autonomous DL systems. This article introduces CuRTAIL, a novel end-to-end computing framework to characterize and thwart potential adversarial attacks and significantly improve the reliability (safety) of a victim DL model. We formalize the goal of preventing adversarial attacks as an optimization problem to minimize the rarely observed regions in the latent feature space spanned by a DL network. To solve the aforementioned minimization problem, a set of complementary but disjoint modular redundancies are trained to validate the legitimacy of the input samples. The proposed countermeasure is unsupervised, meaning that no adversarial sample is leveraged to train modular redundancies. This, in turn, ensures the effectiveness of the defense in the face of generic attacks. We evaluate the robustness of our proposed methodology against the state-of-the-art adaptive attacks in a white-box setting considering that the adversary knows everything about the victim model and its defenders. Extensive evaluations for analyzing MNIST, CIFAR10, and ImageNet data corroborate the effectiveness of CuRTAIL framework against adversarial samples. The computations in each modular redundancy can be performed independently of the other redundancy modules. As such, CuRTAIL detection algorithm can be completely parallelized among multiple hardware settings to achieve maximum throughput. We further provide an open-source Application Programming Interface (API) to facilitate the adoption of the proposed framework for various applications.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available