LanCeX: A Versatile and Lightweight Defense Method against Condensed Adversarial Attacks in Image and Audio Recognition

dc.contributor.authorXu, Zirui
dc.contributor.authorYu, Fuxun
dc.contributor.authorChen, Xiang
dc.contributor.authorLiu, Chenchen
dc.date.accessioned2022-08-23T14:47:59Z
dc.date.available2022-08-23T14:47:59Z
dc.date.issued2022-08-09
dc.description.abstractConvolutional Neural Networks (CNNs) are widely deployed in various embedded recognition applications. However, they demonstrate a considerable vulnerability to adversarial attacks, which leverage the well-designed perturbations to mislead the recognition results. Recently, for easier perturbation injection and higher attack effectiveness, the adversarial perturbations are concentrated into a small area with various types and different data modalities. When defending such condensed adversarial attacks on the embedded recognition scenarios, most of the existing defense works show two critical issues: First, they are particularly designed for each individual condensed attack scenario, lacking enough versatility to accommodate attacks with different data modalities. Second, they rely on computation-intensive pre-processing techniques, which is impractical for time-sensitive embedded recognition scenarios. In this paper, we propose LanCeX – a versatile and lightweight CNN defense solution against condensed adversarial attacks. By examining CNN’s intrinsic vulnerability, we first identify the common attacking mechanism behind condensed adversarial attacks across different data modalities. Based on this mechanism, LanCeX can defend against various condensed attacks with the optimal computation workload in different recognition scenarios. Experiments show that LanCeX can achieve an average 91%, 85%, and 90% detection success rate and optimal adversarial mitigation performance in three recognition scenarios, e.g. image classification, object detection, and audio recognition. Moreover, LanCeX is at most 3 × faster compared with the state-of-the-art defense methods, making it feasible to resource-constrained embedded systems.en_US
dc.description.urihttps://dl.acm.org/doi/abs/10.1145/3555375en_US
dc.format.extent22 pagesen_US
dc.genrejournal articlesen_US
dc.genrepostprintsen_US
dc.identifierdoi:10.13016/m2ltug-sip8
dc.identifier.citationZirui Xu, Fuxun Yu, Xiang Chen, and Chenchen Liu. 2022. LanCeX: A Versatile and Lightweight Defense Method against Condensed Adversarial Attacks in Image and Audio Recognition. ACM Trans. Embed. Comput. Syst. Just Accepted (July 2022). https://doi.org/10.1145/3555375en_US
dc.identifier.urihttps://doi.org/10.1145/3555375
dc.identifier.urihttp://hdl.handle.net/11603/25549
dc.language.isoen_USen_US
dc.publisherACMen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.en_US
dc.titleLanCeX: A Versatile and Lightweight Defense Method against Condensed Adversarial Attacks in Image and Audio Recognitionen_US
dc.typeTexten_US
dcterms.creatorhttps://orcid.org/0000-0001-7749-0640en_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
3555375.pdf
Size:
1.32 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: