Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 22 von 504

Details

Autor(en) / Beteiligte
Titel
Mitigating Targeted Bit-Flip Attacks via Data Augmentation: An Empirical Study
Ist Teil von
  • Knowledge Science, Engineering and Management, p.606-618
Ort / Verlag
Cham: Springer International Publishing
Quelle
Alma/SFX Local Collection
Beschreibungen/Notizen
  • As deep neural networks (DNNs) become more widely used in various safety-critical applications, protecting their security has been an urgent and important task. Recently, one critical security issue is proposed that DNN models are vulnerable to targeted bit-flip attacks. This kind of sophisticated attack tries to inject backdoors into models via flipping only a few bits of carefully chosen model parameters. In this paper, we propose a gradient obfuscation-based data augmentation method to mitigate these targeted bit-flip attacks as an empirical study. Particularly, we mitigate such targeted bit-flip attacks by preprocessing only input samples to break the link between the features carried by triggers of input samples with the modified model parameters. Moreover, our method can keep an acceptable accuracy on benign samples. We show that our method is effective against two targeted bit-flip attacks by experiments on two widely-used structures (ResNet-20 and VGG-16) with one famous dataset (CIFAR-10).
Sprache
Englisch
Identifikatoren
ISBN: 3031109880, 9783031109881
ISSN: 0302-9743
eISSN: 1611-3349
DOI: 10.1007/978-3-031-10989-8_48
Titel-ID: cdi_springer_books_10_1007_978_3_031_10989_8_48

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX