My Account Log in

1 option

Attacks, Defenses and Testing for Deep Learning / by Jinyin Chen, Ximin Zhang, Haibin Zheng.

Springer Nature - Springer Computer Science eBooks 2024 English International Available online

View online
Format:
Book
Author/Creator:
Chen, Jinyin.
Contributor:
Zhang, Ximin.
Zheng, Haibin.
Series:
Computer Science Series
Language:
English
Subjects (All):
Artificial intelligence.
Computer engineering.
Computer networks.
Neural networks (Computer science).
Artificial Intelligence.
Computer Engineering and Networks.
Mathematical Models of Cognitive Processes and Neural Networks.
Local Subjects:
Artificial Intelligence.
Computer Engineering and Networks.
Mathematical Models of Cognitive Processes and Neural Networks.
Physical Description:
1 online resource (413 pages)
Edition:
1st ed. 2024.
Place of Publication:
Singapore : Springer Nature Singapore : Imprint: Springer, 2024.
Summary:
This book provides a systematic study on the security of deep learning. With its powerful learning ability, deep learning is widely used in CV, FL, GNN, RL, and other scenarios. However, during the process of application, researchers have revealed that deep learning is vulnerable to malicious attacks, which will lead to unpredictable consequences. Take autonomous driving as an example, there were more than 12 serious autonomous driving accidents in the world in 2018, including Uber, Tesla and other high technological enterprises. Drawing on the reviewed literature, we need to discover vulnerabilities in deep learning through attacks, reinforce its defense, and test model performance to ensure its robustness. Attacks can be divided into adversarial attacks and poisoning attacks. Adversarial attacks occur during the model testing phase, where the attacker obtains adversarial examples by adding small perturbations. Poisoning attacks occur during the model training phase, where the attacker injects poisoned examples into the training dataset, embedding a backdoor trigger in the trained deep learning model. An effective defense method is an important guarantee for the application of deep learning. The existing defense methods are divided into three types, including the data modification defense method, model modification defense method, and network add-on method. The data modification defense method performs adversarial defense by fine-tuning the input data. The model modification defense method adjusts the model framework to achieve the effect of defending against attacks. The network add-on method prevents the adversarial examples by training the adversarial example detector. Testing deep neural networks is an effective method to measure the security and robustness of deep learning models. Through test evaluation, security vulnerabilities and weaknesses in deep neural networks can be identified. By identifying and fixing these vulnerabilities, the security and robustness of the model can be improved. Our audience includes researchers in the field of deep learning security, as well as software development engineers specializing in deep learning.
Contents:
Perturbation Optimized Black-Box Adversarial Attacks via Genetic Algorithm
Feature Transfer Based Stealthy Poisoning Attack for DNNs
Adversarial Attacks on GNN Based Vertical Federated Learning
A Novel DNN Object Contour Attack on Image Recognition
Query-Efficient Adversarial Attack Against Vertical Federated Graph Learning
Targeted Label Adversarial Attack on Graph Embedding
Backdoor Attack on Dynamic Link Prediction
Attention Mechanism based Adversarial Attack against DRL
Characterizing Adversarial Examples via Local Gradient Checking
A Novel Adversarial Defense by Refocusing on Critical Areas
Neuron-level Inverse Perturbation Against Adversarial Attacks
Adaptive Channel Transformation-based Detector for Adversarial Attacks
Defense Against Free-rider Attack From the Weight Evolving Frequency
An Effective Model Copyright Protection for Federated Learning
Guard the vertical federated graph learning from Property Inference Attack
Using Adversarial Examples to Against Backdoor Attack in FL
Evaluating the Adversarial Robustness of Deep Model by Decision Boundaries
Certifiable Prioritization for Deep Neural Networks via Movement Cost in Feature Space
Interpretable White-Box Fairness Testing through Biased Neuron Identification
A Deep Learning Framework for Dynamic Network Link Prediction. .
Notes:
Description based on publisher supplied metadata and other sources.
ISBN:
981-9704-25-1
OCLC:
1438670466

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account