CN110598400A - 一种基于生成对抗网络的高隐藏中毒攻击的防御方法及应用 - Google Patents
一种基于生成对抗网络的高隐藏中毒攻击的防御方法及应用 Download PDFInfo
- Publication number
- CN110598400A CN110598400A CN201910808010.0A CN201910808010A CN110598400A CN 110598400 A CN110598400 A CN 110598400A CN 201910808010 A CN201910808010 A CN 201910808010A CN 110598400 A CN110598400 A CN 110598400A
- Authority
- CN
- China
- Prior art keywords
- sample
- detector
- adversarial
- generator
- attack
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 230000000607 poisoning effect Effects 0.000 title claims abstract description 61
- 231100000572 poisoning Toxicity 0.000 title claims abstract description 59
- 230000007123 defense Effects 0.000 title claims abstract description 42
- 238000000034 method Methods 0.000 title claims abstract description 40
- 238000012549 training Methods 0.000 claims abstract description 55
- 230000006870 function Effects 0.000 claims abstract description 47
- 241000628997 Flos Species 0.000 claims abstract description 18
- 230000000694 effects Effects 0.000 claims description 13
- 238000013527 convolutional neural network Methods 0.000 claims description 12
- 230000008569 process Effects 0.000 claims description 12
- 238000000605 extraction Methods 0.000 claims description 9
- 230000008859 change Effects 0.000 claims description 6
- 238000012804 iterative process Methods 0.000 claims description 6
- 238000001514 detection method Methods 0.000 claims description 4
- 238000013528 artificial neural network Methods 0.000 claims 1
- 230000003042 antagnostic effect Effects 0.000 abstract 2
- 231100000331 toxic Toxicity 0.000 abstract 1
- 230000002588 toxic effect Effects 0.000 abstract 1
- 238000013135 deep learning Methods 0.000 description 5
- 230000008878 coupling Effects 0.000 description 4
- 238000010168 coupling process Methods 0.000 description 4
- 238000005859 coupling reaction Methods 0.000 description 4
- 230000000007 visual effect Effects 0.000 description 4
- 230000009286 beneficial effect Effects 0.000 description 2
- 230000008901 benefit Effects 0.000 description 2
- 238000004364 calculation method Methods 0.000 description 2
- 238000012795 verification Methods 0.000 description 2
- 238000007792 addition Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000000873 masking effect Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 239000002574 poison Substances 0.000 description 1
- 231100000614 poison Toxicity 0.000 description 1
- 238000012216 screening Methods 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/04—Architecture, e.g. interconnection topology
- G06N3/045—Combinations of networks
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/08—Learning methods
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/16—Human faces, e.g. facial parts, sketches or expressions
- G06V40/161—Detection; Localisation; Normalisation
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Life Sciences & Earth Sciences (AREA)
- Data Mining & Analysis (AREA)
- Molecular Biology (AREA)
- Computational Linguistics (AREA)
- Biophysics (AREA)
- Biomedical Technology (AREA)
- Mathematical Physics (AREA)
- Artificial Intelligence (AREA)
- Evolutionary Computation (AREA)
- Computer Security & Cryptography (AREA)
- Human Computer Interaction (AREA)
- Multimedia (AREA)
- Oral & Maxillofacial Surgery (AREA)
- Computer Hardware Design (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Image Analysis (AREA)
Abstract
Description
Claims (7)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201910808010.0A CN110598400B (zh) | 2019-08-29 | 2019-08-29 | 一种基于生成对抗网络的高隐藏中毒攻击的防御方法及应用 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201910808010.0A CN110598400B (zh) | 2019-08-29 | 2019-08-29 | 一种基于生成对抗网络的高隐藏中毒攻击的防御方法及应用 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN110598400A true CN110598400A (zh) | 2019-12-20 |
CN110598400B CN110598400B (zh) | 2021-03-05 |
Family
ID=68856252
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201910808010.0A Active CN110598400B (zh) | 2019-08-29 | 2019-08-29 | 一种基于生成对抗网络的高隐藏中毒攻击的防御方法及应用 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN110598400B (zh) |
Cited By (19)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111597983A (zh) * | 2020-05-14 | 2020-08-28 | 公安部第三研究所 | 基于深度卷积神经网络实现生成式虚假人脸图像鉴定的方法 |
CN111737691A (zh) * | 2020-07-24 | 2020-10-02 | 支付宝(杭州)信息技术有限公司 | 对抗样本的生成方法和装置 |
CN111738217A (zh) * | 2020-07-24 | 2020-10-02 | 支付宝(杭州)信息技术有限公司 | 生成人脸对抗补丁的方法和装置 |
CN111881935A (zh) * | 2020-06-19 | 2020-11-03 | 北京邮电大学 | 一种基于内容感知gan的对抗样本生成方法 |
CN112162515A (zh) * | 2020-10-10 | 2021-01-01 | 浙江大学 | 一种针对过程监控系统的对抗攻击方法 |
CN112163638A (zh) * | 2020-10-20 | 2021-01-01 | 腾讯科技(深圳)有限公司 | 图像分类模型后门攻击的防御方法、装置、设备及介质 |
CN112528281A (zh) * | 2020-12-11 | 2021-03-19 | 浙江工业大学 | 联邦学习的中毒攻击检测方法、装置及设备 |
CN112598029A (zh) * | 2020-12-07 | 2021-04-02 | 中国建设银行股份有限公司 | 一种ocr识别对抗样本攻击的方法和装置 |
CN112927211A (zh) * | 2021-03-09 | 2021-06-08 | 电子科技大学 | 一种基于深度三维检测器的通用对抗攻击方法、存储介质和终端 |
CN113076557A (zh) * | 2021-04-02 | 2021-07-06 | 北京大学 | 一种基于对抗攻击的多媒体隐私保护方法、装置及设备 |
CN113283476A (zh) * | 2021-04-27 | 2021-08-20 | 广东工业大学 | 一种物联网网络入侵检测方法 |
CN113380255A (zh) * | 2021-05-19 | 2021-09-10 | 浙江工业大学 | 一种基于迁移训练的声纹识别中毒样本生成方法 |
CN113395280A (zh) * | 2021-06-11 | 2021-09-14 | 成都为辰信息科技有限公司 | 基于生成对抗网络的抗混淆性网络入侵检测方法 |
CN113420289A (zh) * | 2021-06-17 | 2021-09-21 | 浙江工业大学 | 面向深度学习模型的隐蔽中毒攻击防御方法及其装置 |
CN113821770A (zh) * | 2021-07-07 | 2021-12-21 | 大连理工大学 | 一种针对共享数据保护的定向对抗下毒攻击方法 |
CN113988312A (zh) * | 2021-11-02 | 2022-01-28 | 贵州大学 | 一种面向机器学习模型的成员推理隐私攻击方法及系统 |
CN113988293A (zh) * | 2021-10-29 | 2022-01-28 | 北京邮电大学 | 一种不同层级函数组合的对抗生成网络的方法 |
CN114726636A (zh) * | 2022-04-19 | 2022-07-08 | 电子科技大学 | 一种异构跨域系统的攻击动态检测与识别方法 |
CN114866341A (zh) * | 2022-06-17 | 2022-08-05 | 哈尔滨工业大学 | 面向网络入侵检测系统的漏洞放大式后门攻击安全评估方法 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108322349A (zh) * | 2018-02-11 | 2018-07-24 | 浙江工业大学 | 基于对抗式生成网络的深度学习对抗性攻击防御方法 |
CN109460814A (zh) * | 2018-09-28 | 2019-03-12 | 浙江工业大学 | 一种具有防御对抗样本攻击功能的深度学习分类方法 |
US20190253452A1 (en) * | 2018-02-14 | 2019-08-15 | Cisco Technology, Inc. | Adaptive union file system based protection of services |
-
2019
- 2019-08-29 CN CN201910808010.0A patent/CN110598400B/zh active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108322349A (zh) * | 2018-02-11 | 2018-07-24 | 浙江工业大学 | 基于对抗式生成网络的深度学习对抗性攻击防御方法 |
US20190253452A1 (en) * | 2018-02-14 | 2019-08-15 | Cisco Technology, Inc. | Adaptive union file system based protection of services |
CN109460814A (zh) * | 2018-09-28 | 2019-03-12 | 浙江工业大学 | 一种具有防御对抗样本攻击功能的深度学习分类方法 |
Non-Patent Citations (1)
Title |
---|
ZHIGANG LI等: "Generate Identity-Preserving Faces by Generative Adversarial Networks", 《ARXIV》 * |
Cited By (32)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111597983A (zh) * | 2020-05-14 | 2020-08-28 | 公安部第三研究所 | 基于深度卷积神经网络实现生成式虚假人脸图像鉴定的方法 |
CN111597983B (zh) * | 2020-05-14 | 2023-06-06 | 公安部第三研究所 | 基于深度卷积神经网络实现生成式虚假人脸图像鉴定的方法 |
CN111881935A (zh) * | 2020-06-19 | 2020-11-03 | 北京邮电大学 | 一种基于内容感知gan的对抗样本生成方法 |
CN111737691A (zh) * | 2020-07-24 | 2020-10-02 | 支付宝(杭州)信息技术有限公司 | 对抗样本的生成方法和装置 |
CN111738217A (zh) * | 2020-07-24 | 2020-10-02 | 支付宝(杭州)信息技术有限公司 | 生成人脸对抗补丁的方法和装置 |
CN111738217B (zh) * | 2020-07-24 | 2020-11-13 | 支付宝(杭州)信息技术有限公司 | 生成人脸对抗补丁的方法和装置 |
CN112162515B (zh) * | 2020-10-10 | 2021-08-03 | 浙江大学 | 一种针对过程监控系统的对抗攻击方法 |
CN112162515A (zh) * | 2020-10-10 | 2021-01-01 | 浙江大学 | 一种针对过程监控系统的对抗攻击方法 |
CN112163638A (zh) * | 2020-10-20 | 2021-01-01 | 腾讯科技(深圳)有限公司 | 图像分类模型后门攻击的防御方法、装置、设备及介质 |
CN112163638B (zh) * | 2020-10-20 | 2024-02-13 | 腾讯科技(深圳)有限公司 | 图像分类模型后门攻击的防御方法、装置、设备及介质 |
CN112598029A (zh) * | 2020-12-07 | 2021-04-02 | 中国建设银行股份有限公司 | 一种ocr识别对抗样本攻击的方法和装置 |
CN112528281B (zh) * | 2020-12-11 | 2024-08-27 | 浙江工业大学 | 联邦学习的中毒攻击检测方法、装置及设备 |
CN112528281A (zh) * | 2020-12-11 | 2021-03-19 | 浙江工业大学 | 联邦学习的中毒攻击检测方法、装置及设备 |
CN112927211A (zh) * | 2021-03-09 | 2021-06-08 | 电子科技大学 | 一种基于深度三维检测器的通用对抗攻击方法、存储介质和终端 |
CN112927211B (zh) * | 2021-03-09 | 2023-08-25 | 电子科技大学 | 一种基于深度三维检测器的通用对抗攻击方法、存储介质和终端 |
CN113076557A (zh) * | 2021-04-02 | 2021-07-06 | 北京大学 | 一种基于对抗攻击的多媒体隐私保护方法、装置及设备 |
CN113076557B (zh) * | 2021-04-02 | 2022-05-20 | 北京大学 | 一种基于对抗攻击的多媒体隐私保护方法、装置及设备 |
CN113283476A (zh) * | 2021-04-27 | 2021-08-20 | 广东工业大学 | 一种物联网网络入侵检测方法 |
CN113283476B (zh) * | 2021-04-27 | 2023-10-10 | 广东工业大学 | 一种物联网网络入侵检测方法 |
CN113380255B (zh) * | 2021-05-19 | 2022-12-20 | 浙江工业大学 | 一种基于迁移训练的声纹识别中毒样本生成方法 |
CN113380255A (zh) * | 2021-05-19 | 2021-09-10 | 浙江工业大学 | 一种基于迁移训练的声纹识别中毒样本生成方法 |
CN113395280B (zh) * | 2021-06-11 | 2022-07-26 | 成都为辰信息科技有限公司 | 基于生成对抗网络的抗混淆性网络入侵检测方法 |
CN113395280A (zh) * | 2021-06-11 | 2021-09-14 | 成都为辰信息科技有限公司 | 基于生成对抗网络的抗混淆性网络入侵检测方法 |
CN113420289B (zh) * | 2021-06-17 | 2022-08-26 | 浙江工业大学 | 面向深度学习模型的隐蔽中毒攻击防御方法及其装置 |
CN113420289A (zh) * | 2021-06-17 | 2021-09-21 | 浙江工业大学 | 面向深度学习模型的隐蔽中毒攻击防御方法及其装置 |
CN113821770A (zh) * | 2021-07-07 | 2021-12-21 | 大连理工大学 | 一种针对共享数据保护的定向对抗下毒攻击方法 |
CN113988293A (zh) * | 2021-10-29 | 2022-01-28 | 北京邮电大学 | 一种不同层级函数组合的对抗生成网络的方法 |
CN113988293B (zh) * | 2021-10-29 | 2024-07-12 | 北京邮电大学 | 一种不同层级函数组合的对抗生成网络的方法 |
CN113988312A (zh) * | 2021-11-02 | 2022-01-28 | 贵州大学 | 一种面向机器学习模型的成员推理隐私攻击方法及系统 |
CN114726636A (zh) * | 2022-04-19 | 2022-07-08 | 电子科技大学 | 一种异构跨域系统的攻击动态检测与识别方法 |
CN114866341A (zh) * | 2022-06-17 | 2022-08-05 | 哈尔滨工业大学 | 面向网络入侵检测系统的漏洞放大式后门攻击安全评估方法 |
CN114866341B (zh) * | 2022-06-17 | 2024-03-05 | 哈尔滨工业大学 | 面向网络入侵检测系统的漏洞放大式后门攻击安全评估方法 |
Also Published As
Publication number | Publication date |
---|---|
CN110598400B (zh) | 2021-03-05 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN110598400A (zh) | 一种基于生成对抗网络的高隐藏中毒攻击的防御方法及应用 | |
CN110674938B (zh) | 基于协同多任务训练的对抗攻击防御方法 | |
Kanimozhi et al. | Artificial intelligence based network intrusion detection with hyper-parameter optimization tuning on the realistic cyber dataset CSE-CIC-IDS2018 using cloud computing | |
Khan et al. | Malicious insider attack detection in IoTs using data analytics | |
US10084822B2 (en) | Intrusion detection and prevention system and method for generating detection rules and taking countermeasures | |
Park et al. | Host-based intrusion detection model using siamese network | |
JP7512523B2 (ja) | ビデオ検出方法、装置、電子機器及び記憶媒体 | |
CN113094707B (zh) | 一种基于异质图网络的横向移动攻击检测方法及系统 | |
CN108960064A (zh) | 一种基于卷积神经网络的人脸检测及识别方法 | |
Yin et al. | Defense against adversarial attacks by low‐level image transformations | |
Liang et al. | Poisoned forgery face: Towards backdoor attacks on face forgery detection | |
Gao et al. | Backdoor attack with sparse and invisible trigger | |
Chen et al. | {FACE-AUDITOR}: Data auditing in facial recognition systems | |
CN117579290A (zh) | 一种基于融合时空注意力的积分时空图卷积神经网络的恶意流量检测方法 | |
Gong et al. | Agramplifier: defending federated learning against poisoning attacks through local update amplification | |
Sun et al. | Instance-level trojan attacks on visual question answering via adversarial learning in neuron activation space | |
Al Solami et al. | Continuous biometric authentication: Can it be more practical? | |
Xue | Research on network security intrusion detection with an extreme learning machine algorithm | |
Hu et al. | ${\sf VeriDIP} $ VeriDIP: Verifying Ownership of Deep Neural Networks Through Privacy Leakage Fingerprints | |
CN113989898B (zh) | 一种基于空间敏感度的人脸对抗样本检测方法 | |
Osamor et al. | Deep learning-based hybrid model for efficient anomaly detection | |
Gomathy et al. | Network intrusion detection using genetic algorithm and neural network | |
Zhang et al. | Pip: Detecting adversarial examples in large vision-language models via attention patterns of irrelevant probe questions | |
CN115664784A (zh) | 一种采用多模组学习的网络攻击免疫防御方法及系统 | |
Srinivasan | Keylogger malware detection using machine learning model for platform-independent devices |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
OL01 | Intention to license declared | ||
OL01 | Intention to license declared | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20191220 Assignee: Linyi CITIC Information Technology Co.,Ltd. Assignor: JIANG University OF TECHNOLOGY Contract record no.: X2024980035813 Denomination of invention: A defense method and application for high hidden poisoning attacks based on generative adversarial networks Granted publication date: 20210305 License type: Open License Record date: 20241219 |
|
EE01 | Entry into force of recordation of patent licensing contract | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20191220 Assignee: FENGCHENG TANTAI BIOTECHNOLOGY Co.,Ltd. Assignor: JIANG University OF TECHNOLOGY Contract record no.: X2024980037343 Denomination of invention: A defense method and application for high hidden poisoning attacks based on generative adversarial networks Granted publication date: 20210305 License type: Open License Record date: 20241223 Application publication date: 20191220 Assignee: Shandong Kangdi Decoration Material Co.,Ltd. Assignor: JIANG University OF TECHNOLOGY Contract record no.: X2024980037342 Denomination of invention: A defense method and application for high hidden poisoning attacks based on generative adversarial networks Granted publication date: 20210305 License type: Open License Record date: 20241222 Application publication date: 20191220 Assignee: Shandong Quanyi Machinery Manufacturing Co.,Ltd. Assignor: JIANG University OF TECHNOLOGY Contract record no.: X2024980037341 Denomination of invention: A defense method and application for high hidden poisoning attacks based on generative adversarial networks Granted publication date: 20210305 License type: Open License Record date: 20241222 |
|
EE01 | Entry into force of recordation of patent licensing contract | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20191220 Assignee: SHANDONG KAIJIA ENERGY SAVING BUILDING MATERIAL ENGINEERING Co.,Ltd. Assignor: JIANG University OF TECHNOLOGY Contract record no.: X2024980038855 Denomination of invention: A defense method and application for high hidden poisoning attacks based on generative adversarial networks Granted publication date: 20210305 License type: Open License Record date: 20241226 |
|
EE01 | Entry into force of recordation of patent licensing contract | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20191220 Assignee: Hangzhou MuShang Exhibition Design Co.,Ltd. Assignor: JIANG University OF TECHNOLOGY Contract record no.: X2024980041359 Denomination of invention: A defense method and application for high hidden poisoning attacks based on generative adversarial networks Granted publication date: 20210305 License type: Open License Record date: 20241231 |
|
EE01 | Entry into force of recordation of patent licensing contract |