Back to results

Monterey, CA; Naval Postgraduate School

DETECTING AND DEFENDING AGAINST DIFFERENT FAMILIES OF ADVERSARIAL EXAMPLE ATTACKS

Abstract

dc:description.abstract

Adversarial example attacks alter an image so the image appears largely unaltered to human eyes, but image-recognition models will misclassify it. This is a common type of attack, against which there is currently no good general defense. Most state-of-the-art methods of detecting adversarial example attacks only consistently succeed in recognizing a few known attacks. These defenses do not generalize well to detecting other attacks, which means an adversary only needs to change their attack to leave us without robust abilities to detect attacks. Military intelligence increasingly relies on machine learning image recognition for analyzing satellite images. Finding defenses against these adversarial example attacks is important for ensuring our intelligence-gathering capabilities are not compromised. This thesis seeks to contribute models which will push the state of the art towards successful recognition of adversarial attacks regardless of which type of attack was used. Models we named 3-Mix were trained using combinations of different attacked images; other models were trained using SaliencyMix. These defenses were evaluated against ten attacks: PGD, auto-PGD, autoattack, square, Carlini L2 and L-inf, deepfool, elasticnet, JSMA, and boundary. On average the attack success rate against the best defense model was 0.12 for 3-Mix, 0.31 for SaliencyMix, and 0.77 for comparison model Mixup.

Degree

thesis:*
Department dc:contributor.department
Computer Science (CS)
Grantor dc:publisher
Monterey, CA; Naval Postgraduate School
Year dc:date.issued
2023

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Kallis, Shaun
Advisor dc:contributor.advisor
  • Barton, Armon C.

Rights

dc:rights
Statement dc:rights
  • Copyright is reserved by the copyright owner.

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10945/72200
OAI identifier oai:identifier
oai:calhoun.nps.edu:10945/72200

Chain of custody

source
Harvested from
Naval Postgraduate School
Base URL
calhoun.nps.edu/server/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
related terms
citation

Kallis, Shaun. DETECTING AND DEFENDING AGAINST DIFFERENT FAMILIES OF ADVERSARIAL EXAMPLE ATTACKS. Monterey, CA; Naval Postgraduate School, 2023. https://hdl.handle.net/10945/72200