• 中国精品科技期刊
  • CCF推荐A类中文期刊
  • 计算领域高质量科技期刊T1类


李明慧, 江沛佩, 王骞, 沈超, 李琦

李明慧, 江沛佩, 王骞, 沈超, 李琦. 针对深度学习模型的对抗性攻击与防御[J]. 计算机研究与发展, 2021, 58(5): 909-926. DOI: 10.7544/issn1000-1239.2021.20200920
引用本文: 李明慧, 江沛佩, 王骞, 沈超, 李琦. 针对深度学习模型的对抗性攻击与防御[J]. 计算机研究与发展, 2021, 58(5): 909-926. DOI: 10.7544/issn1000-1239.2021.20200920
Li Minghui, Jiang Peipei, Wang Qian, Shen Chao, Li Qi. Adversarial Attacks and Defenses for Deep Learning Models[J]. Journal of Computer Research and Development, 2021, 58(5): 909-926. DOI: 10.7544/issn1000-1239.2021.20200920
Citation: Li Minghui, Jiang Peipei, Wang Qian, Shen Chao, Li Qi. Adversarial Attacks and Defenses for Deep Learning Models[J]. Journal of Computer Research and Development, 2021, 58(5): 909-926. DOI: 10.7544/issn1000-1239.2021.20200920


基金项目: 国家重点研发计划项目(2020AAA0107700);国家自然科学基金优秀青年科学基金项目(61822207);国家自然科学基金重点项目(U20B2049)
  • 中图分类号: TP391

Adversarial Attacks and Defenses for Deep Learning Models

Funds: This work was supported by the National Key Research and Development Program of China (2020AAA0107700), the National Natural Science Foundation of China for Excellent Young Scientists (61822207), and the Key Program of the National Natural Science Foundation of China (U20B2049).
  • 摘要: 以深度学习为主要代表的人工智能技术正在悄然改变人们的生产生活方式,但深度学习模型的部署也带来了一定的安全隐患.研究针对深度学习模型的攻防分析基础理论与关键技术,对深刻理解模型内在脆弱性、全面保障智能系统安全性、广泛部署人工智能应用具有重要意义.拟从对抗的角度出发,探讨针对深度学习模型的攻击与防御技术进展和未来挑战.首先介绍了深度学习生命周期不同阶段所面临的安全威胁.然后从对抗性攻击生成机理分析、对抗性攻击生成、对抗攻击的防御策略设计、对抗性攻击与防御框架构建4个方面对现有工作进行系统的总结和归纳.还讨论了现有研究的局限性并提出了针对深度学习模型攻防的基本框架.最后讨论了针对深度学习模型的对抗性攻击与防御未来的研究方向和面临的技术挑战.
    Abstract: Deep learning is one of the main representatives of artificial intelligence technology, which is quietly enhancing our daily lives. However, the deployment of deep learning models has also brought potential security risks. Studying the basic theories and key technologies of attacks and defenses for deep learning models is of great significance for a deep understanding of the inherent vulnerability of the models, comprehensive protection of intelligent systems, and widespread deployment of artificial intelligence applications. This paper discusses the development and future challenges of the adversarial attacks and defenses for deep learning models from the perspective of confrontation. In this paper, we first introduce the potential threats faced by deep learning at different stages. Afterwards, we systematically summarize the progress of existing attack and defense technologies in artificial intelligence systems from the perspectives of the essential mechanism of adversarial attacks, the methods of adversarial attack generation, defensive strategies against the attacks, and the framework of the attacks and defenses. We also discuss the limitations of related research and propose an attack framework and a defense framework for guidance in building better adversarial attacks and defenses. Finally, we discuss several potential future research directions and challenges for adversarial attacks and defenses against deep learning model.
  • 期刊类型引用(14)

    1. 董彦松,刘月浩,董旭乾,赵亮,田聪,于斌,段振华. 基于误差分治的神经网络验证. 软件学报. 2024(05): 2307-2324 . 百度学术
    2. 江钦辉,李默涵,孙彦斌. 深度神经网络后门防御综述. 信息安全学报. 2024(04): 47-63 . 百度学术
    3. 陆正之,黄希宸,彭勃. 军事智能数据安全问题:对抗攻击威胁. 网络安全与数据治理. 2024(11): 23-28 . 百度学术
    4. 王志波,王雪,马菁菁,秦湛,任炬,任奎. 面向计算机视觉系统的对抗样本攻击综述. 计算机学报. 2023(02): 436-468 . 百度学术
    5. 萧晓彤,丁建伟,张琪. 基于图片边界后门嵌入的图像识别攻击研究. 现代电子技术. 2023(06): 129-134 . 百度学术
    6. 张恒,吕雪,刘东,王国胤,杭芹,沙睿,郭宾. 核电人工智能应用:现状、挑战和机遇. 核动力工程. 2023(01): 1-8 . 百度学术
    7. 吴炜霞,向红权,石凯. 智能无人系统安全防御体系研究. 信息安全与通信保密. 2023(05): 81-87 . 百度学术
    8. 顾凡. 无线局域网络入侵行为的预判算法设计与仿真. 贵阳学院学报(自然科学版). 2023(03): 50-55 . 百度学术
    9. 汪欣欣,陈晶,何琨,张子君,杜瑞颖,李瞧,佘计思. 面向目标检测的对抗攻击与防御综述. 通信学报. 2023(11): 260-277 . 百度学术
    10. 姜忠龙,邓德位. 军事信息系统人工智能对抗技术研究. 舰船电子工程. 2023(11): 27-32 . 百度学术
    11. 刘佳美,孙涵,林磊. 基于伪标签的可防御稳定网络. 计算机技术与发展. 2022(06): 34-38 . 百度学术
    12. 彭琨,丁小波,蔡茂贞,钟地秀,黎蕴玉. 分布式图像解析系统的设计与研究. 现代计算机. 2022(11): 31-34+40 . 百度学术
    13. 李自拓,孙建彬,杨克巍,熊德辉. 面向图像分类的对抗鲁棒性评估综述. 计算机研究与发展. 2022(10): 2164-2189 . 本站查看
    14. 陈国明,袁泽铎,龙舜,麦舒桃. 一种基于格雷码置乱与分块混沌置乱的医学影像隐私保护分类方案. 数据采集与处理. 2022(05): 984-996 . 百度学术


  • 文章访问数:  2302
  • HTML全文浏览量:  28
  • PDF下载量:  1759
  • 被引次数: 36
  • 发布日期:  2021-04-30


