Engineering (Mar 2020)

Adversarial Attacks and Defenses in Deep Learning

  • Kui Ren,
  • Tianhang Zheng,
  • Zhan Qin,
  • Xue Liu

Journal volume & issue
Vol. 6, no. 3
pp. 346 – 360

Abstract

Read online

With the rapid developments of artificial intelligence (AI) and deep learning (DL) techniques, it is critical to ensure the security and robustness of the deployed algorithms. Recently, the security vulnerability of DL algorithms to adversarial samples has been widely recognized. The fabricated samples can lead to various misbehaviors of the DL models while being perceived as benign by humans. Successful implementations of adversarial attacks in real physical-world scenarios further demonstrate their practicality. Hence, adversarial attack and defense techniques have attracted increasing attention from both machine learning and security communities and have become a hot research topic in recent years. In this paper, we first introduce the theoretical foundations, algorithms, and applications of adversarial attack techniques. We then describe a few research efforts on the defense techniques, which cover the broad frontier in the field. Several open problems and challenges are subsequently discussed, which we hope will provoke further research efforts in this critical area. Keywords: Machine learning, Deep neural network, Adversarial example, Adversarial attack, Adversarial defense