CAAI Transactions on Intelligence Technology (Mar 2021)

A survey on adversarial attacks and defences

  • Anirban Chakraborty,
  • Manaar Alam,
  • Vishal Dey,
  • Anupam Chattopadhyay,
  • Debdeep Mukhopadhyay

DOI
https://doi.org/10.1049/cit2.12028
Journal volume & issue
Vol. 6, no. 1
pp. 25 – 45

Abstract

Read online

Abstract Deep learning has evolved as a strong and efficient framework that can be applied to a broad spectrum of complex learning problems which were difficult to solve using the traditional machine learning techniques in the past. The advancement of deep learning has been so radical that today it can surpass human‐level performance. As a consequence, deep learning is being extensively used in most of the recent day‐to‐day applications. However, efficient deep learning systems can be jeopardised by using crafted adversarial samples, which may be imperceptible to the human eye, but can lead the model to misclassify the output. In recent times, different types of adversaries based on their threat model leverage these vulnerabilities to compromise a deep learning system where adversaries have high incentives. Hence, it is extremely important to provide robustness to deep learning algorithms against these adversaries. However, there are only a few strong countermeasures which can be used in all types of attack scenarios to design a robust deep learning system. Herein, the authors attempt to provide a detailed discussion on different types of adversarial attacks with various threat models and also elaborate on the efficiency and challenges of recent countermeasures against them.

Keywords