Emulated Autoencoder: A Time-Efficient Image Denoiser for Defense of Convolutional Neural Networks against Evasion Attacks

dc.contributor.advisorLagesse, Brent
dc.contributor.authorLe, Dat Tien
dc.date.accessioned2022-07-14T22:01:31Z
dc.date.available2022-07-14T22:01:31Z
dc.date.issued2022-07-14
dc.date.submitted2022
dc.descriptionThesis (Master's)--University of Washington, 2022
dc.description.abstractAs Convolutional Neural Networks (CNN) have become essential to modern applications such as image classification on social networks or self-driving vehicles, evasion attacks targeting CNNs can lead to damage for users. Therefore, there has been a rising amount of research focusing on defending against evasion attacks. Image denoisers have been used to mitigate the impact of evasion attacks; however, there is not a sufficiently broad view of the use of image denoisers as adversarial defenses in image classification due to a lack of trade-off analysis. Thus, image denoisers' costs, including training time, image reconstruction time, and loss of benign F1 scores of CNN classifiers, are explored in this thesis. Additionally, Emulated Autoencoder (EAE), which is the proposed method of this thesis to optimize trade-offs for high volume classification tasks, is evaluated alongside state-of-the-art image denoisers in the gray-box and white-box threat models. EAE outperforms most image denoisers in both the gray-box and white-box threat models while drastically reducing training and image reconstruction time compared to the state-of-the-art denoisers. As a result, EAE is more appropriate for securing high-volume classification applications of images.
dc.embargo.termsOpen Access
dc.format.mimetypeapplication/pdf
dc.identifier.otherLe_washington_0250O_24118.pdf
dc.identifier.urihttp://hdl.handle.net/1773/48662
dc.language.isoen_US
dc.rightsnone
dc.subjectAdversarial Machine Learning
dc.subjectAutoencoder
dc.subjectConvolutional Neural Networks
dc.subjectImage Denoiser
dc.subjectMachine Learning Adversarial Defense
dc.subjectComputer science
dc.subject.otherComputing and software systems
dc.titleEmulated Autoencoder: A Time-Efficient Image Denoiser for Defense of Convolutional Neural Networks against Evasion Attacks
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Le_washington_0250O_24118.pdf
Size:
4.22 MB
Format:
Adobe Portable Document Format