Browse > Article
http://dx.doi.org/10.3745/JIPS.03.0161

Secure Object Detection Based on Deep Learning  

Kim, Keonhyeong (School of Electronics and Engineering, Kyungpook National University)
Jung, Im Young (School of Electronics and Engineering, Kyungpook National University)
Publication Information
Journal of Information Processing Systems / v.17, no.3, 2021 , pp. 571-585 More about this Journal
Abstract
Applications for object detection are expanding as it is automated through artificial intelligence-based processing, such as deep learning, on a large volume of images and videos. High dependence on training data and a non-transparent way to find answers are the common characteristics of deep learning. Attacks on training data and training models have emerged, which are closely related to the nature of deep learning. Privacy, integrity, and robustness for the extracted information are important security issues because deep learning enables object recognition in images and videos. This paper summarizes the security issues that need to be addressed for future applications and analyzes the state-of-the-art security studies related to robustness, privacy, and integrity of object detection for images and videos.
Keywords
Deep Learning; Integrity; Object Detection; Privacy; Robustness;
Citations & Related Records
연도 인용수 순위
  • Reference
1 J. Chao, A. A. Badawi, B. Unnikrishnan, J. Lin, C. F. Mun, J. M. Brown, et al., "CaRENets: compact and resource-efficient CNN for homomorphic inference on encrypted medical images," 2019 [Online]. Available: https://arxiv.org/abs/1901.10074.
2 C. Dwork and A. Roth, "The algorithmic foundations of differential privacy," Theoretical Computer Science, vol. 9, nos. 3-4, pp. 211-407, 2014.
3 S. Dasiopoulou, V. Mezaris, I. Kompatsiaris, V. Papastathis, and M. Strintzis, "Knowledge-assisted semantic video object detection," IEEE Transactions on Circuits and Systems for Video Technology, vol. 15, no. 10, pp. 1210-1224, 2005.   DOI
4 D. Cao, Z. Chen, and L. Gao, "An improved object detection algorithm based on multi-scaled and deformable convolutional neural networks," Human-centric Computing and Information Sciences, vol. 10, article no. 14, 2020.
5 N. Papernot, P. McDaniel, and I. Goodfellow, "Transferability in machine learning: from phenomena to black-box attacks using adversarial samples," 2016 [Online]. Available: https://arxiv.org/abs/1605.07277.
6 N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, "Practical black-box attacks against machine learning," in Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates, 2017, pp. 506-519.
7 W. Brendel, J. Rauber, and M. Bethge, "Decision-based adversarial attacks: reliable attacks against black-box machine learning models," in Proceedings of the 6th International Conference on Learning Representations (ICLR), Vancouver, Canada, 2018.
8 J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff, "On detecting adversarial perturbations," 2017 [Online]. Available: https://arxiv.org/abs/1702.04267.
9 C. Burkard and B. Lagesse, "Analysis of causative attacks against SVMs learning from data streams," in Proceedings of the 3rd ACM on International Workshop on Security and Privacy Analytics, Scottsdale, AZ, 2017, pp. 31-36.
10 K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, "Robust physical-world attacks on deep learning models," 2018 [Online]. Available: https://arxiv.org/abs/1707.08945.
11 Y. Dong, T. Pang, H. Su, and J. Zhu, "Evading defenses to transferable adversarial examples by translation-invariant attacks," in Proceedings of IEEE Conference of Computer Vision and Pattern Recognition (CVPR), Long Beach, CA, 2019, pp. 4312-4321.
12 M. Noura, H. Noura, A. Chehab, M. M. Mansour, L. Sleem, and R. Couturier, "A dynamic approach for a lightweight and secure cipher for medical images," Multimedia Tools and Applications, vol. 77, no. 23, pp. 31397-31426, 2018.   DOI
13 N. A. Memon, "Watermarking of medical images for content authentication and copyright protection," Ph.D. dissertation, GIK Institute of Engineering Sciences and Technology, Topi, Pakistan, 2010.
14 N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, "Distillation as a defense to adversarial perturbations against deep neural networks," in Proceedings of the 2016 IEEE Symposium on Security & Privacy, San Jose, CA, 2016, pp. 582-597.
15 M. Beye, Z. Erkin, and R. L. Lagendijk, "Efficient privacy preserving k-means clustering in a three-party setting," in Proceedings of IEEE International Workshop on Information Forensics and Security, Iguacu Falls, Argentina, 2011, pp. 1-6.
16 P. Selvaraj and R. Varatharajan, "Whirlpool algorithm with hash function based watermarking algorithm for the secured transmission of digital medical images," Mobile Networks and Applications, 2018. https://doi.org/10.1007/s11036-018-1057-4   DOI
17 Y. Liu, X. Chen, C. Liu, and D. Song, "Delving into transferable adversarial examples and blackbox attacks," in Proceedings of the 5th International Conference on Learning Representations (ICLR), Toulon, France, 2017.
18 J. Aigrain and M. Detyniecki, "Detecting adversarial examples and other misclassifications in neural networks by introspection," 2019 [Online]. https://arxiv.org/abs/1905.09186.
19 C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille, "Mitigating adversarial effects through randomization," 2018 [Online]. Available: https://arxiv.org/abs/1711.01991.
20 A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok, "Synthesizing robust adversarial examples," in Proceedings of the 35th International Conference on Machine Learning (ICML), Stockholm, Sweden, 2018, pp. 284-293.
21 P. Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C. J. Hsieh, "Zoo: zeroth order optimization based blackbox attacks to deep neural networks without training substitute models," in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security (AISec), Dallas, TX, 2017, pp. 15-26.
22 A. Kurakin, I. Goodfellow, S. Bengio, "Adversarial examples in the physical world," in Proceedings of the 5th International Conference on Learning Representations (ICLR), Toulon, France, 2017.
23 C. Yin, B. Zhou, Z. Yin, and J. Wang, "Local privacy protection classification based on human-centric computing," Human-centric Computing and Information Sciences, vol. 9, article no. 33, 2019.
24 Q. Jia, L. Guo, Z. Jin, and Y. Fang, "Preserving model privacy for machine learning in distributed systems," IEEE Transactions on Parallel and Distributed Systems, vol. 29, no. 8, pp. 1808-1822, 2018.   DOI
25 L. Wang, L. Li, J. Li, J. Li, B. B. Gupta, and L. Xia, "Compressive sensing of medical images with confidentially homomorphic aggregations," IEEE Internet of Things Journal, vol. 6, no. 2, pp. 1402-1409, 2019.   DOI
26 X. Zhang, X. Zhu, and L. Lessard, "Online data poisoning attacks," 2019 [Online]. Available: https://arxiv.org/abs/1903.01666.
27 B. Li, Y. Wang, A. Singh, and Y. Vorobeychik, "Data poisoning attacks on factorization-based collaborative filtering," Advances in Neural Information Processing, vol. 29, pp. 1885-1893, 2016.
28 I. J. Goodfellow, J. Shlens, and C. Szegedy, "Explaining and harnessing adversarial examples," in Proceedings of the 3rd International Conference on Learning Representations(ICLR), San Diego, CA, 2015.
29 N. Carlini and D. Wagner, "Towards evaluating the robustness of neural networks," in Proceedings of 2017 IEEE Symposium on Security and Privacy, San Jose, CA, 2017, pp. 39-57.
30 D. W. Hosmer Jr, S. Lemeshow, and R. X. Sturdivant, Applied Logistic Regression. Hoboken, NJ: John Wiley & Sons, 2013.
31 M. J. J. Ghrabat, G. Ma, I. Y. Maolood, S. S. Alresheedi, and Z. A. Abduljabbar, "An effective image retrieval based on optimized genetic algorithm utilized a novel SVM-based convolutional neural network classifier," Human-centric Computing and Information Sciences, vol. 9, article no. 31, 2019.
32 Y. Liu, Z. Ma, X. Liu, S. Ma, and K. Ren, "Privacy-preserving object detection for medical images with faster R-CNN," IEEE Transactions on Information Forensics and Security, 2019. https://doi.org/10.1109/TIFS.2019.2946476   DOI
33 S. Patel, S. Garasia, and D. Jinwala, "An efficient approach for privacy preserving distributed k-means clustering based on Shamir's secret sharing scheme," in Trust Management VI. Heidelberg, Germany: Springer, 2012, pp. 129-141.
34 M. S. Riazi, C. Weinert, O. Tkachenko, E. M. Songhori, T. Schneider, and F. Koushanfar, "Chameleon: a hybrid secure computation framework for machine learning applications," in Proceedings of the 2018 on Asia Conference on Computer and Communications Security (ASIACCS), Incheon, Republic of Korea, 2018, PP. 707-721.
35 C. Wang, H. Zhang, X. Zhou, "LBP and DWT based fragile watermarking for image authentication," Journal of Information Processing Systems, vol. 14, no. 3, pp. 666-679, 2018.   DOI
36 C. Wang, H. Zhang, and X. Zhou, "Review on self-embedding fragile watermarking for image authentication and self-recovery," Journal of Information Processing Systems, vol. 14, no. 2, pp. 510-522, 2018.   DOI
37 D. J. Miller, Z. Xiang, and G. Kesidis, "Adversarial learning in statistical classification: a comprehensive review of defenses against attacks," 2019 [Online]. Available: https://arxiv.org/abs/1904.06292.
38 X. Wu, "An algorithm for reversible information hiding of encrypted medical images in homomorphic encrypted domain," Discrete & Continuous Dynamical Systems-S, vol. 12, no. 4-5, pp. 1441-1455, 2019.   DOI
39 Y. Zheng, H. Cui, C. Wang, and J. Zhou, "Privacy-preserving image denoising from external cloud databases," IEEE Transactions on Information Forensics and Security, vol. 12, no. 6, pp. 1285-1298, 2017.   DOI
40 Z. Ma, Y. Liu, X. Liu, J. Ma, and F. Li, "Privacy-preserving outsourced speech recognition for smart IoT devices," IEEE Internet of Things Journal, vol. 6, no. 5, pp. 8406-8420, 2019.   DOI
41 K. Y. Chu, Y. H. Kuo, and W. H. Hsu, "Real-time privacy-preserving moving object detection in the cloud," in Proceedings of the 21st ACM International Conference on Multimedia, Barcelona, Spain, 2013, pp. 597-600.
42 S. M. Mousavi, A. Naghsh, and S. Abu-Bakar, "Watermarking techniques used in medical images: a survey," Journal of Digital Imaging, vol. 27, no. 6, pp. 714-729, 2014.   DOI
43 F. Tramer, A. Kurakin, N. Papernot, D. Boneh, and P. McDaniel, "Ensemble adversarial training: Attacks and defenses," in Proceedings of the 6th International Conference on Learning Representations (ICLR), Vancouver, Canada, 2018.
44 A. Shamir, "How to share a secret," Communications of the ACM, vol. 22, no. 11, pp. 612-613, 1979.   DOI
45 A. Sen, S. Alfeld, X. Zhang, A. Vartanian, Y. Ma, and X. Zhu, "Training set camouflage," in Decision and Game Theory for Security. Cham, Switzerland: Springer, 2018, pp. 59-79.
46 S. Gu and L. Rigazio, "Towards deep neural network architectures robust to adversarial examples," in Proceedings of the 3rd International Conference on Learning Representations, San Diego, CA, 2015.
47 F. Liao, M. Liang, Y. Dong, T. Pang, X. Hu, and J. Zhu, "Defense against adversarial attacks using high-level representation guided denoiser," 2018 [Online]. Available: https://arxiv.org/abs/1712.02976.
48 Y. Chen and X. Zhu, "Optimal adversarial attack on autoregressive models by manipulating the environment," 2019 [Online]. Available: https://arxiv.org/abs/1902.00202.
49 C. Guo, M. Rana, M. Cisse, and L. V. D. Maaten, "Countering adversarial images using input transformations," in Proceedings of the 6th International Conference on Learning Representations (ICLR), Vancouver, Canada, 2018.
50 M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, "Deep learning with differential privacy," in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, 2016, pp. 308-318.