電気学会論文誌C(電子・情報・システム部門誌)
Online ISSN : 1348-8155
Print ISSN : 0385-4221
ISSN-L : 0385-4221
<ソフトコンピューティング・学習>
MNISTに対する敵対的サンプル攻撃耐性を有する説明困難なルールを用いた分類手法
稲元 勉樋上 喜信松本 卓也榊原 一紀
著者情報
ジャーナル 認証あり

2025 年 145 巻 4 号 p. 498-509

詳細
抄録

In this paper, we propose a classification method that deploys hard-to-explain rules and is robust against adversarial example (AE) attacks on the MNIST. The purpose of this paper is to solve the technical difficulties of the deep learning-based technology that include the unexplainability of the classification and the vulnerability against the AE attack. The method proposed in this paper is similar to the existing method (DkNN) in terms of using output vectors computed from an artificial neural network (ANN), thus can solve the unexplainability difficulty. The proposed method is different from the DkNN in terms of the architecture of used ANNs and the format of output vectors. Those output vectors are discrete and used as hard-to-explain rules that mitigate the vulnerability against the AE attack. In computational experiments, the MNIST is taken as the target problem, then FGSM and BIM are used as the AE attacks. Computational results display that the proposed method achieved accuracies over 95% for all attacks.

著者関連情報
© 2025 電気学会
前の記事 次の記事
feedback
Top