<?xml version="1.1" encoding="utf-8"?>
<article xsi:noNamespaceSchemaLocation="http://jats.nlm.nih.gov/publishing/1.1/xsd/JATS-journalpublishing1-mathml3.xsd" dtd-version="1.1" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"><front><journal-meta><journal-id journal-id-type="publisher-id">JCER</journal-id><journal-title-group><journal-title>Journal of Contemporary Educational Research</journal-title></journal-title-group><issn>2208-8466</issn><eissn>2208-8474</eissn><publisher><publisher-name>Bio-Byword Scientific Publishing Pty. Ltd.</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.26689/jcer.v8i11.8797</article-id><article-categories><subj-group subj-group-type="heading"><subject>Article</subject></subj-group></article-categories><title>A Study on Filter-Based Adversarial Image Classification Models</title><url>https://artdesignp.com/journal/JCER/8/11/10.26689/jcer.v8i11.8797</url><author>ZhaoZhongcheng</author><pub-date pub-type="publication-year"><year>2024</year></pub-date><volume>8</volume><issue>11</issue><history><date date-type="pub"><published-time>2024-11-27</published-time></date></history><abstract>In view of the fact that adversarial examples can lead to high-confidence erroneous outputs of deep neural networks, this study aims to improve the safety of deep neural networks by distinguishing adversarial examples. A classification model based on filter residual network structure is used to accurately classify adversarial examples. The filter-based classification model includes residual network feature extraction and classification modules, which are iteratively optimized by an&amp;nbsp;adversarial training strategy. Three mainstream adversarial attack methods are improved, and adversarial samples are generated on the Mini-ImageNet dataset. Subsequently, these samples are used to attack the EfficientNet and the filter-based classification model respectively, and the attack effects are compared. Experimental results show that the filter-based classification model has high classification accuracy when dealing with Mini-ImageNet adversarial examples. Adversarial training can effectively enhance the robustness of deep neural network models.</abstract><keywords/></article-meta></front><body/><back><ref-list><ref id="B1" content-type="article"><label>1</label><element-citation publication-type="journal"><p>Li C, Cao YN, Peng YK, 2022, Research on Automatic Driving Target Detection Based on YOLOv5s. Journal of Physics: Conference Series, 2171(1): 012047.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B2" content-type="article"><label>2</label><element-citation publication-type="journal"><p>Sainath TN, He YZ, Li B, et al., 2020, A Streaming on Device End-to-End Model Surpassing Server-Side Conventional Model Quality and Latency, International Conference on Acoustics, Speech and Signal Processing, Barcelona, 6059–6063.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B3" content-type="article"><label>3</label><element-citation publication-type="journal"><p>Wang Q, 2021, Research on Image Recognition Technology Based on Convolution Neural Network, International Conference on Information Systems and Computer Aided Education, Dalian, 2628–2632.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B4" content-type="article"><label>4</label><element-citation publication-type="journal"><p>Chen JF, Zhang WH, 2020, Research and Application of Deep Learning in Image Recognition. Electronics World, 2020(19): 48–49.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B5" content-type="article"><label>5</label><element-citation publication-type="journal"><p>Krizhevsky A, Sutskever Hinton GE, 2017, ImageNet Classification with Deep Convolutional Neural Networks. J Communications of the ACM, 60(6): 84–90.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B6" content-type="article"><label>6</label><element-citation publication-type="journal"><p>Chen QY, Huang Y, Sun R, et al., 2020, An Efficient Accelerator for Multiple Convolutions from the Sparsity Perspective. IEEE Transactions on Very Large Scale Integration (VLS) Systems, 28(6): 1540–1544.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B7" content-type="article"><label>7</label><element-citation publication-type="journal"><p>Chen X, Weng J, Deng XL, et al., 2023, Feature Distillation in Deep Attention Network Against Adversarial Examples. IEEE Transactions on Neural Networks and Learning Systems, 34(7): 3691–3705.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B8" content-type="article"><label>8</label><element-citation publication-type="journal"><p>Goodfellow IJ, Shlens J, Szegedy C, 2023, Explaining and Harnessing Adversarial Examples. arXiv. https://doi.org/10.48550/arXiv.1412.6572</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B9" content-type="article"><label>9</label><element-citation publication-type="journal"><p>Zantedeschi V, Nicolae MI, Rawat A, 2017, Efficient Defenses Against Adversarial Attacks. arXiv. https://doi.org/10.48550/arXiv.1707.06728</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B10" content-type="article"><label>10</label><element-citation publication-type="journal"><p>Li X, Li FX, 2017, Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics, International Conference on Computer Vision, Venice, 5775–5783.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B11" content-type="article"><label>11</label><element-citation publication-type="journal"><p>Zhang CL, Ye ZC, Wang Y, et al., 2018, Detecting Adversarial Perturbations with Saliency, International Conference on Signal and Image Processing, Shenzhen, 271–275.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B12" content-type="article"><label>12</label><element-citation publication-type="journal"><p>Lu JJ, Issaranon T, Forsyth D, 2017, SafetyNet: Detecting and Rejecting Adversarial Examples Robustly, International Conference on Computer Vision, Venice, 446–454.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B13" content-type="article"><label>13</label><element-citation publication-type="journal"><p>Linardos P, Little S, McGuinness K, 2019, MediaEval 2019: Concealed FGSM Perturbations for Privacy Preservation. arXiv. https://doi.org/10.48550/arXiv.1910.11603</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B14" content-type="article"><label>14</label><element-citation publication-type="journal"><p>Moosavidezfoolis M, Fawzi A, Frossard P, 2023, DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. arXiv. https://doi.org/10.48550/arXiv.1511.04599</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B15" content-type="article"><label>15</label><element-citation publication-type="journal"><p>McCaffrey J, 2014, Test Run: Distorting the MNIST Image Data Set. MSDN Magazine, 29(7): 66–69.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B16" content-type="article"><label>16</label><element-citation publication-type="journal"><p>Wu DX, Xu J, Liu H, 2020, Analysis of the Influence of Stylized-CIFAR10 Dataset on ResNet, in Chen XF, Yan HY, Yan QB, et al., Machine learning for Cybersecurity, Springer, Cham, 416–426.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B17" content-type="article"><label>17</label><element-citation publication-type="journal"><p>Mangla P, Jandial S, Varshney S, et al., 2023, AdvGAN+: Harnessing Latent Layers for Adversary Generation. arXiv. https://doi.org/10.48550/arXiv.1908.00706</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B18" content-type="article"><label>18</label><element-citation publication-type="journal"><p>Jabra MB, Koubaa A, Benidira B, et al., 2021, COVID-19 Diagnosis in Chest X-Rays Using Deep Learning and Majority Voting. Applied Sciences, 11(6): 2884.</p><pub-id pub-id-type="doi"/></element-citation></ref></ref-list></back></article>
