Deep learning has been widely used in many fields. A large number of images can be quickly recognized by the deep learning models to provide information. How to improve the robustness of deep learning applications has become the focus of research. Unfortunately, the recognition ability of the existing deep learning model has been greatly threatened, many images can cause recognition errors in a well-trained model. Although data augmentation is an effective method, the existence of adversarial examples shows that traditional data augmentation methods have no obvious effect on minor pixel changes. After analyzing the impact of pixel changes on model recognition accuracy, a data augmentation method based on a small number of pixel changes is proposed. Our method can optimize the corresponding classification boundary and improve the recognition robustness of the model. Finally, a simple evaluation method to measure the robustness of model recognition is proposed. Our experiments prove the threat of a small number of pixels and the effectiveness of our data augmentation method. Moreover, the data augmentation method has strong generalization ability and can be applied to image recognition in many different fields.
Goodfellow, I., Bengio, Y., Courville, A. and Bengio, Y. (2016) Deep Learning, Volume 1. MIT Press, Cambridge.
Lecun, Y., Bengio, Y. and Hinton, G. (2015) Deep Learning. Nature, 521, 436. https://doi.org/10.1038/nature14539
Deng, L. and Yu, D. (2014) Deep Learning: Methods and Applications. Foundations and Trends in Signal Processing, 7, 197-387. https://doi.org/10.1561/2000000039
Parkhi, O.M., Vedaldi, A. and Zisserman, A. (2015) Deep Face Recognition. Proceedings of the British Machine Vision Conference, Swansea, 7-10 September 2015, 41.1-41.12. https://doi.org/10.5244/C.29.41
Hu, G., Yang, Y., Yi, D., Kittler, J., Christmas, W., Li, S.Z. and Hospedales, T. (2015) When Face Recognition Meets with Deep Learning: An Evaluation of Convolutional Neural Networks for Face Recognition. Proceedings of the IEEE International Conference on Computer Vision Workshops, Boston, 7-12 June 2015, 142-150. https://doi.org/10.1109/ICCVW.2015.58
Alotaibi, M. and Mahmood, A. (2017) Improved Gait Recognition Based on Specialized Deep Convolutional Neural Network. Computer Vision and Image Understanding, 164, 103-110. https://doi.org/10.1016/j.cviu.2017.10.004
Wang, J., Ma, Y., Zhang, L., Gao, R.X. and Wu, D. (2018) Deep Learning for Smart Manufacturing: Methods and Applications. Journal of Manufacturing Systems, 48, 144-156. https://doi.org/10.1016/j.jmsy.2018.01.003
Essien, A. and Giannetti, C. (2020) A Deep Learning Model for Smart Manufacturing Using Convolutional LSTM Neural Network Autoencoders. IEEE Transactions on Industrial Informatics, 16, 6069-6078. https://doi.org/10.1109/TII.2020.2967556
Lee, J., Azamfar, M., Singh, J. and Siahpour, S. (2020) Integration of Digital Twin and Deep Learning in Cyber-Physical Systems: Towards Smart Manufacturing. IET Collaborative Intelligent Manufacturing, 2, 34-36. https://doi.org/10.1049/iet-cim.2020.0009
Ahuett-Garza, H. and Kurfess, T. (2018) A Brief Discussion on the Trends of Habilitating Technologies for Industry 4.0 and Smart Manufacturing. Manufacturing Letters, 15, 60-63. https://doi.org/10.1016/j.mfglet.2018.02.011
Kotsiopoulos, T., Sarigiannidis, P., Ioannidis, D. and Tzovaras, D. (2021) Machine Learning and Deep Learning in Smart Manufacturing: The Smart Grid Paradigm. Computer Science Review, 40, Article ID: 100341. https://doi.org/10.1016/j.cosrev.2020.100341
Ulicny, M., Lundstrom, J. and Byttner, S. (2016) Robustness of Deep Convolutional Neural Networks for Image Recognition. In: International Symposium on Intelligent Computing Systems, Springer, Berlin, 16-30. https://doi.org/10.1007/978-3-319-30447-2_2
Goswami, G., Ratha, N., Agarwal, A., Singh, R. and Vatsa, M. (2018) Unravelling Robustness of Deep Learning Based Face Recognition against Adversarial Attacks. Proceedings of the AAAI Conference on Artificial Intelligence, Volume 32, 6829-6936.
Goodfellow, I.J., Shlens, J. and Szegedy, C. (2014) Explaining and Harnessing Adversarial Examples.
Van Dyk, D.A. and Meng, X.L. (2001) The Art of Data Augmentation. Journal of Computational and Graphical Statistics, 10, 1-50. https://doi.org/10.1198/10618600152418584
Miko lajczyk, A. and Grochowski, M. (2018) Data Augmentation for Improving Deep Learning in Image Classification Problem. 2018 IEEE International Interdisciplinary PhD Workshop (IIPhDW), Swinoujscie, 9-12 May 2018, 117-122. https://doi.org/10.1109/IIPHDW.2018.8388338
Deng, J., Dong, W., Socher, R., et al. (2009) ImageNet: A Large-Scale Hierarchical Image Database. 2009 IEEE Conference on Computer Vision and Pattern Recognition, Miami, 20-25 June 2009, 248-255. https://doi.org/10.1109/CVPR.2009.5206848
He, K., Zhang, X., Ren, S. and Sun, J. (2016) Deep Residual Learning for Image Recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, 27-30 June 2016, 770-778. https://doi.org/10.1109/CVPR.2016.90
Huang, G., Liu, Z., Van Der Maaten, L. and Weinberger, K.Q. (2017) Densely Connected Convolutional Networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, 21-26 July 2017, 4700-4708. https://doi.org/10.1109/CVPR.2017.243
Simonyan, K. and Zisserman, A. (2014) Very Deep Convolutional Networks for Large-Scale Image Recognition.
Krizhevsky, A., Sutskever, I. and Hinton, G.E. (2017) Imagenet Classification with Deep Convolutional Neural Networks. Communications of the ACM, 60, 84-90. https://doi.org/10.1145/3065386
Iandola, F.N., Han, S., Moskewicz, M.W., Ashraf, K., Dally, W.J. and Keutzer, K. (2016) Squeezenet: Alexnet-Level Accuracy with 50x Fewer Parameters and < 0.5 mb Model Size.
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. and Fergus, R. (2013) Intriguing Properties of Neural Networks.
Ozbulak, U., Van Messem, A. and De Neve, W. (2019) Impact of Adversarial Examples on Deep Learning Models for Biomedical Image Segmentation. In: International Conference on Medical Image Computing and Computer-Assisted Intervention, Springer, Berlin, 300-308. https://doi.org/10.1007/978-3-030-32245-8_34
Kurakin, A., Goodfellow, I. and Bengio, S. (2016) Adversarial Examples in the Physical World.
Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B. and Madry, A. (2019) Adversarial Examples Are Not Bugs, They Are Features. 33rd Annual Conference on Neural Information Processing Systems (NeurIPS 2019), Vancouver, 8-14 December 2019, 125-136.
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B. and Swami, A. (2017) Practical Black-Box Attacks against Machine Learning. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, 2-6 April 2017, 506-519. https://doi.org/10.1145/3052973.3053009
Ilyas, A., Engstrom, L., Athalye, A. and Lin, J. (2018) Black-Box Adversarial Attacks with Limited Queries and Information.
Hosseini, H., Chen, Y., Kannan, S., Zhang, B. and Poovendran, R. (2017) Blocking Transferability of Adversarial Examples in Black-Box Learning Systems.
Carlini, N. and Wagner, D. (2016) Towards Evaluating the Robustness of Neural Networks. 2017 IEEE Symposium on Security and Privacy (SP), San Jose, 22-26 May 2017. https://doi.org/10.1109/SP.2017.49
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B. and Swami, A. (2016) The Limitations of Deep Learning in Adversarial Settings. 2016 IEEE European Symposium on Security and Privacy (EuroS&P), Genoa, 7-11 September 2020, 372-387. https://doi.org/10.1109/EuroSP.2016.36
Baluja, S. and Fischer, I. (2017) Adversarial Transformation Networks: Learning to Generate Adversarial Examples.
Su, J., Vargas, D.V. and Sakurai, K. (2019) One Pixel Attack for Fooling Deep Neural Networks. IEEE Transactions on Evolutionary Computation, 23, 828-841. https://doi.org/10.1109/TEVC.2019.2890858
Wong, S.C., Gatt, A., Stamatescu, V. and McDonnell, M.D. (2016) Understanding Data Augmentation for Classification: When to Warp? 2016 IEEE International Conference on Digital Image Computing: Techniques and Applications (DICTA), Gold Coast, 30 November-2 December 2016, 1-6. https://doi.org/10.1109/DICTA.2016.7797091
Cubuk, E.D., Zoph, B., Mane, D., Vasudevan, V. and Le, Q.V. (2018) Autoaugment: Learning Augmentation Policies from Data. 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Long Beach, 15-20 June 2019. https://doi.org/10.1109/CVPR.2019.00020
Zhong, Z., Zheng, L., Kang, G., Li, S. and Yang, Y. (2020) Random Erasing Data Augmentation. The Thirty-Fourth AAAI Conference on Artificial Intelligence (AAAI-20), New York, 7-12 February 2020, 13001-13008. https://doi.org/10.1609/aaai.v34i07.7000
Cubuk, E.D., Zoph, B., Mane, D., Vasudevan, V. and Le, Q.V. (2019) Autoaugment: Learning Augmentation Strategies from Data. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Long Beach, 15-20 June 2019, 113-123. https://doi.org/10.1109/CVPR.2019.00020
Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A. and Bengio, Y. (2020) Generative Adversarial Networks. Communications of the ACM, 63, 139-144. https://doi.org/10.1145/3422622
Jan, S.T., Messou, J., Lin, Y.C., Huang, J.B. and Wang, G. (2019) Connecting the Digital and Physical World: Improving the Robustness of Adversarial Attacks. Proceedings of the AAAI Conference on Artificial Intelligence, Volume 33, 962-969. https://doi.org/10.1609/aaai.v33i01.3301962
Luo, B., Liu, Y., Wei, L. and Xu, Q. (2018) Towards Imperceptible and Robust Adversarial Example Attacks against Neural Networks. Proceedings of the AAAI Conference on Artificial Intelligence, New York, 7-12 February 2020.