A Game Theoretical Error-Correction Framework for Secure Traffic-Sign Classification

01/30/2019
by   Muhammed O. Sayin, et al.
0

We introduce a game theoretical error-correction framework to design classification algorithms that are reliable even in adversarial environments, with a specific focus on traffic-sign classification. Machine learning algorithms possess inherent vulnerabilities against maliciously crafted inputs especially at high dimensional input spaces. We seek to achieve reliable and timely performance in classification by redesigning the input space physically to significantly lower dimensions. Traffic-sign classification is an important use-case enabling the redesign of the inputs since traffic-signs have already been designed for their easy recognition by human drivers. We encode the original input samples to, e.g., strings of bits, through error-correction methods that can provide certain distance guarantees in-between any two different encoded inputs. And we model the interaction between the defense and the adversary as a game. Then, we analyze the underlying game using the concept of hierarchical equilibrium, where the defense strategies are designed by taking into account the best possible attack against them. At large scale, for computational simplicity, we provide an approximate solution, where we transform the problem into an efficient linear program with substantially small size compared to the original size of the entire input space. Finally, we examine the performance of the proposed scheme over different traffic-sign classification scenarios.

READ FULL TEXT
research
10/10/2017

Traffic Sign Timely Visual Recognizability Evaluation Based on 3D Measurable Point Clouds

The timely provision of traffic sign information to drivers is essential...
research
01/12/2020

Functional Error Correction for Robust Neural Networks

When neural networks (NeuralNets) are implemented in hardware, their wei...
research
10/04/2021

Error Correction for FrodoKEM Using the Gosset Lattice

We consider FrodoKEM, a lattice-based cryptosystem based on LWE, and pro...
research
04/25/2022

A Hybrid Defense Method against Adversarial Attacks on Traffic Sign Classifiers in Autonomous Vehicles

Adversarial attacks can make deep neural network (DNN) models predict in...
research
07/05/2023

Leveraging Denoised Abstract Meaning Representation for Grammatical Error Correction

Grammatical Error Correction (GEC) is the task of correcting errorful se...
research
09/06/2021

Comparing the Machine Readability of Traffic Sign Pictograms in Austria and Germany

We compare the machine readability of pictograms found on Austrian and G...

Please sign up or login with your details

Forgot password? Click here to reset