Anomaly detection method robust against adversarial attacks
The anomaly detection method addresses the vulnerability of neural network models to adversarial attacks by using a dual-score approach to enhance detection robustness and accuracy.
Patent Information
- Application Number
- PCT/KR2024/012559
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-08-22
- Publication Date
- 2025-05-30
AI Technical Summary
Anomaly detection models based on artificial neural networks are vulnerable to adversarial attacks, which compromise their ability to make accurate judgments, reducing their reliability.
An anomaly detection method that involves calculating a first anomaly score and pre-detecting anomalies, followed by calculating a second anomaly score and post-detecting anomalies if the pre-detection is uncertain, to enhance robustness against adversarial attacks.
The method effectively detects anomalies even in data subjected to adversarial attacks, improving the reliability and accuracy of anomaly detection compared to existing methods.
Smart Images

Figure KR2024012559_30052025_PF_FP_ABST
Abstract
Description
Anomaly Detection Methods Robust to Adversarial Attacks
[0001] The technique described below is about anomaly detection methods.
[0002] Anomaly detection technology refers to the technology that detects abnormal situations that are not normal. For example, anomaly detection technology may include detecting abnormal behavior or patterns occurring in a system or network. Alternatively, it may include detecting situations in which a machine device is malfunctioning. Recently, with the development of artificial intelligence technology based on artificial neural networks (ANNs), a branch of machine learning (ML), AI-based anomaly detection methods based on artificial neural networks are being developed. For example, there are technologies that input network traffic data into an ANN-based model and then determine whether there has been anomaly based on the output of the ANN model.
[0003] [Prior Art Literature]
[0004] [Patent Document]
[0005] (Patent Document 1) Korean Patent Publication No. 10-2023-0031117
[0006] One of the challenges of utilizing anomaly detection models based on artificial neural networks is adversarial attacks. Adversarial attacks attempt to deceive anomaly detection models by introducing subtle changes to input data. For example, an adversarial attack might involve injecting tiny noise, invisible to the human eye, into input data, leading to incorrect model judgments. Anomaly detection models are unable to accurately assess data subject to adversarial attacks, thereby reducing their reliability.
[0007] The technique described below aims to disclose an anomaly detection method that is robust to adversarial attacks.
[0008] A method for detecting anomalies robust to adversarial attacks includes: a step in which an anomaly detection device acquires data to be analyzed; a step in which the anomaly detection device calculates a first anomaly score for the data to be analyzed; a step in which the anomaly detection device pre-detects whether there is an anomaly in the data to be analyzed based on the first anomaly score; a step in which the anomaly detection device calculates a second anomaly score for the data to be analyzed if it is impossible to determine whether there is an anomaly in the data to be analyzed based on the pre-detection result; and a step in which the anomaly detection device post-detects whether there is an anomaly in the data to be analyzed based on the second anomaly score.
[0009] The techniques described below can be used to detect anomalies. For example, the techniques described below can be used to detect cyberattacks by detecting abnormal traffic from network traffic data.
[0010] The technology described below can detect anomalies even in data subjected to adversarial attacks. In other words, the technology described below enables anomaly detection methods that are robust against adversarial attacks. For example, the technology described below can be used to detect cyberattacks by detecting abnormal traffic in network traffic data subjected to adversarial attacks.
[0011] Figure 1 is an overall process in which an anomaly detection device (100) performs an anomaly detection method that is robust against adversarial attacks.
[0012] Figure 2 is a flowchart (200) of one embodiment of an anomaly detection method robust to adversarial attacks.
[0013] Figure 3 is one example of an anomaly detection method that is robust to adversarial attacks.
[0014] Figure 4 is one example of analysis target data input to an anomaly detection model.
[0015] Figure 5 shows the outlier scores for normal data, abnormal data, and adversarial data.
[0016] Fig. 6 is a configuration of one embodiment of an anomaly detection device (300).
[0017] The technology described below is susceptible to various modifications and embodiments. Specific embodiments of the technology described below may be illustrated in the drawings of the specification. However, these are intended to illustrate the technology described below and are not intended to limit the technology described below to any specific embodiments. Therefore, it should be understood that all modifications, equivalents, or alternatives that fall within the spirit and scope of the technology described below are encompassed by the technology described below.
[0018] Terms such as first, second, A, and B may be used to describe various components. However, these terms are only used to distinguish one component from other components and are not intended to limit the components. For example, without departing from the scope of the technology described below, the first component may be referred to as the second component, and similarly, the second component may also be referred to as the first component. The term "and / or" includes any combination of multiple related listed items or any one of multiple related listed items.
[0019] In the terms used hereinafter, singular expressions should be understood to include plural expressions unless the context clearly dictates otherwise, and terms such as "comprises" should be understood to mean the presence of a described feature, number, step, operation, component, part, or combination thereof, but not to exclude the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0020] Before going into a detailed description of the drawings, it should be made clear that the division of components in this specification is merely a division based on the main function of each component. That is, two or more components described below may be combined into one component, or one component may be further divided into two or more components with more detailed functions. In addition to its own main function, each component described below may additionally perform some or all of the functions of other components, and of course, some of the main functions of each component may be exclusively performed by other components.
[0021] In addition, in performing a method or method of operation, each process constituting the method may occur in a different order than the stated order unless the context clearly indicates a specific order. That is, each process may occur in the same order as the stated order, may be performed substantially simultaneously, or may be performed in the opposite order.
[0022] Below, we examine the overall process by which the anomaly detection device performs an anomaly detection method that is robust against adversarial attacks.
[0023] Figure 1 is an overall process in which an anomaly detection device (100) performs an anomaly detection method that is robust against adversarial attacks.
[0024] The anomaly detection device (100) can be physically implemented in various forms. For example, the anomaly detection device (100) can take the form of a PC, laptop, smart device, server, or data processing-dedicated chipset.
[0025] The anomaly detection device (100) can perform an anomaly detection method that is robust against adversarial attacks. The anomaly detection device (100) may be a device that acquires analysis target data and outputs anomaly detection results.
[0026] Specifically, the anomaly detection device (100) can obtain data to be analyzed. The anomaly detection device (100) can calculate a first anomaly score for the data to be analyzed. The anomaly detection device (100) can pre-detect whether there is an anomaly in the data to be analyzed based on the first anomaly score. If it is impossible to determine whether there is an anomaly in the data to be analyzed based on the pre-detection result, the anomaly detection device (100) can calculate a second anomaly score for the data to be analyzed. The anomaly detection device (100) can post-detect whether there is an anomaly in the data to be analyzed based on the second anomaly score.
[0027] Below, we describe in detail an anomaly detection method that is robust against adversarial attacks.
[0028] Figure 2 is a flowchart (200) of one embodiment of an anomaly detection method robust to adversarial attacks. Figure 3 is one example of how an anomaly detection method robust to adversarial attacks is performed.
[0029] The anomaly detection device can obtain analysis target data (210).
[0030] The data to be analyzed may be data required for anomaly detection using the techniques described below. In other words, the data to be analyzed may be data that is subject to analysis to detect anomalies.
[0031] For example, the data to be analyzed could be data measured from network traffic. Data measured when the network is operating normally could be considered normal data. Conversely, data measured when a network malfunction occurs (e.g., a cyber attack, traffic congestion) could be considered abnormal data. Another example could be data from machine operating noise. Data measured when the machine is operating normally could be considered normal data. Conversely, data measured when the machine is malfunctioning could be considered abnormal data.
[0032] The data being analyzed may include data subjected to adversarial attacks. An adversarial attack involves subtle changes to input data to deceive a model. For example, if anomalous data from an adversarial attack is input into a model, the model may interpret it as normal data. Therefore, it is necessary to build a model that is robust to adversarial attacks. The technology described below can effectively detect anomalies even in data subjected to adversarial attacks.
[0033] The data to be analyzed can have multiple feature values. The data to be analyzed can be multiple data. For example, the data to be analyzed can be n data with d feature values. In other words, the data to be analyzed (X) |R n X D It could be.
[0034] The anomaly detection device can calculate a first outlier score for the data to be analyzed (220).
[0035] The first outlier score can be used to determine whether the data being analyzed is normal or anomalous. For example, if the first outlier score is above a preset value, the data being analyzed can be considered anomalous. Conversely, if the first outlier score is below a preset value, the data being analyzed can be considered normal.
[0036] The first outlier score may be calculated based on the values calculated by the anomaly detection model after the data to be analyzed is entered into the anomaly detection model.
[0037] Anomaly detection models can be machine learning (ML)-based. Machine learning is a technological approach that enables computing devices to learn from data to understand specific objects or conditions, or to identify and classify patterns in data. Examples of machine learning-based models include decision trees, random forests, k-nearest neighbors (KNN), naive Bayes, support vector machines (SVMs), and artificial neural networks (ANNs).
[0038] Anomaly detection models can be based on artificial neural networks (ANNs). ANNs can be deep neural networks (DNNs). DNNs can also include convolutional neural networks (CNNs), recurrent neural networks (RNNs), restricted Boltzmann machines (RBMs), deep belief networks (DBNs), generative adversarial networks (GANs), and relational networks (RLs).
[0039] Anomaly detection models can be autoencoder-based. Autoencoder-based models can create a latent space from input data and then reconstruct the input data from that latent space.
[0040] Furthermore, the anomaly detection model can be based on a variational autoencoder (VAE). The encoder of a variational autoencoder can extract a mean vector and a variance vector from input data. The encoder of a variational autoencoder can form a latent space containing latent variables by sampling from a multivariate normal distribution corresponding to the mean vector and variance vector. The decoder of a variational autoencoder can utilize the latent variables within the latent space to generate output data that follows a distribution similar to the input data.
[0041] An anomaly detection model may be trained solely on normal data. Therefore, the anomaly detection model can handle normal data well. Conversely, it may not handle anomalous data well. For example, consider a variational autoencoder model. A variational autoencoder trained solely on normal data reconstructs data in a similar form to normal data when fed normal data. Conversely, a variational autoencoder trained solely on normal data cannot reconstruct anomalous data well when fed anomalous data. This is because it has never trained on anomalous data, but only on how to reconstruct normal data. Therefore, the first outlier score can be calculated by comparing the target data input to the anomaly detection model with the reconstructed data, which is the output of the anomaly detection model.
[0042] Mathematical Formula 1 is one of the formulas used to calculate the first outlier score. Mathematical Formula 1 is one of the formulas used to calculate the first outlier score based on the Mean Absolute Error (MAE).
[0043] [Mathematical Formula 1]
[0044]
[0045] In equation 1, x i is the i-th analysis target data (input data). In mathematical expression 1, x i is [ x (1) 1, x (2) 2, x (3) 3, ..., x (d) i ] can be. In mathematical formula 1 is the output value when the ith analysis target data is input to the anomaly detection model. In Equation 1, Is [ (1) 1, (2) 2, (3) 3, ..., (d) i ] can be. In mathematical expression 1, e(x i ) is the first outlier score for the i-th analysis target data. In Equation 1, d is the number of feature values (dimensions) of the analysis target data.
[0046] The anomaly detection device can preemptively detect whether there is an anomaly in the analysis target data based on the first anomaly score (230).
[0047] Anomaly detection models can be vulnerable to adversarial attacks on target data. For example, if an adversarial attack is performed on an anomaly detection model and the target data is input with a similar format to normal data, the anomaly detection model may reconstruct the input data to resemble normal data. In this case, the anomalous data may be mistakenly identified as normal. Therefore, it may be difficult to distinguish normal data from adversarial data based solely on the first outlier score. To address this issue, the technology described below divides anomaly detection into pre-detection and post-detection stages.
[0048] Pre-detection can be the process of detecting the presence of anomalies based on data for analysis that is easily determined or whose presence is certain. Specifically, pre-detection can involve determining whether anomalies can be clearly identified using only the first outlier score, and if so, classifying the data for analysis as normal or anomalous. Therefore, if pre-detection results do not clearly indicate anomalies, a post-detection process is used to determine whether anomalies exist. Data for analysis that cannot be determined during the pre-detection process are referred to as uncertain data. The post-detection process is described in detail below.
[0049] Pre-detection may include comparing the first outlier score to a first reference value and a second reference value. The first reference value may be greater than the second reference value (first reference value > second reference value).
[0050] In one embodiment, pre-detection may include a process of detecting an abnormality if the first outlier score is greater than (or equal to) a first reference value. Alternatively, pre-detection may include a process of detecting a normality if the first outlier score is less than (or below) a second reference value. Alternatively, pre-detection may include a process of determining that it is impossible to determine an abnormality if the first outlier score is less than (or below) the first reference value and greater than (or above) the second reference value.
[0051] Mathematical expression 2 is one of the expressions used in the pre-detection process.
[0052] [Equation 2]
[0053]
[0054] In Equation 2, t indicates whether there is an abnormality. In Equation 2, 0 indicates normal. In Equation 2, 1 indicates an abnormality. In Equation 2, 2 indicates a case where it is impossible to determine whether there is an abnormality. In Equation 2, δ u is the first reference value. In Equation 2, δ l is the second reference value. In mathematical expression 2, x i is the i-th analysis target data (input data). In mathematical expression 2, e(x i ) is the first outlier score for the i-th analysis target data.
[0055] If it is impossible to determine whether there is an anomaly in the target data for analysis based on the pre-detection results, the anomaly detection device can calculate a second anomaly score for the target data for analysis (240).
[0056] As mentioned above, cases where it's impossible to determine if there's an anomaly based on the pre-detection results may be those where it's impossible to definitively determine the presence of an anomaly using only the first outlier score. In other words, cases where it's impossible to determine if there's an anomaly based on the pre-detection results include cases where the first outlier score is below (less than) the first threshold and above (more than) the second threshold. Therefore, if it's possible to determine if there's an anomaly based on the pre-detection results, there's no need to calculate the second outlier score.
[0057] The second outlier score can be used to determine whether uncertain data is normal or anomalous. For example, if the second outlier score is above a preset value, the uncertain data can be judged as anomalous. Conversely, if the second outlier score is below a preset value, the uncertain data can be judged as normal.
[0058] The second outlier score may be calculated based on the Shapley Value.
[0059] In one embodiment, the second outlier score may be calculated based on a feature importance value based on a Shapley value. The feature importance value may include the degree to which each feature value included in the analysis target data influences anomaly detection. Specifically, the feature importance value may include the degree to which each feature value included in the analysis target data influences the anomaly detection model. For example, if the anomaly detection model is a variational autoencoder, the feature importance value may indicate how much each feature value contributed to creating a latent variable in the anomaly detection model based on the variational autoencoder.
[0060] Mathematical expression 3 is one of the equations used to calculate feature importance values.
[0061] [Equation 3]
[0062]
[0063] In mathematical formula 3, Φ jis the jth feature vector (f) for n input data. (j) ) is the feature importance value for the feature vector (f (j) ) is in vector form [ x (j) 1, x (j) 2, x (j) 3, ..., x (d) n ] can be (1<=j<=d). That is, the feature vector can be a vector created by extracting the jth feature value from n input data having d feature values, as in Fig. 4. In mathematical expression 3, N is a feature set. In mathematical expression 3, P ( N {j}) can be a subset excluding the j-th feature. In Equation 3, v ( . ) can be a value function.
[0064] The second outlier score may be calculated by comparing the data under analysis with normal data. In one embodiment, the second outlier score may be calculated based on the difference between the feature importance values for feature values included in the data under analysis and the feature importance values for feature values included in the normal data.
[0065] Mathematical expression 4 is one of the equations used to calculate the second outlier score.
[0066] [Equation 4]
[0067]
[0068] In mathematical formula 4, Φ i is the i-th analysis target data (x i ) is the feature importance value for Φ. In Equation 4, Φ i is [Φ (1) 1, Φ (2) 2, Φ (3) 3, … Φ (d) i ] can be. In Equation 4, Φ (j) i is the feature importance value for the jth feature value of the ith analysis target data. In Equation 4, (j)is the average feature importance value for the jth feature value of normal data. In Equation 4, e s (Φ i ) is the second outlier score for the i-th analysis target data. In Equation 4, d is the dimensionality of the feature importance value, which is the same as the dimensionality of the analysis target data.
[0069] The anomaly detection device can post-detect whether there is an anomaly in the analysis target data based on the second anomaly score (250).
[0070] Post-detection may include the process of determining whether there are any anomalies in uncertain data that could not be determined to be anomalies during the pre-detection process.
[0071] Post-detection may include a process performed by comparing the second outlier score with a third reference value.
[0072] In one embodiment, post-detection may include detecting an abnormality if the second outlier score is greater than (or equal to) a third reference value. Alternatively, post-detection may include detecting a normality if the second outlier score is less than (or equal to) a third reference value.
[0073] Mathematical expression 5 is one of the expressions used in the post-detection process.
[0074] [Equation 5]
[0075]
[0076] In Equation 5, t s is an abnormality. In Equation 5, 0 is normal. In Equation 5, 1 is abnormal. In Equation 5, δ s is the third reference value. In Equation 5, e s (Φ i ) is the second outlier score for the i-th analysis target data.
[0077] Below, we build an anomaly detection model and examine the experimental results of detecting anomalies using the built anomaly detection model.
[0078] The dataset used in the experiment is the NSL-KDD dataset. NSL-KDD is a dataset used for network intrusion detection.
[0079] The anomaly detection model used in the experiment is a variational autoencoder. The variational autoencoder has n analysis target data (X) with d (d=40) feature values. |R n X d ) can be input. The variational autoencoder can have m (m=20) hidden layer nodes. The variational autoencoder can extract the mean vector and variance vector from the analysis target data (X). The variational autoencoder samples from the multivariate normal distribution corresponding to the mean vector and variance vector to extract the latent variable (Z). |R m X d ) can be generated. The variational autoencoder utilizes the generated latent variable (Z) to generate output data ( |R n x d ) can be created.
[0080] To construct data on which adversarial attacks are performed, the Fast Gradient Sign Method (FGSM) can be used. FGSM can be a method for quickly generating adversarial examples by updating data in just one step.
[0081] Figure 5 shows outlier scores for normal, abnormal, and adversarial data. Figure 5(a) shows the first outlier score. Figure 5(b) shows the second outlier score. Adversarial data is data subjected to an adversarial attack, adding noise that humans cannot distinguish from abnormal data.
[0082] As shown in Figure 5(a), the distributions of the first outlier scores for normal and abnormal data differ. Therefore, normal and abnormal data can be distinguished based on the first outlier score. On the other hand, the distributions of the first outlier scores for normal and adversarial data are very similar. It is difficult to distinguish normal and adversarial data based on the first outlier score.
[0083] As shown in Figure 5(b), the distributions of the second outlier scores for normal and abnormal data differ. Therefore, normal and abnormal data can be distinguished based on the second outlier score.
[0084] Table 6 shows the performance evaluation results of the anomaly detection model.
[0085] AccuracyPrecisionRecallF1- scoreBaseline0.78740.80040.90750.8506Proposed0.93430.93710.96630.9515
[0086] The anomaly detection accuracy of the existing method (Baseline) is 0.7874, precision is 0.8004, recall is 0.9075, and F1-score is 0.8506.
[0087] On the other hand, the hierarchical anomaly detection method (Proposed) that is robust to adversarial attacks has an accuracy of 0.9343, a precision of 0.9371, a recall of 0.9663, and an F1-score of 0.9515.
[0088] It can be confirmed that the performance of the hierarchical anomaly detection method described above is improved compared to the existing anomaly detection method.
[0089] Below is a description of the anomaly detection device.
[0090] Fig. 6 is a configuration of one embodiment of an anomaly detection device (300).
[0091] The anomaly detection device (300) of Fig. 6 may correspond to the anomaly detection device (100) described in Fig. 1. That is, the anomaly detection device (300) of Fig. 6 may be a device that performs the anomaly detection method that is robust to the aforementioned hostile attack.
[0092] The anomaly detection device (300) may include an input device (310), a storage device (320), a calculation device (330), an output device (340), an interface device (350), and a communication device (360).
[0093] The input device (310) may include an interface device (keyboard, mouse, touch screen, etc.) that receives a specific command or data. The input device (310) may also include a configuration that receives information through a separate storage device (USB, CD, hard disk, etc.). The input device (310) may receive the input data through a separate measuring device or a separate database. The input device (310) may also receive data through wired or wireless communication through a communication device (360).
[0094] The input device (310) can receive information necessary for performing the aforementioned robust anomaly detection method against adversarial attacks. The input device (310) can receive a model necessary for performing the aforementioned robust anomaly detection method against adversarial attacks. The input device (310) can receive analysis target data. The input device (310) can receive an anomaly detection model.
[0095] The storage device (320) may be a device that stores certain information. The storage device (320) may store information input through the input device (310). The storage device (320) may store information generated during the operation of the calculation device (330). In other words, the storage device (320) may include a memory.
[0096] The storage device (320) can store information necessary for performing the aforementioned robust anomaly detection method against adversarial attacks. The storage device (320) can store models necessary for performing the aforementioned robust anomaly detection method against adversarial attacks. The storage device (320) can store analysis target data. The storage device (320) can store an anomaly detection model.
[0097] The computing device (330) may be a device such as a processor, AP, or a chip embedded with a program that processes data and performs certain operations. The computing device (330) may generate a control signal that controls the anomaly detection device (300). The computing device (330) may generate a control signal that controls the input device (310), storage device (320), output device (340), interface device (350), and communication device (360) included in the anomaly detection device (300).
[0098] The computational unit (330) can perform the computations necessary to perform the above-described robust anomaly detection method against adversarial attacks. The computational unit (330) can calculate a first outlier score for the data to be analyzed. Based on the first outlier score, the computational unit (330) can pre-detect whether the data to be analyzed has an anomaly. If the pre-detection result does not determine whether the data to be analyzed has an anomaly, the computational unit (330) can calculate a second outlier score for the data to be analyzed. Based on the second outlier score, the computational unit (330) can post-detect whether the data to be analyzed has an anomaly.
[0099] The output device (340) may be a device that outputs certain information. The output device (340) may output interfaces required for data processing, input data, analysis results, etc. The output device (340) may be physically implemented in various forms, such as a display, a device that outputs documents, a speaker, etc. The output device (340) may output information stored in the storage device (330). The output device (340) may output information generated during the process of calculation by the calculation device (330). The output device (340) may output the result of the calculation by the calculation device (330). The output device (340) may output the result of anomaly detection.
[0100] The interface device (350) may be a device that receives certain commands and data from the outside. The interface device (350) may receive a control signal for controlling the anomaly detection device (300). The interface device (350) may output the results analyzed by the anomaly detection device (300). The interface device (350) may receive information necessary for performing the anomaly detection method robust to the aforementioned hostile attack from a physically connected input device or an external storage device.
[0101] The communication device (360) may refer to a configuration that receives and transmits certain information via a wired or wireless network. The communication device (360) may perform network communication such as Wi-Fi (Wireless Fidelity), Wi-Fi Direct, Bluetooth, UWB (Ultra Wide Band), NFC (Near Field Communication), USB (Universal Serial Bus), HDMI (High Definition Multimedia Interface), LAN (Local Area Network), etc. The communication device (360) may receive a control signal necessary to control the anomaly detection device (300). The communication device (360) may transmit the results analyzed by the anomaly detection device (300). The communication device (360) may receive information necessary to perform the anomaly detection method that is robust to the aforementioned adversarial attack. The communication device (360) may receive a model necessary to perform the anomaly detection method that is robust to the aforementioned adversarial attack.
[0102] The above-described robust anomaly detection method against adversarial attacks can be implemented as a program (or application) comprising an executable algorithm that can be run on a computer.
[0103] The above program may be provided stored on a non-transitory computer readable medium.
[0104] The above-mentioned temporarily readable medium refers to various RAMs such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous DRAM (Synclink DRAM, SLDRAM), and direct Rambus RAM (DRRAM).
[0105] The above non-transitory readable medium refers to a medium that stores data semi-permanently and can be read by a device, rather than a medium that stores data for a short period of time, such as a register, cache, or memory. Specifically, the various applications or programs described above may be stored and provided in a non-transitory readable medium, such as a CD, DVD, hard disk, Blu-ray disk, USB, memory card, ROM (read-only memory), PROM (programmable read only memory), EPROM (Erasable PROM, EPROM), EEPROM (Electrically EPROM), or flash memory.
[0106] The present embodiment and the drawings attached to the present specification only clearly illustrate a part of the technical idea included in the above-described technology, and it will be obvious that all modified examples and specific embodiments that can be easily inferred by a person skilled in the art within the scope of the technical idea included in the specification and drawings of the above-described technology are included in the scope of the rights of the above-described technology.
Claims
1. A step in which an anomaly detection device acquires data to be analyzed; A step in which the above anomaly detection device calculates a first anomaly score for the analysis target data; A step in which the above anomaly detection device pre-detects whether there is an anomaly in the analysis target data based on the first anomaly score; If it is impossible to determine whether there is an abnormality in the analysis target data as a result of the above detection, the step of the above abnormality detection device calculating a second abnormality score for the analysis target data; and An anomaly detection method robust to adversarial attacks, comprising: a step of post-detecting, by the anomaly detection device, whether there is an anomaly in the analysis target data based on the second anomaly score; 2. In paragraph 1, The above analysis target data is an anomaly detection method robust to adversarial attacks, which includes data on which an adversarial attack has been performed.
3. In paragraph 1, The above analysis target data is an anomaly detection method that is robust to adversarial attacks and has multiple feature values.
4. In paragraph 1, The above first outlier score is calculated based on a value calculated by the anomaly detection model after inputting the analysis target data into the anomaly detection model, and is an anomaly detection method robust to adversarial attacks.
5. In paragraph 4, The above anomaly detection model is an anomaly detection method that is robust to adversarial attacks, and is based on an autoencoder or variational autoencoder (VAE).
6. In paragraph 1, The above detection includes a process of comparing the first outlier score with a first reference value and a second reference value, An anomaly detection method robust to adversarial attacks, wherein the first threshold value is greater than the second threshold value.
7. In paragraph 6, An anomaly detection method robust to adversarial attacks, wherein the above detection includes a process of detecting an anomaly when the first anomaly score exceeds or is higher than the first reference value.
8. In paragraph 6, An anomaly detection method robust to adversarial attacks, wherein the above detection includes a process of detecting as normal if the first anomaly score is less than or equal to the second reference value.
9. In paragraph 6, An anomaly detection method robust to adversarial attacks, including a case where it is impossible to determine whether the above detection result is abnormal, wherein the first anomaly score is less than or below the first reference value and more than or above the second reference value.
10. In paragraph 1, An anomaly detection method robust to adversarial attacks, wherein the second outlier score is calculated based on the Shapley value.
11. In paragraph 10, The above second outlier score is calculated based on the feature importance value based on the Shapley value, An anomaly detection method robust to adversarial attacks, wherein the above feature importance value includes the degree to which each feature value included in the above analysis target data affects anomaly detection.
12. In paragraph 11, An anomaly detection method robust to adversarial attacks, wherein the above feature importance value is calculated using the following mathematical formula 3. [Mathematical Formula 3] In the above mathematical expression 3, Φ j is the jth feature vector (f) for n input data. (j) ) is the feature importance value for the feature vector (f). (j) ) is in vector form [ x (j) 1 , x (j) 2 , x (j) 3 , ..., x (d) n ] is (1<=j<=d). The above feature vector is a vector created by extracting the jth feature value from n input data having d feature values. In the above mathematical expression 3, N is a feature set. In mathematical expression 3, P ( N {j}) can be a subset excluding the jth feature. In the above mathematical expression 3, v ( . ) is a value function.
13. In paragraph 1, An anomaly detection method robust to adversarial attacks, wherein the second outlier score is calculated by comparing the analysis target data with normal data.
14. In paragraph 13, An anomaly detection method robust to adversarial attacks, wherein the second outlier score is calculated based on the difference between the feature importance value for the feature value included in the analysis target data and the feature importance value for the feature value included in the normal data.
15. In paragraph 14, An anomaly detection method robust to adversarial attacks, wherein the second outlier score is calculated using the following mathematical expression 4. [Mathematical formula 4] In the above mathematical expression 4, Φ i is the i-th analysis target data (x i ) is the feature importance value for Φ in the above mathematical expression 4. i is [Φ (1) 1 , Φ (2) 2 , Φ (3) 3 , … Φ (d) i ] can be. In the above mathematical expression 4, Φ (j) i is the feature importance value for the jth feature value of the ith analysis target data. In the mathematical expression 4 above, (j) is the average feature importance value for the jth feature value of normal data. In the above mathematical expression 4, e s (Φ i ) is the second outlier score for the i-th analysis target data. In the mathematical expression 4 above, d is the dimensionality of the feature importance value, which is the same as the dimensionality of the analysis target data.
16. In paragraph 1, An anomaly detection method robust to adversarial attacks, wherein the post-detection comprises a process of comparing the second outlier score with a third reference value.
17. Input device for receiving data to be analyzed; A computing device that calculates a first outlier score for the above analysis target data, pre-detects whether there is an abnormality in the analysis target data based on the first outlier score, and if it is impossible to determine whether there is an abnormality in the analysis target data based on the pre-detection result, the anomaly detection device calculates a second outlier score for the analysis target data, and post-detects whether there is an abnormality in the analysis target data based on the second outlier score; and An anomaly detection device, comprising a storage device storing the above analysis target data.
18. A computer-readable recording medium having recorded thereon a program for executing an anomaly detection method robust to adversarial attacks as described in Article 1.
Citation Information
Patent Citations
Method, device, and computer program product for protecting deep neural network (DNN) (detecting adversary attack on dnn
JP2022080285A
SYSTEM AND METHOD FOR DETECTING ADVERSARY ATTACKS - Patent application
JP2023518331A
Manufacturing method of display device and display device manufactured using the same
KR1020210052725A
3D memory device and method of forming seal structure
KR1020240062875A
Charger latch support apparatus
KR1020240125372A