Abstract
Convolutional neural networks (CNN) have been widely used in myoelectric control field, such as prosthesis control, physical rehabilitation and human-computer interaction. Nevertheless, it was found that CNN models are very easily tricked by adversarial instances, which are normal instances with tiny intentional perturbations. In this study, an attack framework based on universal adversarial perturbations (UAP) was proposed to attack the CNN-based myoelectric control system. The performance of the proposed framework was evaluated with data recorded by a High-density surface EMG electrode array of 8 subjects during performing 6 finger and wrist extension movements. The experiment results demonstrated the effectiveness of two adversarial attack algorithms including DeepFool-based UAPs and Total Loss Minimization-based UAPs on the CNN-based EMG gesture recognition network for both target and non-target attacks. To our knowledge, this is the first work on the vulnerability of the CNN classifier in EMG-based gesture recognition system, which hopefully can draw more attention to the security of muscle-computer interface.
Supported by the National Key Research and Development Program of China under Grant 2018YFB1005001, the National Natural Science Foundation of China under Grant 61922075 and the USTC Research Funds of the Double First-Class Initiative under Grant YD2100002004.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
References
Oskoei, M.A., Hu, H.: Myoelectric control systems-a survey. Biomed. Signal Process. Control 2(4), 275–294 (2007)
Yang, X., Chen, X., Cao, X., Wei, S., Zhang, X.: Chinese sign language recognition based on an optimized tree-structure framework. IEEE J. Biomed. Health Inform. 21(4), 994–1004 (2016)
Park, K.H., Lee, S.W.: Movement intention decoding based on deep learning for multiuser myoelectric interfaces. In: 2016 4th international winter conference on brain-computer Interface (BCI), pp. 1–2. IEEE (2016)
Zhang, X., Wu, D.: On the vulnerability of CNN classifiers in EEG-based BCIS. IEEE Trans. Neural Syst. Rehabil. Eng. 27(5), 814–825 (2019)
Geng, W., Du, Y., Jin, W., Wei, W., Hu, Y., Li, J.: Gesture recognition by instantaneous surface EMG images. Sci. Rep. 6(1), 1–8 (2016)
Ding, Z., Yang, C., Tian, Z., Yi, C., Fu, Y., Jiang, F.: SEMG-based gesture recognition with convolution neural networks. Sustainability 10(6), 1865 (2018)
Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)
Kurakin, A., Goodfellow, I., Bengio, S., et al.: Adversarial examples in the physical world (2016)
Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P.: Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2574–2582 (2016)
Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39–57. IEEE (2017)
Baluja, S., Fischer, I.: Adversarial transformation networks: learning to generate adversarial examples. arXiv preprint arXiv:1703.09387 (2017)
Liu, Z., Zhang, X., Meng, L., Wu, D.: Universal adversarial perturbations for CNN classifiers in EEG-based BCIS. arXiv preprint arXiv:1912.01171 (2019)
Zhang, X., Wu, L., Yu, B., Chen, X., Chen, X.: Adaptive calibration of electrode array shifts enables robust myoelectric control. IEEE Trans. Biomed. Eng. 67(7), 1947–1957 (2019)
LeCun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. Proc. IEEE 86(11), 2278–2324 (1998)
Chen, X., Li, Y., Hu, R., Zhang, X., Chen, X.: Hand gesture recognition based on surface electromyography using convolutional neural network with transfer learning method. IEEE J. Biomed. Health Inform. 25(4), 1292–1304 (2020)
Atzori, M., Cognolato, M., Müller, H.: Deep learning with convolutional neural networks applied to electromyography data: a resource for the classification of movements for prosthetic hands. Front. Neurorobot. 10, 9 (2016)
Tam, S., Boukadoum, M., Campeau-Lecours, A., Gosselin, B.: A fully embedded adaptive real-time hand gesture classifier leveraging HD-SEMG and deep learning. IEEE Trans. Biomed. Circuits Syst. 14(2), 232–243 (2019)
Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1765–1773 (2017)
Athalye, A., Carlini, N., Wagner, D.: Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In: International Conference on Machine Learning, pp. 274–283. PMLR (2018)
Chen, J., Meng, Z., Sun, C., Tang, W., Zhu, Y.: ReabsNet: detecting and revising adversarial examples. arXiv preprint arXiv:1712.08250 (2017)
Abbasi, M., Gagné, C.: Robustness to adversarial examples through an ensemble of specialists. arXiv preprint arXiv:1702.06856 (2017)
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2021 Springer Nature Switzerland AG
About this paper
Cite this paper
Xue, B., Wu, L., Liu, A., Zhang, X., Chen, X. (2021). White-Box Attacks on the CNN-Based Myoelectric Control System. In: Fang, L., Chen, Y., Zhai, G., Wang, J., Wang, R., Dong, W. (eds) Artificial Intelligence. CICAI 2021. Lecture Notes in Computer Science(), vol 13069. Springer, Cham. https://doi.org/10.1007/978-3-030-93046-2_13
Download citation
DOI: https://doi.org/10.1007/978-3-030-93046-2_13
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-030-93045-5
Online ISBN: 978-3-030-93046-2
eBook Packages: Computer ScienceComputer Science (R0)