Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5results about How to "Improve attack efficiency" patented technology

Simulation attack-defense method for power grid load frequency control system with DRL controller

PendingCN122225434Aimprove performanceImprove attack efficiencyBiological modelsSecuring communication
The application relates to the field of power systems and artificial intelligence security, and discloses a simulation attack and defense method of a power grid load frequency control system adopting a DRL controller, which comprises the following steps of: simulation attack: identifying system state variables most critical to DRL decision; setting an attack target and calculating an initial disturbance amount of the critical state variables, limiting the generation of a final disturbance amount; deducing disturbance amounts of the remaining dependent state variables to obtain an adversarial disturbance vector, which is superimposed to the DRL controller to implement the attack. Simulation defense: applied to a hybrid system containing DRL and a backup PID controller: real-time monitoring of the Q value sequence output by the DRL evaluation network to detect whether it is continuously lower than the normal benchmark; once the statistical quantity exceeds the threshold, it is determined that an attack is suffered, and the control right is immediately switched from the DRL to the PID controller to maintain the stability of the system. The method can generate a hidden and physically regular adversarial attack to evaluate the vulnerability of the system, and provide a fast and low-cost active defense mechanism to improve the security and resilience of the LFC system in the adversarial environment.
Owner:GUIZHOU UNIV

An extensible artificial intelligence attack benchmarking method and system

ActiveCN117312119BResolve the model under testSolve the problem of language restrictionsData setAlgorithm
This invention provides an scalable AI attack benchmark testing method and system. A model conversion module transforms the tested model according to its type and framework, obtaining a converted model that matches the attack framework. The dataset attacks the converted model, yielding a test result. The attack framework invokes various attack algorithms with a standardized format, generates corresponding attack scripts, and then performs several attacks on the converted model, resulting in multiple attack results. When testing the next tested model, the model conversion module again transforms its framework according to its type before launching the attack. The advantages are: it can flexibly convert for different AI models, attacking the converted model to obtain attack results, without needing to rebuild test modules for different AI models, improving attack efficiency, reducing testing costs, and solving the problem of existing testing methods (frameworks) being limited by the tested model and language.
Owner:北京银联金卡科技有限公司

A method, system, storage medium, and terminal for generating adversarial examples

This invention discloses an adversarial example generation method, system, storage medium, and terminal, belonging to the field of adversarial attack technology. The method includes: determining the context region of a target object and dividing it into multiple sub-regions; performing importance analysis on each sub-region; mapping the influence of each sub-region on the detection results of the target detection model to the context region, generating a context attribution graph; selecting one or more influential sub-regions exceeding an influence threshold; and fine-tuning the influential sub-regions under a total loss function (including a loss function and a perceptual loss function) to generate adversarial examples. This invention accurately guides the attack direction through the context attribution graph and introduces a dual loss function, suppressing position, direction, and confidence prediction while ensuring the visual imperceptibility of adversarial perturbations, thus preserving the integrity of the target object and enhancing the stealth of the attack. Attacking only some influential sub-regions improves attack efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Method and device for evaluating robustness of diffusion-based purification model

PendingCN121999264AImprove attack efficiencyeasy to understandNeural learning methodsEngineeringSample image
The embodiment of the invention discloses a method and device for evaluating robustness of a diffusion-based purification model. The specific implementation mode of the method comprises the steps that random purification is carried out on a noise image for a first number of times through a purification model, a first number of purification results are obtained, and the noise image is obtained after adversarial noise is superimposed on a sample image; determining a first number of classification results according to the first number of purification results through a classifier; determining a loss value and a gradient in each random purification process based on the difference between each classification result and the actual category of the sample image; determining a representative random purification process based on the loss value and gradient in each random purification process; performing reverse gradient propagation based on a representative random purification process, and determining a target gradient; and attacking the purification model based on the target gradient, and determining the robustness of the purification model. According to the embodiment, the accuracy of evaluating the robustness of the diffusion-based purification model is improved.
Owner:THE HONG KONG UNIV OF SCI & TECH

A method and system for adversarial attack on an image quality assessment model based on a heat map guide

PendingCN122597406AEnhanced description abilityImprove analytical performance
The application provides a heat map guidance-based image quality evaluation model attack method and system, and belongs to the technical field of black-box attack. The method comprises the following steps: S1, obtaining an original image and a target image quality evaluation model, setting a perturbation constraint and a query parameter, generating an initial adversarial sample and initializing a sensitivity heat map; S2, selecting an image perturbation region according to the sensitivity heat map, updating the perturbation in combination with a dynamic scheduling strategy, generating a candidate adversarial sample and obtaining a model output; S3, performing reward, punishment and smoothing update on the sensitivity heat map according to the target function change of the candidate sample and the current sample; and S4, outputting a final adversarial sample when a termination condition is reached. The application can effectively solve the problems of low attack success rate, poor query efficiency and insufficient generalization ability of the existing adversarial attack method in the image quality evaluation task, and provides technical support for the robustness test, security evaluation and defense mechanism design of the image quality evaluation model.
Owner:CHONGQING UNIV