Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8results about How to "Improve attack success rate" patented technology

Active Learning-Based Data-Free Black-Box Attack Method and System Based on Multidimensional Value Assessment

This invention relates to an active learning-based data-free black-box attack method and system based on multidimensional value assessment, belonging to the field of artificial intelligence security technology. This method constructs a pre-emptive "sample screening funnel," utilizing a local substitution model to perform multidimensional assessments of sample boundary approximation, information uncertainty, and geometric diversity before sending images to a commercial cloud API. Only high-value samples are selected for querying, thereby achieving low-cost, high-efficiency model theft and adversarial attacks. This invention ensures the diversity and training stability of data-free generated samples, significantly improves the transfer success rate of adversarial examples, and achieves "low-cost, low-risk" economical attacks. It has strong versatility and can be seamlessly integrated into various existing data-free attack frameworks, facilitating deployment and implementation in practical security assessment systems.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

An adversarial sample generation method based on AdvDrop

The application discloses an adversarial sample generation method based on AdvDrop, relates to the technical field of machine learning security, and processes two different branches of an image input space domain and a frequency domain; for the frequency domain attack AdvDrop, first, the input image is segmented into N*N blocks, and discrete cosine transform (DCT) is used on each block to convert them to the frequency domain; a quantization matrix M is introduced to reduce some specific frequencies of the transformed image; a tangent function is introduced in the quantization process to gradually approach the quantization function, and then the quantization matrix M is accurately adjusted through the new quantization function; then, the image is converted from the frequency domain to the space domain through inverse discrete cosine transform (IDCT) operation; finally, the space domain attack and the frequency domain attack fusion module are used to iteratively update the adversarial perturbation by using the gradients from different fields, and the adversarial sample is generated; the quality of the generated adversarial sample is improved, the difference between the distribution characteristics of the adversarial sample and the distribution characteristics of the real sample is reduced, and the attack success rate is improved.
Owner:GUANGDONG UNIV OF TECH

A method for generating adversarial examples for voiceprint recognition

ActiveCN115620730BImprove robustnessImprove attack success rateSpeech analysisMachine learningAlgorithmBox model
This invention relates to the field of artificial intelligence security and discloses a method for generating adversarial examples for voiceprint recognition. It integrates multiple existing voiceprint recognition models to generate a substitute model to replace the target black-box voiceprint recognition model. Adversarial examples are generated by attacking the substitute model, thereby attacking the target black-box model. This overcomes the difficulty of obtaining model information from a black-box model and improves the low success rate of attacks. In generating adversarial examples, a Nesterov-based accelerated gradient method is used, which can find adversarial examples with better attack effects more quickly. During the generation of adversarial examples, the target black-box model is queried a small number of times to correct the direction of adversarial example generation, thus improving the success rate of the attack.
Owner:GUANGZHOU UNIVERSITY

Backdoor attack methods, systems, and media based on text-to-image diffusion models with multi-object semantic coexistence.

PendingCN122090449AImproved visual concealmentImprove attack success rateBiological modelsCharacter and pattern recognitionData setImage diffusion
This invention discloses a backdoor attack method, system, and medium based on multi-object semantic coexistence in text-to-image diffusion models. This method utilizes the perspective of multi-object semantic coexistence in text-to-image diffusion models to develop MOBA backdoor attack schemes. First, by constructing a trigger alignment dataset and optimizing backdoor implantation and semantic preservation in parallel, the attack success rate and visual concealment are effectively improved, reducing the impact of semantic corruption on attack effectiveness. Second, during model training, an attention-based decoupling backdoor enhancement mechanism is adopted. By decoupling the attention regions of different objects, the semantic integrity of the input prompt is maintained while the backdoor is activated and the attention distribution is reasonably adjusted to reduce the impact of generation bias on attack concealment. The method of this invention ensures both visual concealment and model performance under benign input while achieving efficient backdoor attacks.
Owner:HUNAN UNIV OF SCI & TECH SANYA RES INST

A white-box adversarial sample generation method and system for a liquid state machine

PendingCN122287702AEffective white box attackavoid queryAlgorithmForward propagation
This invention relates to a white-box adversarial example generation method and system for liquid state machines, belonging to the field of neural network security. It aims to address the problem that existing methods cannot effectively handle non-differentiable cyclic components and gradient calculation failures caused by random pulse coding in liquid state machines. The method constructs a computable and stable gradient propagation path from model loss to the original input through gradient splitting and time-averaged gradient approximation. It includes a cyclic process of forward propagation and backward gradient calculation. The corresponding system includes a data input and preprocessing module, a target model loading and inference module, a gradient calculation module, an attack algorithm integration module, and an adversarial example synthesis and feedback module. This invention achieves an effective white-box attack on liquid state machines for the first time, with advantages such as high attack success rate, good perturbation concealment, and strong scalability, providing a powerful tool for evaluating the security of spiking neural networks.
Owner:NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI

Transferable adversarial sample generation method and device based on wavelet transform and multi-scale filling, and storage medium

PendingCN121982451AImprove migration abilityPrecisely expose security vulnerabilitiesCharacter and pattern recognitionBiological modelsAlgorithmEngineering
The invention relates to a transferable adversarial sample generation method and device based on wavelet transform and multi-scale filling, and a storage medium, and the method comprises the following steps: obtaining an input image, converting the input image from a spatial domain to a frequency domain through wavelet transform, and carrying out the random block disruption of a high-frequency component block, and obtaining a preprocessed image; mI-FGSM-based sample updating is performed on the preprocessed image, and in the updating process, a global random multi-scale filling method is used, MI-FGSM input is transformed from multiple angles of a space domain and a frequency domain, a plurality of substitution models are combined, combined gradient loss is calculated, and training is performed to obtain an adversarial sample. Compared with the prior art, the method has the advantages of remarkably improving the migration capability of the adversarial sample among the black box models, improving the attack success rate and the like.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

Frame-level alignment boundary adversarial attack method, system, device and equipment for sequence recognition model and medium

ActiveCN121744272BImprove attack success rateImprove production efficiencyProgram/content distribution protectionPattern recognitionMargin (machine learning)
The application provides a frame-level alignment boundary adversarial attack method, system, device and equipment for a sequence recognition model and a medium, and belongs to the fields of computer vision, speech processing and adversarial machine learning. The method comprises the following steps: S1: inputting a sample into a target sequence recognition model in a test stage to obtain an initial reference alignment label sequence; S2: based on the initial reference alignment label sequence, constructing an alignment boundary margin between a reference alignment label and a competitive label; S3: based on the alignment boundary margin, generating a dynamic continuous gating weight by using a smoothing mapping, constructing a margin optimization target with gating weighting and iteratively updating to obtain a candidate adversarial sample; and S4: performing total variation (TV) smoothing under a success maintaining constraint and amplitude scaling search on the candidate adversarial sample to generate a high-fidelity adversarial sample. The application can improve the adversarial attack efficiency and success rate and can be used in sequence recognition model robustness evaluation and privacy protection, copyright protection and the like.
Owner:DONGHUA UNIV +1

Unmanned aerial vehicle image detection confrontation sample generation method and system based on black box normal form

The invention discloses an unmanned aerial vehicle image detection confrontation sample generation method and system based on a black box normal form. The method comprises the steps of S1, candidate region generation: extracting multi-scale features from an input unmanned aerial vehicle image, and generating a candidate region set containing potential target frame coordinates through feature fusion and transformation; s2, target category retrieval and allocation: allocating a target category with the highest attack efficiency to each candidate region in the candidate region set based on pre-constructed object category correlation prior information to form a target category set; and S3, adversarial sample generation: combining the candidate region set with the target category set, generating a virtual instance set, and adding the virtual instance set into the original input image to obtain a final adversarial sample image. According to the method, efficient black box attacks are realized, calculation delay and energy consumption are innovatively induced, the attack pertinence is high, the concealment is high, the attack success rate is improved, the adaptability is high, and a new view angle is provided for security assessment and defense.
Owner:安徽明生恒卓科技有限公司 +1