Anti-sample defense method, device, system and storage medium
A technology against samples and storage media, applied in the security field, can solve problems such as deceiving artificial intelligence systems, speech recognition system recognition errors, and judgment errors
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
no. 1 example
[0042]Please refer tofigure 2 ,figure 2 This is a flowchart of a method for defending against samples provided by the first embodiment of the present invention. The method is applied tofigure 1 The electronic device 100 shown, the following willfigure 2 The illustrated process is elaborated, and the method includes:
[0043]S100: Obtain raw data to be processed.
[0044]Wherein, the original data may be separate image data, for example, the original data may be a picture of an apple, a picture of a human face, etc., wherein the original data is content directly observed by the human eye, and It is not the content recognized by the image recognition system; the original data can also be separate audio data. For example, the original data can be a voice of "hello", a voice of "power on", etc. The original data is passed through The sound directly heard by human ears is not the voice recognized by the voice recognition system; the original data may also be video data including both image dat...
no. 2 example
[0087]Please refer toimage 3 ,image 3 It is a structural block diagram of a defense device 400 against samples provided by the second embodiment of the present invention. The device is stored asfigure 1 The electronic device 100 will be described belowimage 3 The structure shown in the block diagram is illustrated, and the shown device includes:
[0088]The first acquiring unit 410 is configured to acquire raw data to be processed.
[0089]The second acquiring unit 420 is configured to acquire a feature vector used to characterize the original data.
[0090]The matching unit 430 is configured to match the feature vector with the pre-stored feature vector of the normal sample and the feature vector of the adversarial sample to obtain a matching result, wherein the adversarial sample represents data after normal data is destroyed.
[0091]The processing unit 440 is configured to process the original data when the matching result indicates that the feature vector belongs to the feature vector of t...
no. 3 example
[0101]Please refer toFigure 4,Figure 4It is a structural block diagram of a defense system against samples provided by the third embodiment of the present invention. The system includes: a recognition system 500 and the device 400 described in the second embodiment, the device is connected to the recognition system 500, and the original data After being processed by the anti-sample defense device, it is input to the recognition system 500. Wherein, the recognition system 500 is an image recognition system and / or a voice recognition system, the recognition system 500 may be an image recognition system alone, the recognition system 500 may be a voice recognition system alone, and the recognition system 500 may include both an image recognition system and a voice recognition system.
[0102]In addition, the embodiment of the present invention also provides a storage medium in which a computer program is stored. When the computer program runs on a computer, the computer is caused to execut...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


