White box adversarial sample generation method for scene character recognition model

An adversarial sample, text recognition technology, applied in character and pattern recognition, neural learning methods, biological neural network models, etc., can solve the problems of time-consuming and unstable that cannot meet the time-consuming and unstable adversarial sample image confrontation attack, and avoid time-consuming and instability, ensuring robustness, and improving confidence

Pending Publication Date: 2020-07-31
BEIJING YUNJIANG TECH CO LTD
View PDF16 Cites 15 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0008] In order to solve the above-mentioned problems in the prior art, that is, in order to solve the problem that the existing white-box attack algorithm cannot meet the needs of the scene text recognition model based on the attention mechanism to generate ad...

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • White box adversarial sample generation method for scene character recognition model
  • White box adversarial sample generation method for scene character recognition model
  • White box adversarial sample generation method for scene character recognition model

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0044] In order to make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than Full examples. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0045] The application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain related inventions, not to limit the invention. It should also be noted that, for the convenience of description, only the parts related to the related invention are sho...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention belongs to the technical field of scene character recognition and white box attack, particularly relates to a white box confrontation sample generation method, system and device for a scene character recognition model, and aims to solve the problems that an existing white box attack algorithm cannot meet requirements and is long in attack time and unstable. The method comprises the following steps: acquiring a to-be-attacked image, and generating an adversarial sample image in combination with disturbance; obtaining a recognition result of the adversarial sample image through a scene character recognition model, judging whether the image is successfully attacked or not based on the result, and taking the image as an optimal adversarial sample image if the image is successfully attacked and the disturbed matrix norm is reduced; otherwise, judging whether the number of iterations is less than a set maximum number of iterations: if so, updating the disturbance and adversarial sample image, and otherwise, outputting an optimal adversarial sample image. According to the method, the white box adversarial sample generation requirement for the scene character recognition model is met, and time consumption and instability of an attack algorithm are avoided through gradient cutting.

Description

technical field [0001] The invention belongs to the technical field of scene text recognition and white-box attack, and in particular relates to a method, system and device for generating a white-box confrontation sample for a scene text recognition model. Background technique [0002] Scene Text Recognition (STR) refers to the recognition of text information in any natural scene picture. Compared with the traditional Optical Character Recognition (OCR), scene text recognition is more difficult, mainly because the text display forms in natural scenes are very rich, such as one, multi-language mixed, text area There may be phenomena such as deformation, incompleteness and blurring; 2. The scene is changeable, and the character arrangement and form are changeable. Scene character recognition includes two parts: positioning and recognition. The present invention is mainly aimed at the recognition part of the depth model, that is, the input is all pictures that have been extrac...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): G06K9/20G06K9/62G06N3/04G06N3/08
CPCG06N3/08G06V10/22G06N3/045G06F18/241G06F18/214
Inventor 徐行肖金辉陈杰夫陈李江
Owner BEIJING YUNJIANG TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products