White box adversarial sample generation method for scene character recognition model

An adversarial sample, text recognition technology, applied in character and pattern recognition, neural learning methods, biological neural network models, etc., can solve the problems of time-consuming and unstable that cannot meet the time-consuming and unstable adversarial sample image confrontation attack, and avoid time-consuming and instability, ensuring robustness, and improving confidence
CN111476228APending Publication Date: 2020-07-31BEIJING YUNJIANG TECH CO LTD

Patent Information

Authority / Receiving Office
CN Β· China
Current Assignee / Owner
BEIJING YUNJIANG TECH CO LTD
Publication Date
2020-07-31

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention belongs to the technical field of scene character recognition and white box attack, particularly relates to a white box confrontation sample generation method, system and device for a scene character recognition model, and aims to solve the problems that an existing white box attack algorithm cannot meet requirements and is long in attack time and unstable. The method comprises the following steps: acquiring a to-be-attacked image, and generating an adversarial sample image in combination with disturbance; obtaining a recognition result of the adversarial sample image through a scene character recognition model, judging whether the image is successfully attacked or not based on the result, and taking the image as an optimal adversarial sample image if the image is successfully attacked and the disturbed matrix norm is reduced; otherwise, judging whether the number of iterations is less than a set maximum number of iterations: if so, updating the disturbance and adversarial sample image, and otherwise, outputting an optimal adversarial sample image. According to the method, the white box adversarial sample generation requirement for the scene character recognition model is met, and time consumption and instability of an attack algorithm are avoided through gradient cutting.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the technical field of scene text recognition and white-box attack, and in particular relates to a method, system and device for generating a white-box confrontation sample for a scene text recognition model. Background technique

[0002] Scene Text Recognition (STR) refers to the recognition of text information in any natural scene picture. Compared with the traditional Optical Character Recognition (OCR), scene text recognition is more difficult, mainly because the text display forms in natural scenes are very rich, such as one, multi-language mixed, text area There may be phenomena such as deformation, incompleteness and blurring; 2. The scene is changeable, and the character arrangement and form are changeable. Scene character recognition includes two parts: positioning and recognition. The present invention is mainly aimed at the recognition part of the depth model, that is, the input is all pictures that have been extrac...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More