Adversarial sample generation method and device, storage medium and electronic equipment

A technology against samples and targets, applied in the field of image processing, can solve the problems of weak offensiveness, inability to achieve effective defense, and lack of defense capabilities of image processing models, so as to achieve the effect of improving offensiveness, effective defense, and improving scene applicability

Pending Publication Date: 2021-05-07
BEIJING YOUZHUJU NETWORK TECH CO LTD
View PDF0 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] In related technologies, the generation of adversarial samples is usually based on applying pixel-level perturbations to the image, which can be regarded as imposing some special noise on the image. Therefore, such adversarial samples can be generated by introducing a feature-level denoising module. To a certain extent, the attack is not strong, so the image processing model is trained through this type of adversarial samples, and the defense capability of the trained image processing model is also lacking, and it is impossible to achieve effective defense against other types of adversarial samples.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Adversarial sample generation method and device, storage medium and electronic equipment
  • Adversarial sample generation method and device, storage medium and electronic equipment
  • Adversarial sample generation method and device, storage medium and electronic equipment

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0026] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it should be understood that the disclosure may be embodied in various forms and should not be construed as limited to the embodiments set forth herein; A more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for exemplary purposes only, and are not intended to limit the protection scope of the present disclosure.

[0027] It should be understood that the various steps described in the method implementations of the present disclosure may be executed in different orders, and / or executed in parallel. Additionally, method embodiments may include additional steps and / or omit performing illustrated steps. The scope of the present disclosure is not limited in this regard. ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to an adversarial sample generation method and device, a storage medium and electronic equipment, and aims to improve aggressiveness of generated adversarial samples so as to defend adversarial attacks more effectively. The method comprises the following steps: acquiring an original image of a to-be-generated adversarial sample; determining a target standard deviation image with the same size as the original image, and determining a target Gaussian blurring kernel corresponding to each pixel point in the original image according to the target standard deviation image and a preset blurring radius; for each pixel point in the original image, determining a target Gaussian blur value corresponding to the pixel point according to the target Gaussian blur kernel and target pixel points located around the pixel point and within the preset blur radius range, so as to obtain a target Gaussian blur image corresponding to the original image; and taking the target Gaussian blurred image as an adversarial sample corresponding to the original image.

Description

technical field [0001] The present disclosure relates to the technical field of image processing, and in particular, to a method, device, storage medium, and electronic device for generating an adversarial example. Background technique [0002] With the large-scale application of various image processing models, attacks against image processing models emerge in an endless stream. It is necessary to follow up research in time to discover potential attack methods and prevent dangers before they happen. Among many attack methods, adversarial attack is a new type of attack method with strong aggressiveness. Adversarial attacks cause image processing models to give a wrong output with high confidence through adversarial examples. Among them, adversarial samples are constructed by attackers through specific means. Human eyes look no different from normal samples, but a type of image that the machine will misclassify. [0003] In related technologies, the generation of adversaria...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): G06K9/00G06K9/62
CPCG06V40/172G06V40/40G06F18/24
Inventor 郭怡文王智王长虎
Owner BEIJING YOUZHUJU NETWORK TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products