Intelligent confrontation sample generation method and system based on optimization algorithm and invariance

A technology against samples and optimization algorithms, applied in neural learning methods, calculations, computer components, etc., can solve problems such as low attack success rate, achieve the effects of improving transferability, improving the generation process, and good application prospects

Pending Publication Date: 2022-02-18
PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU
View PDF0 Cites 4 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, these existing methods often show a low attack success rate in

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Intelligent confrontation sample generation method and system based on optimization algorithm and invariance
  • Intelligent confrontation sample generation method and system based on optimization algorithm and invariance
  • Intelligent confrontation sample generation method and system based on optimization algorithm and invariance

Examples

Experimental program
Comparison scheme
Effect test

Example Embodiment

[0031] In order to make the objectives, technical solutions and advantages of the present invention clearer and more comprehensible, the present invention will be described in further detail below with reference to the accompanying drawings and technical solutions.

[0032]Deep neural networks are very vulnerable to adversarial samples, which are generated by adding tiny perturbations to clean images that are barely perceptible to humans, thereby misleading the deep neural network and causing the neural network to give an error Output. Therefore, before the deployment of deep neural networks, adversarial example attacks can be used as an important method to evaluate and improve the robustness of the model. However, under the challenging black-box setting, the attack success rate of most existing adversarial attack methods still needs to be improved. To this end, the embodiment of the present invention provides an intelligent adversarial sample generation method based on an op...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention belongs to the technical field of image recognition data processing, and particularly relates to an intelligent adversarial sample generation method and system based on an optimization algorithm and invariance. The method comprises the steps: collecting original image data with a correct label; constructing a neural network model for adversarial sample generation and a model loss function, and optimizing adversarial disturbance between an original input image and a corresponding output adversarial sample by maximizing the model loss function; based on original image data and a neural network model, an Adazief iterative quick gradient method and a cutting invariance method are used for iterative solution, and a finally generated adversarial sample is obtained according to an iteration termination condition. From the perspective that the generation process of the adversarial sample is similar to the neural network training process, the convergence process is optimized through the Adazief iteration quick gradient method, the over-fitting phenomenon in the adversarial attack is avoided by using the cutting invariance, the adversarial sample with better mobility can be generated, the robustness of the network model is improved, and the practical scene application is facilitated.

Description

technical field [0001] The invention belongs to the technical field of image recognition data processing, and in particular relates to a method and system for generating intelligent adversarial samples based on optimization algorithms and invariance. Background technique [0002] In the field of image recognition, experimental results on relevant standard datasets show that the recognition ability of deep neural networks can reach or even exceed the human level. However, researchers have found that deep neural networks are fragile. For example, Szegedy et al. first discovered an interesting property of deep neural networks: adding small perturbations imperceptible to humans to the original clean image can make deep neural networks give wrong outputs with high confidence. The perturbed image is an adversarial example; although the existence of adversarial examples seriously affects the safe use of deep neural networks, adversarial examples with strong attack performance can ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): G06T7/11G06V10/764G06K9/62G06N3/04G06N3/08
CPCG06T7/11G06N3/08G06T2207/20132G06T2207/20081G06T2207/20084G06N3/045G06F18/24
Inventor 张恒巍杨博李晨蔚刘志林刘小虎张玉臣王晋东
Owner PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products