Confrontation sample generation method and device, storage medium and program product
By generating random masks and multi-version gradient optimization methods in the proxy model, the overfitting relationship between perturbation and model is broken, the migration ability and robustness against perturbation is improved, the problem of insufficient perturbation pattern dependence and migration in the existing technology is solved, and stronger attack generalization and robustness are achieved.
Patent Information
- Application Number
- CN202510446512.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-29
AI Technical Summary
In the prior art, there is a co-adaptive problem in the generation process of anti-perturbation, which leads to excessive dependence on the specific feature distribution of the proxy model and the inability to effectively adapt to the structural differences of the target model, which seriously reduces the migration performance and robustness of the perturbation.
By generating random masks at different layers of the proxy model, generating multi-version proxy models, and combining multiple versions of gradient information for perturbation optimization, breaking the overfitting relationship between perturbation and model, improving migration ability and robustness.
Without relying on additional model training, the migration ability and attack strength against perturbations on the unseen target model is significantly improved, and the attack generalization and robustness of attacks are achieved, and the technical difficulties in the existing technology are difficult to take into account both the perturbation attack performance and the migration performance.
Smart Images

Figure CN120387497A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of adversarial attacks, and particularly to an adversarial sample generation method, device, storage medium, and program product for a migration scenario. Background Art
[0002] Adversarial attacks aim to generate adversarial samples by adding tiny perturbations to input samples to mislead deep neural networks (DNNs). It is widely applied in fields such as image recognition, face recognition, autonomous driving, etc. For example, in image recognition, by adding subtle interferences (such as adversarial noise), the classifier can be misled to misclassify an image (such as misjudging a stop sign as a speed limit sign); in face recognition, the interference can deceive the system, allowing unauthorized persons to pass the verification or legitimate users to be rejected; in autonomous driving, attacking traffic signs or road images (such as pasting interference stickers) can mislead the vehicle to make dangerous decisions (such as recognizing a "stop" sign as a "speed limit").
[0003] The existing technology generally has the problem of perturbation co-adaptation in adversarial perturbation generation, that is, multiple perturbed pixels or features form a highly dependent collaborative relationship during the optimization process, thus achieving a high attack effect on the surrogate model. However, this co-adaptation causes the perturbation pattern to overly depend on the specific feature distribution of the surrogate model and cannot effectively adapt to the structural differences of the target model, seriously reducing the migration performance of the perturbation. This overfitting characteristic directly limits the practical application value of adversarial perturbations in cross-model attacks.
[0004] In addition, the co-adaptation problem also causes a series of incidental defects. Since the perturbation depends on a larger range of key regions or more pixel collaborations, it is more sensitive to local or global modifications of the input sample, resulting in poor robustness. This dependence makes the adversarial sample easily fail in the face of input perturbations, cropping, or other defense mechanisms, further weakening the effectiveness of the attack. The existing technology fails to provide an effective means to balance the attack intensity and migration, which has become an important bottleneck restricting the development of adversarial attacks. Summary of the Invention
[0005] Aiming at the deficiencies of the existing technology, the present invention proposes an adversarial sample generation method, device, storage medium, and program product for a migration scenario. While improving the migration ability of adversarial samples, this method can still maintain a high attack intensity and robustness, enhancing the practicality and generality in different scenario applications.
[0006] On the one hand, the present invention provides an adversarial sample generation method for a migration scenario, including:
[0007] Receiving a surrogate model to be attacked, selecting multiple network layers in the surrogate model, and generating a random mask that matches the parameter shape of the selected network layers;
[0008] Mask the parameters of the selected network layer based on the random mask to generate multi-version proxy models;
[0009] Input the original input sample into the multi-version proxy model for forward propagation, calculate the gradient information of each proxy model for the current adversarial sample respectively, and generate a gradient direction;
[0010] Iteratively update the perturbation using the gradient direction, and superimpose the updated perturbation on the original input sample to generate an adversarial sample.
[0011] In an embodiment of the present invention, the original input sample is the original image to be attacked, and its format is an RGB pixel matrix or a grayscale pixel matrix.
[0012] In an embodiment of the present invention, the method for generating the random mask is as follows:
[0013] Independently generate binary masks for the weights and bias parameters of each selected network layer based on the Bernoulli distribution, where the masking probability of each parameter is a preset fixed value.
[0014] In an embodiment of the present invention, input the original input sample into the multi-version proxy model for forward propagation, and record the gradient information of each proxy model for the current adversarial sample through backpropagation.
[0015] In an embodiment of the present invention, calculate the mean value of the gradient information of each proxy model for the current adversarial sample to obtain the gradient direction.
[0016] In an embodiment of the present invention, the iterative gradient ascent method is adopted to gradually adjust the perturbation direction and amplitude of the original input sample according to the gradient direction until the preset attack condition is met, and update the perturbation.
[0017] In an embodiment of the present invention, the masking operation is implemented through dynamic hook technology, and different versions of proxy models are generated in real time during each round of forward propagation, and the multi-version proxy models are obtained by summarization.
[0018] In an embodiment of the present invention, the selected network layers include linear layers and normalization layers, the linear layers include fully connected layers or convolutional layers, and the normalization layers include batch normalization layers or layer normalization layers.
[0019] In an embodiment of the present invention, the proxy model includes a pre-trained neural network model with a ResNet, Vision Transformer, or DenseNet architecture.
[0020] On the other hand, the present invention also provides an adversarial sample generation method for a migration scenario, including:
[0021] A mask generation module, configured to receive a proxy model to be attacked, select a plurality of network layers in the proxy model, and generate a random mask that matches the parameter shape of the selected network layers;
[0022] A multi-model generation module, configured to mask the parameters of the selected network layers based on the random mask to generate multi-version proxy models;
[0023] A gradient calculation module, configured to input an original input sample into the multi-version proxy models for forward propagation, calculate the gradient information of each proxy model for the current adversarial sample respectively, and generate a gradient direction;
[0024] A perturbation optimization module, configured to iteratively update the perturbation using the gradient direction;
[0025] An adversarial sample generation module, configured to superimpose the updated perturbation on the original input sample to generate an adversarial sample.
[0026] Another aspect of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0027] Another aspect of the present invention further provides a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, the steps of the above method are implemented.
[0028] As can be seen from the above solutions, the advantages of the present invention are as follows:
[0029] The adversarial sample generation method for migration scenarios disclosed by the present invention effectively breaks the overfitting relationship between adversarial perturbations and proxy models by randomly masking the parameters of the proxy model and randomly discarding connections in the proxy model during the perturbation generation process. Without relying on additional model training, it can effectively reduce perturbation dependence, thereby enhancing the migration ability of adversarial perturbations on unseen target models and achieving stronger attack generalization. At the same time, this method combines multi-model gradient information, greatly improving the generality of perturbations while maintaining the attack strength, solving the technical problem in the prior art that it is difficult to balance both the perturbation attack performance and migration performance. The generated adversarial samples show excellent attack effects on multiple target models and demonstrate excellent performance in complex attack environments and cross-model attack tasks. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a schematic diagram of the overall process of the adversarial sample generation method for migration scenarios provided by an embodiment of the present invention;
[0031] Figure 2 It is a schematic diagram of the structure of the adversarial sample generation device for migration scenarios provided by an embodiment of the present invention.
[0032] Reference Signs:
[0033] 300: Adversarial Sample Generation Device;
[0034] 310: Mask Generation Module;
[0035] 320: Multi-Model Generation Module;
[0036] 330: Gradient Calculation Module;
[0037] 340: Perturbation Optimization Module;
[0038] 350: Adversarial Sample Generation Module. Detailed Implementation Manner
[0039] It should be noted that in this application, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.
[0040] Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.
[0041] In the prior art, during the generation process of adversarial perturbations, highly dependent collaborative relationships often form, overly adapting to the specific feature distribution of the surrogate model and being unable to effectively generalize to the target model, thus significantly reducing the success rate of black-box attacks. In addition, existing methods lack effective control over the global and local dependencies of perturbations, resulting in susceptibility to random noise or input modifications during the perturbation generation process, not only reducing the robustness of the perturbations but also increasing the complexity and instability of the generation process.
[0042] To this end, the present invention proposes an adversarial sample generation method for the migration scenario. By performing random masking on different layers of the model, the co-adaptability of the perturbations is explicitly disrupted, thereby enhancing the transferability and robustness of the adversarial perturbations. This method generates multiple versions of the surrogate model that are both effective by randomly discarding different parameters of different layers of the surrogate model, significantly reducing the overfitting problem while maintaining the strength of the perturbation attack, and achieving an effective balance between transferability and attack strength. Then, during the adversarial sample generation process, multiple versions of the surrogate model are combined to participate in the perturbation calculation in parallel, fully introducing the diversity at the model level, and improving the robustness and randomness of the overall attack process.
[0043] Specifically, referring to Figure 1 as shown, Figure 1 FIG. shows a schematic flow chart of an adversarial sample generation method for the migration scenario provided by an embodiment of the present invention.
[0044] An adversarial sample generation method for the migration scenario, the method comprising the following steps:
[0045] Step S1, receiving the surrogate model to be attacked, selecting a plurality of network layers in the surrogate model, and generating a random mask that matches the parameter shape of the selected network layer.
[0046] As described above, there is a co-adaptability phenomenon in the optimization process of adversarial perturbations in the prior art. Among them, during the process of using gradient optimization to generate adversarial perturbations, different pixels or features often exhibit highly cooperative behaviors and rely on each other to enhance the attack ability on the surrogate model. However, this co-adaptability tendency causes the perturbations to overfit the feature distribution of the surrogate model, forming complex perturbation patterns that are limited to the structure of the surrogate model, thereby significantly weakening the transfer attack effect on the target model. In response to this, the present invention proposes a "random masking strategy" for structural interference in the perturbation optimization process. Traditional Dropout reduces the co-adaptability between features and enhances the generalization ability of the model by randomly masking some neuron connections during training. Drawing on this idea, the present invention considers that during the adversarial sample generation process, the binding relationship between the perturbation and the surrogate model can also be weakened by randomly discarding model connections, thereby enhancing the cross-model transfer ability of the perturbation. However, different from the role of the Dropout technique on model parameters during training, in the adversarial sample generation task, the main body being updated is the input sample, and the neural network structure is fixed. Therefore, the present invention further considers introducing a random masking mechanism for the key network layers in the surrogate model during the adversarial perturbation optimization process, dynamically constructing multiple versions of the surrogate model, disrupting the adaptation process between the perturbation and the model from the structural level, and enhancing the generalization performance of the perturbation.
[0047] Based on this, in one embodiment, a proxy model to be attacked is received. According to the structure and scale of the proxy model to be attacked, multiple network layers are selected in the proxy model for masking, and a random mask matching the parameter shape of the selected network layers is generated.
[0048] In one embodiment, the proxy model to be attacked includes a pre-trained neural network model with an architecture such as ResNet, Vision Transformer, or DenseNet, etc., but the present invention is not limited thereto.
[0049] In one embodiment, to ensure good generality of this method, by evaluating the importance and stability of different layer types in multiple neural networks, the selected network layers preferably select the linear layers and normalization layers that are commonly present in mainstream neural networks. Linear layers usually have dense parameters and contain rich semantic features; while normalization layers contain rich statistical distribution information and have important structural features. Among them, linear layers include fully connected layers or convolutional layers, and normalization layers include batch normalization layers or layer normalization layers.
[0050] Then, for the weight and bias parameters of the selected network layers, a random mask matching their shapes is generated. To enhance randomness, masks for weights and biases are generated independently. The mask adopts a fixed masking probability (such as 0.01) to maintain structural simplicity and transferability. The setting of a low masking probability and multiple generations helps generate more diverse proxy models, thereby enhancing the diversity and effectiveness of the proxy models. In one embodiment, based on the parameter dropout strategy of the Bernoulli distribution, a random mask is generated by sampling from the Bernoulli distribution, specifically generating a binary mask independently for the weight and bias parameters of each selected network layer based on the Bernoulli distribution.
[0051] In this embodiment, by randomly masking the parameters of the key network layers of the proxy model to be attacked, the randomness in the generation process is effectively enhanced, and the overfitting relationship between the adversarial perturbation and the proxy model is effectively broken, thereby enhancing the transfer ability of the adversarial perturbation on unseen target models and achieving stronger attack generalization.
[0052] Step S2: Mask the parameters of the selected network layers based on the random mask to generate multiple versions of the proxy model.
[0053] In one embodiment, the generated random mask is applied to the parameters of the corresponding layer to achieve masking of some parameters. The masks of each layer are independent of each other, enhancing the random difference between the generated proxy models, effectively alleviating the co-adaptation relationship between pixels in the model, and finally constructing multiple versions of the proxy model to be used in the subsequent adversarial sample generation process.
[0054] In one embodiment, according to the characteristics of the normalization layer and the linear layer in the neural network, random masking operations are performed separately. The normalization layer is rich in statistical distribution information, while the linear layer carries rich semantic features. Masking these two types of layer structures can further improve the difference and effectiveness between the generated surrogate models while ensuring the functionality of the model.
[0055] In one embodiment, during the attack process, the masking operation is implemented through the dynamic hook technology. Different versions of the surrogate model are generated in real time during each forward propagation round, and the multi-version surrogate model can be obtained by summarizing each version of the surrogate model, significantly reducing the storage overhead and improving the flexibility of the system. Each surrogate model processes the adversarial samples in the state of enabling gradient recording for subsequent calculation.
[0056] Step S3: Input the original input sample into the multi-version surrogate model for forward propagation, and calculate the gradient information of each surrogate model for the current adversarial sample respectively to generate the gradient direction.
[0057] In one embodiment, after generating the multi-version surrogate model, further input the original input sample into each surrogate model of the multi-version surrogate model for forward propagation, calculate the gradient information of each surrogate model for the current adversarial sample respectively, and determine the gradient direction. At the same time, initialize the perturbation and determine that the norm of the perturbation does not exceed the preset range.
[0058] In one embodiment, the original input sample is the original image to be attacked, and its format is an RGB pixel matrix or a grayscale pixel matrix.
[0059] In one embodiment, to enhance the consistency and stability of the perturbation direction, input the original input sample into the multi-version surrogate model for forward propagation, and record the gradient information of each surrogate model for the original input sample through backpropagation. Then, calculate the mean value of the gradient information of each surrogate model for the current adversarial sample to obtain the final gradient direction for updating the perturbation. By statistically averaging the gradients generated by multiple surrogate models during backpropagation, the gradient direction is determined to form a stable and consistent perturbation update gradient. By statistically averaging the gradients generated by multiple surrogate models during backpropagation, while maintaining the attack efficiency, the perturbation deviation problem caused by a single model is effectively alleviated, and the generality of the perturbation between different models is significantly enhanced, which helps to generate more transferable adversarial samples.
[0060] Step S4: Iteratively update the perturbation using the gradient direction and superimpose the updated perturbation on the original input sample to generate an adversarial sample.
[0061] It should be noted that the original input samples are the input basis for the entire process. Adversarial samples do not exist in the initial stage, but are gradually generated and evolved based on the original input samples by adding controllable perturbations. The process of generating adversarial samples is iterative. In each iteration, the gradient direction is determined according to the gradient information of the current adversarial sample to update the perturbation. During the loop, the perturbation is continuously adjusted according to the gradient direction, so that the original input sample gradually transforms into an adversarial sample. In each loop, the current adversarial sample is updated according to the calculated gradient direction to make it closer and closer to the final adversarial sample. After iterative updates for a predetermined number of loops, the original input sample plus the finally determined perturbation forms the final adversarial samples with high transferability and high attack efficiency. These samples can not only effectively attack on the surrogate model, but also have powerful attack capabilities on unknown target models, and can be used for specific attack purposes (such as deceiving certain image recognition models, etc.).
[0062] In one embodiment, the iterative gradient ascent method is adopted. In each iteration, the gradient information is calculated according to the current loss function, the gradient direction is determined, and the perturbation direction and amplitude of the original input sample are gradually adjusted according to the gradient direction until the preset attack condition is met, and the perturbation is updated. In one embodiment, the preset attack condition can be configured according to the perturbation reaching an ideal balance state between the attack performance and the image fidelity.
[0063] Next, the effect of the method of the present invention is verified. The method of the present invention is compared with the existing input transformation-based methods DI, RDI, BSR, Admix, SI, and the loss function optimization-based method CFM to evaluate the performance comparison between the present invention and these mainstream methods of the existing technology.
[0064] Compared with the previous optimal method, the transfer success rate of the present invention on the convolutional model is increased by more than 11.1%, and the transfer success rate on the Transformer model is increased by more than 13.0%. When attacking a model with defense, the present invention also has an obvious improvement of at least 3% compared with the previous best effect.
[0065] To evaluate the transfer effect of adversarial perturbations on different models, the present invention adopts a comprehensive experimental evaluation scheme. During the attack process, models such as ResNet50 (RN50), Inceptionv3 (IncV3), Vision Transformer (ViT), and DenseNet-121 (DN121) are used as white-box models for attack, and at the same time, the transfer performance of the perturbations is evaluated on the target models. The target models include 10 convolutional-based models: VGG-16, ResNet18, ResNet-50, DenseNet-121 (DN121), Xception, MobileNet-v2, EfficientNet-B0, Inception ResNetv2, Inception-v3, and Inception-v4, and 6 Transformer-based models: Vision Transformer (ViT), LeViT, ConViT, Twins, Pooling-based Vision Transformer (PiT), and CLIP. Finally, the effectiveness of the present invention is comprehensively evaluated by the average transfer performance of these target models.
[0066] Table 1 shows the transfer attack success rates evaluated on convolutional models using IncV3 and ViT as proxy models in the present invention and prior art methods. Table 2 shows the transfer attack success rates evaluated on Transformer-based models in the present invention and prior art methods. Table 3 shows the comparison of attack success rates of the present invention and prior art methods against a series of neural network defense methods.
[0067] Table 1: Transfer attack success rate based on randomly dropping connections (effect on convolutional models)
[0068]
[0069] Table 2: Transfer attack success rate based on randomly dropping connections (effect on Transformer models)
[0070]
[0071] Table 1 presents the test results of specific target transfer attacks on convolutional models after improving existing mainstream methods using the method proposed in the present invention on the ImageNet test set. These results aim to evaluate the robustness of different methods when facing target models with significant differences. As can be seen from Table 1, the method of the present invention shows a significant improvement in the success rate of transfer attacks. Especially when facing Transformer-based target models that are quite different from the surrogate model, the transfer success rate has been significantly improved compared to the case without using this method. For example, when using IncV3 as the surrogate model, the transfer success rate increased by 13.2%; when using ViT as the surrogate model, the average attack success rate increased by 11.1%.
[0072] Table 2 is also based on the ImageNet test set and shows the test results of specific target transfer attacks on convolutional models using the improved existing mainstream methods of the present invention with a Transformer model as the surrogate model. The results of previous methods in this experimental setting were very low, and as can be seen from Table 2, our method effectively improved the transfer success rate. Specifically, when using RN50 as the surrogate model, the average attack success rate increased by 13.0%; when using DN121 as the surrogate model, the average attack success rate increased by 17.9%.
[0073] There are already some methods of adversarial training or purification defense for resisting attacks by adversarial samples. The method of the present invention tests its performance when facing several mainstream defense methods, including JPEG (image compression), HGD (Gaussian blur purification), adversarial training model (Robust), and integrated defense models (such as Inception-Resnet-v2-ensemble, IR_ens). ResNet50 is selected as the surrogate model for specific target attacks during the test. The attack success rate shown when facing defense methods can actually better illustrate the true transfer performance of different methods, so it is very important.
[0074] Table 3: Specific target attack success rates of different attack methods when facing defense methods
[0075]
[0076] Table 3 details the performance of the method of the present invention when facing various defense strategies. It can be clearly seen from the data in the table that the method of the present invention has achieved a significant improvement in the attack success rate. Taking HGD as an example, the previous optimal attack success rate was 15.2%, while the method of the present invention increased it to 25.7%; on Inception-Resnetv2-ensemble, the previous optimal attack success rate was 13.8%, and the method of the present invention increased it to 43.2%. These data fully demonstrate the superior performance of the method of the present invention in dealing with adversarial defense strategies.
[0077] In summary, the adversarial sample generation method for the migration scenario disclosed by the present invention effectively breaks the overfitting relationship between the adversarial perturbation and the surrogate model by randomly masking the parameters of the surrogate model and randomly dropping connections in the perturbation generation process. Without relying on additional model training, it can effectively reduce the perturbation dependence, thereby improving the migration ability of the adversarial perturbation on the unseen target model and achieving stronger attack generalization. At the same time, this method integrates the gradient information of multiple models, greatly improving the generality of the perturbation while maintaining the attack strength, solving the technical problem in the prior art that it is difficult to balance the perturbation attack performance and migration performance at the same time. The generated adversarial samples show excellent attack effects on multiple target models. Compared with the prior art, this method not only solves the problem of overfitting of the perturbation to the features of the surrogate model, but also reduces the impact of model changes on the effectiveness of the model, ensuring the strength of the model, achieving an effective balance between migration and attack strength, and showing excellent performance in complex attack environments and cross-model attack tasks. While improving the migration ability of adversarial samples, this method can still maintain a high attack strength and robustness, improving the practicality and generality in different scenario applications.
[0078] In addition, it should be understood that in various embodiments of the present invention, the size of the sequence numbers of the above processes does not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0079] The following is a corresponding device embodiment of the above method embodiment. As Figure 2 shown, Figure 2 shows a schematic structural diagram of an adversarial sample generation device. The implementation manner of this device can be implemented in cooperation with the above method implementation manner. The relevant technical details mentioned in the above method implementation manner are still valid in the implementation manner of this device. To avoid repetition, they will not be elaborated here. Correspondingly, the relevant technical details mentioned in the implementation manner of this device can also be applied to the above method implementation manner.
[0080] An adversarial sample generation device 300 for the migration scenario includes:
[0081] A mask generation module 310 is configured to receive a proxy model to be attacked, select multiple network layers in the proxy model, and generate a random mask that matches the parameter shape of the selected network layers.
[0082] A multi-model generation module 320 is configured to mask the parameters of the selected network layers based on the random mask to generate multiple versions of the proxy model.
[0083] A gradient calculation module 330 is configured to input an original input sample into the multiple versions of the proxy model for forward propagation, calculate the gradient information of each proxy model for the current adversarial sample respectively, and generate a gradient direction.
[0084] A perturbation optimization module 340 is configured to iteratively update the perturbation using the gradient direction.
[0085] An adversarial sample generation module 350 is configured to superimpose the updated perturbation on the original input sample to generate an adversarial sample.
[0086] The device embodiments described above are merely illustrative. For example, the division of functional modules is only a logical functional division, and there may be other division methods in actual implementation. In addition, in various embodiments of the present invention, each functional module may be integrated in a processing unit, or each module may exist physically alone, or two or more modules may be integrated in a processing unit.
[0087] In addition, the above method embodiments can be implemented in whole or in part by software. When implemented using software, the above method embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. The computer program can be stored on a readable storage medium. When the computer program is executed by a processor, the computer can execute the above-provided adversarial sample generation method for the migration scenario. When loading or executing the computer instructions or computer programs on the computer, the processes or functions described in the method embodiments of the present invention are generated in whole or in part.
[0088] In addition, if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and is used to store a computer program for executing the adversarial sample generation method for the migration scenario, so that a computer device (which can be a personal computer, a server, or a network device, etc.) can execute all or part of the steps of the methods described in various embodiments of the present invention.
[0089] It should be understood that the storage medium in the embodiments of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0090] Although the embodiments of the present invention have been disclosed above, they are not limited to the applications listed in the specification and the embodiments. It can be fully applied to various fields suitable for the present invention. For those skilled in the art, additional modifications can be easily achieved. Therefore, without departing from the general concept defined by the claims and the equivalent scope, the present invention is not limited to the specific details and the illustrated and described examples here.
Claims
1. An adversarial sample generation method for migration scenarios, characterized in that, Including: Receiving a proxy model to be attacked, selecting multiple network layers in the proxy model, and generating a random mask that matches the parameter shape of the selected network layers; Based on the random mask, masking the parameters of the selected network layers to generate multiple versions of the proxy model; Inputting the original input sample into the multiple versions of the proxy model for forward propagation, respectively calculating the gradient information of each proxy model for the current adversarial sample, and generating a gradient direction; Using the gradient direction to iteratively update the perturbation, and superimposing the updated perturbation on the original input sample to generate an adversarial sample.
2. The method according to claim 1, characterized in that The original input sample is the original image to be attacked, and its format is an RGB pixel matrix or a grayscale pixel matrix.
3. The method according to claim 1, characterized in that, The method for generating the random mask is as follows: Based on the Bernoulli distribution, independently generating a binary mask for the weights and bias parameters of each selected network layer, where the masking probability of each parameter is a preset fixed value.
4. The method according to claim 1, wherein Inputting the original input sample into the multiple versions of the proxy model for forward propagation, and recording the gradient information of each proxy model for the current adversarial sample through backpropagation.
5. The method according to claim 1 or 4, characterized in that, Calculating the mean value of the gradient information of each proxy model for the current adversarial sample to obtain the gradient direction.
6. The method according to claim 1, wherein Adopting the iterative gradient ascent method, gradually adjusting the perturbation direction and amplitude of the original input sample according to the gradient direction until the preset attack condition is met, and updating the perturbation.
7. The method according to claim 1, wherein The masking operation is implemented through the dynamic hook technology, and different versions of the proxy model are generated in real time during each round of forward propagation, and the multiple versions of the proxy model are summarized.
8. The method according to claim 1, wherein The selected network layers include linear layers and normalization layers. The linear layers include fully connected layers or convolutional layers, and the normalization layers include batch normalization layers or layer normalization layers.
9. The method according to claim 1, characterized in that, The proxy model includes a pre-trained neural network model with a ResNet, VisionTransformer, or DenseNet architecture.
10. An adversarial example generation device for migration scenarios, characterized in that, Containing: A mask generation module for receiving a proxy model to be attacked, selecting multiple network layers in the proxy model, and generating a random mask that matches the parameter shape of the selected network layers; A multi-model generation module for masking the parameters of the selected network layers based on the random mask to generate multiple versions of the proxy model; A gradient calculation module for inputting the original input sample into the multiple versions of the proxy model for forward propagation, respectively calculating the gradient information of each proxy model for the current adversarial sample, and generating a gradient direction; A perturbation optimization module for iteratively updating the perturbation using the gradient direction; An adversarial sample generation module for superimposing the updated perturbation on the original input sample to generate an adversarial sample.
11. A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1-9 are implemented.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-9 are implemented.
Citation Information
Cited By
Disturbance direction and position cooperative constraint time sequence adversarial sample generation method and system
CN121524964A
Cross-modal anti-attack method and system based on mask weight and random cutting
CN121706883A