Multi-outlet neural network adversarial robustness evaluation and defense method and device based on game theory
By modeling the adversarial attack and defense of multi-outlet neural networks as a two-player zero-sum game, constructing a payoff matrix and optimizing the defense strategy, the problems of evaluation inaccuracy and defense vulnerability of multi-outlet neural networks under adversarial attacks are solved, achieving more efficient robustness evaluation and defense.
Patent Information
- Application Number
- CN202510663317.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-09-12
AI Technical Summary
Existing adversarial attack evaluation methods for multi-export neural networks suffer from attack-defense mismatch, evaluation method limitations, and defense strategy fragility, and cannot accurately reflect the true robustness of multi-export neural networks in the face of diverse attacks.
The adversarial attack and defense of a multi-export neural network are modeled as a two-player zero-sum game. The payoff matrix is constructed through attack experiments on the dataset. The attacker's optimal strategy is calculated and adversarial samples are generated. Game theory is combined to optimize the defense strategy to improve robustness.
It improves the robustness evaluation accuracy of multi-output neural networks in actual adversarial scenarios, reduces computational costs, and has good scalability, making it suitable for networks of different sizes and complexities.
Smart Images

Figure CN120633762A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer vision, and more specifically, to a method and device for evaluating and defending against adversarial robustness of a multi-output neural network based on game theory. Background Art
[0002] With the widespread application of deep neural networks in computer vision, adversarial attacks and defenses have become a hot topic of research. Adversarial attacks, by adding carefully crafted perturbations to input data, can significantly degrade the model's predictive performance, posing a serious threat to the security of deep learning systems. In recent years, the rapid development of adversarial attack techniques has driven research in adversarial defense techniques, aiming to improve the robustness of models against adversarial attacks.
[0003] As an emerging neural network structure, multi-export neural networks can significantly reduce computational costs while maintaining high accuracy by setting multiple exits at different depth levels. However, the robustness of multi-export neural networks under adversarial attacks has not been fully studied. The adversarial attack and defense of multi-export neural networks has unique complexity. Both attackers and defenders can choose different exits (or exit combinations) to generate adversarial samples or perform inference. This flexibility brings more possibilities for adversarial attack and defense, but also makes the evaluation method more complicated. Existing studies usually adopt a fixed exit evaluation method, that is, both attackers and defenders use a fixed exit combination for attack and inference. However, this fixed exit evaluation method has significant limitations: (1) Attack-Defense Mismatch (AD Mismatch) When the export combinations chosen by the attacker and defender do not fully match, the estimated robustness may be higher than the actual situation. This mismatch leads to an overestimation of the defense capability, thus masking the true robustness of the model.
[0004] (2) Limitations of the evaluation method Existing research primarily considers single-egress attacks, average attacks, or maximum average attacks, ignoring the possibility that attackers may choose specific egress combinations to attack. This evaluation method cannot accurately reflect the true defense capabilities of multi-egress neural networks against diverse attacks.
[0005] (3) Vulnerability of defense strategies Because existing evaluation methods fail to fully consider the flexibility of attackers, defense strategies may rely too much on fixed exit combinations and thus perform poorly in the face of more complex attacks. Summary of the Invention
[0006] The purpose of this paper is to introduce the ideas of game theory and propose an improved adversarial robustness evaluation method (Adaptive Evaluation of Multi-Exit Robustness, AIMER) and a Nash Equilibrium Enhanced Defense (NEED) method to more accurately reflect the true robustness of multi-exit neural networks in actual adversarial scenarios.
[0007] To achieve the above objectives, the present invention provides, in a first aspect, a method for evaluating the robustness of a multi-output neural network to adversarial attacks based on game theory, comprising: The adversarial attack and defense of multi-export neural networks are modeled as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits. Through attack experiments on the dataset, an approximate profit matrix is constructed to quantify the profit relationship between attackers and defenders under different export combinations; Based on the payoff matrix, calculate the attacker's optimal strategy given the defender's strategy; According to the attacker's optimal strategy, randomly select export combinations to generate adversarial samples; Evaluating the adversarial robustness of multi-output neural networks using generated adversarial examples.
[0008] In one embodiment, adversarial attacks and defenses against multi-output neural networks are modeled as a two-player zero-sum game, including: Modeling adversarial attacks and defenses against multi-export neural networks as a two-player zero-sum game , where the player set is ,in Indicates the attacker, The behavior space representing the defender, attacker, and defender is defined as , Indicates the number of network exits, Indicates the combination of exports, , the attacker and defender strategies are defined as and , satisfying the following conditions , is a set of probability vectors that satisfies and .
[0009] In one embodiment, an approximate profit matrix is constructed through attack experiments on the dataset, specifically:
[0010] in, Represents the combination of exports, according to each and Down and The value of is used to construct an approximate profit matrix and , is the profit function, represents the exit combination chosen by the attacker, represents the defender's choice of export combination, represents the payoff under the exit combination selected by the attacker and the exit combination selected by the defender, represents the accuracy of the network on the test set, represents a multi-export neural network, and , each element in the payoff matrix express hour, The goal of each player is to maximize his expected profit or , is the expected return function.
[0011] In one embodiment, based on the payoff matrix, the optimal strategy of the attacker is calculated under the given strategy of the defender, including: Given the defender's strategy , the attacker calculates the attacker's optimal strategy by maximizing his expected reward , while the defender pursues the maximum benefit, the attacker pursues the tightest lower bound in the formula :
[0012] in and is the approximate payoff matrix of the attacker and defender, and the attacker’s optimal strategy is expressed as a probability vector , the attacker will not prefer any of them, , It is a set that contains the best possible attack strategies of all attackers.
[0013] In one embodiment, based on the attacker's optimal strategy, a random combination of exits is selected to generate adversarial samples, specifically:
[0014] in, is the attacker’s optimal strategy, For adversarial samples.
[0015] Based on the same inventive concept, the second aspect of the present invention provides a method for defending a multi-output neural network based on game theory, which is implemented based on the multi-output neural network adversarial robustness assessment method based on game theory described in the first aspect. The defense method includes: Given the attacker's strategy , the defender calculates the optimal strategy of the defender by minimizing the maximum loss that the attacker can cause :
[0016] in, is a set of probability vectors that satisfies and , and is the approximate payoff matrix of the attacker and defender, While the attacker seeks to maximize the benefit, the defender seeks the tightest upper bound in the formula; According to the attacker's optimal strategy and the defender's optimal strategy , the attacker has the probability Select export combination , the defender takes the probability Select export combination , for the input sample , by selecting the export combination and Perform inference, calculate the output of each outlet and take the average as the final prediction.
[0017] Based on the same inventive concept, the third aspect of the present invention provides a multi-output neural network adversarial robustness evaluation device based on game theory, comprising: A problem modeling module is used to model adversarial attacks and defenses on multi-export neural networks as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits; The profit matrix construction module is used to construct an approximate profit matrix through attack experiments on the dataset, which is used to quantify the profit relationship between the attacker and the defender under different export combinations; The attacker's optimal strategy calculation module is used to calculate the attacker's optimal strategy based on the payoff matrix under the given defender's strategy; The adversarial sample generation module is used to randomly select exit combinations to generate adversarial samples based on the attacker's optimal strategy; The adversarial robustness evaluation module is used to evaluate the adversarial robustness of multi-output neural networks using generated adversarial samples.
[0018] Based on the same inventive concept, a fourth aspect of the present invention provides a defense device for a multi-output neural network based on game theory, which is implemented based on the multi-output neural network adversarial robustness assessment device based on game theory of the third aspect. The defense device includes: The defender's optimal strategy calculation module is used to calculate the optimal strategy of the attacker. , the defender calculates the optimal strategy of the defender by minimizing the maximum loss that the attacker can cause :
[0019] in, is a set of probability vectors that satisfies and , and is the approximate payoff matrix of the attacker and defender, While the attacker seeks to maximize the benefit, the defender seeks the tightest upper bound in the formula; Reasoning prediction module, used to predict the attacker's optimal strategy and the defender's optimal strategy , the attacker has the probability Select export combination , the defender takes the probability Select export combination , for the input sample , by selecting the export combination and Perform inference, calculate the output of each outlet and take the average as the final prediction.
[0020] Based on the same inventive concept, the fifth aspect of the present invention provides a computer-readable storage medium storing a computer program, which is executed by a processor to implement the method of the first aspect or the second aspect.
[0021] Based on the same inventive concept, the sixth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, the method of the first aspect or the second aspect of the first aspect is implemented.
[0022] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows: This invention provides a game-theoretic method for evaluating the adversarial robustness of multi-exit neural networks. By incorporating game-theoretic concepts, the adversarial attack and defense of a multi-exit neural network is modeled as a two-player zero-sum game, where the behavior space of the attacker and defender is defined as a set of network exit combinations. First, an approximate payoff matrix is constructed through attack experiments on a dataset to quantify the payoff relationship between the attacker and defender under different exit combinations. Based on the payoff matrix, the attacker's optimal strategy is calculated. Exit combinations are selected by maximizing the expected payoff to generate adversarial samples, which are then used to evaluate the adversarial robustness of the multi-exit neural network. Based on this, a game-theoretic defense method for multi-exit neural networks is also provided. The defender solves the optimal strategy to minimize the maximum possible loss inflicted by the attacker. Finally, an exit combination is probabilistically selected for inference, and the average of the exit outputs is taken as the final prediction result. The proposed Adaptive Evaluation of Multi-Exit Robustness (AIMER) method can more realistically reflect the robustness of multi-exit neural networks in actual adversarial scenarios, while the Nash Equilibrium Enhanced Defense (NEED) method ensures that the defender maintains high defense performance even under the most unfavorable attack scenarios by finding a Nash equilibrium. This method has the following advantages: 1. It reduces the impact of attack-defense mismatches, improving the authenticity of robustness assessments; 2. By optimizing the outlet combination strategy, it reduces computational costs while maintaining high robustness; 3. It exhibits good scalability and is applicable to multi-outlet neural networks of varying scales and complexities. This paper experimentally validates the effectiveness of the AIMER and NEED methods in various attack scenarios, providing theoretical support and practical application value for improving the adversarial robustness of multi-outlet neural networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0024] Figure 1 This is a flowchart of a method for evaluating the robustness of a multi-output neural network to adversarial robustness based on game theory in an embodiment of the present invention; Figure 2 This is a flowchart of a multi-exit neural network defense method based on game theory in an embodiment of the present invention. Figure 3 A flowchart of a method for an attacker to find an optimal attack strategy in an embodiment of the present invention; Figure 4 A flowchart of a method for finding an optimal defense strategy for a defender in an embodiment of the present invention. DETAILED DESCRIPTION
[0025] Example 1 This embodiment provides a method for evaluating the robustness of a multi-output neural network to adversarial attacks based on game theory. Figure 1 ,include: S101: Model the adversarial attack and defense of multi-export neural networks as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits; S102: Construct an approximate profit matrix through attack experiments on the dataset to quantify the profit relationship between the attacker and the defender under different export combinations; S103: Based on the payoff matrix, calculate the attacker's optimal strategy given the defender's strategy; S104: Based on the attacker’s optimal strategy, randomly select an exit combination to generate an adversarial sample; S105: Use generated adversarial examples to evaluate the adversarial robustness of multi-output neural networks.
[0026] S101 can be implemented in the following ways: Modeling adversarial attacks and defenses against multi-export neural networks as a two-player zero-sum game , where the player set is ,in Indicates the attacker, The behavior space representing the defender, attacker, and defender is defined as , Indicates the number of network exits, Indicates the combination of exports, , the attacker and defender strategies are defined as and , satisfying the following conditions , is a set of probability vectors that satisfies and .
[0027] In the specific implementation process, it is assumed that a Multi-output neural network with multiple outputs Divided into consecutive blocks , each sub-network can be expressed as ,in ,in yes Middle The classifier of the export.
[0028] S102 can be achieved by:
[0029] in, Represents the combination of exports, according to each and Down and The value of is used to construct an approximate profit matrix and , is the profit function, represents the exit combination chosen by the attacker, represents the defender's choice of export combination, represents the payoff under the exit combination selected by the attacker and the exit combination selected by the defender, represents the accuracy of the network on the test set, represents a multi-export neural network, and , each element in the payoff matrix express hour, The goal of each player is to maximize his expected profit or , is the expected return function.
[0030] During the specific implementation process, we first use an adversarial sample generation algorithm (such as FGSM and PGD) to generate adversarial samples for each combination to prepare for the subsequent calculation of the benefit value.
[0031] Then, the benefits of the attacker and defender are calculated for each attack and defense export combination, and the privacy benefit matrix is constructed based on the benefit function.
[0032] S103 can be achieved by: Given the defender's strategy , the attacker calculates the attacker's optimal strategy by maximizing his expected reward , while the defender pursues the maximum benefit, the attacker pursues the tightest lower bound in the formula :
[0033] in and is the approximate payoff matrix of the attacker and defender, and the attacker’s optimal strategy is expressed as a probability vector , the attacker will not prefer any of them, , It is a set that contains the best possible attack strategies of all attackers.
[0034] Specifically, when calculating the optimal strategy, the attacker faces a minimax problem, that is, while the defender pursues the maximum benefit, the attacker pursues the tightest lower bound in the formula .like Figure 3 FIG. 1 is a flowchart of a method for an attacker to find an optimal attack strategy in an embodiment of the present invention.
[0035] S104 can be achieved by:
[0036] in, is the attacker’s optimal strategy, For adversarial samples.
[0037] Specifically, the adversarial sample generated in S104 is an adversarial sample under the attacker's optimal strategy, which is used in step S105 to evaluate the robustness of the final model.
[0038] During the evaluation, we first use the test set to evaluate the robustness of the model and record the defense performance under different export combinations. Then, we adjust the profit matrix and strategy based on the evaluation results to optimize the adversarial robustness of the model.
[0039] Example 2 Based on the same inventive concept, this embodiment provides a method for defending a multi-output neural network based on game theory. This method is implemented based on the multi-output neural network adversarial robustness assessment method based on game theory in Example 1. The method includes: S201: Model the adversarial attack and defense of multi-export neural networks as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits; S202: Construct an approximate profit matrix through attack experiments on the dataset to quantify the profit relationship between the attacker and the defender under different export combinations; S203: Based on the profit matrix, calculate the attacker's optimal strategy given the defender's strategy; S204: Given the attacker's strategy , the defender calculates the optimal strategy of the defender by minimizing the maximum loss that the attacker can cause :
[0040] in, is a set of probability vectors that satisfies and , and is the approximate payoff matrix of the attacker and defender, While the attacker seeks to maximize the benefit, the defender seeks the tightest upper bound in the formula; S205: Based on the attacker's optimal strategy and the defender's optimal strategy , the attacker has the probability Select export combination , the defender takes the probability Select export combination , for the input sample , by selecting the export combination and Perform inference, calculate the output of each outlet and take the average as the final prediction.
[0041] Specifically, see Figure 2 , which is a flowchart of a multi-exit neural network defense method based on game theory in an embodiment of the present invention. It includes S201 to S205, where steps S201 to S203 are the same as steps S101 to S103.
[0042] The defender is calculating the optimal strategy When the attacker is pursuing the maximum benefit, the defender is pursuing the tightest upper bound in the formula. .like Figure 4 FIG. 1 is a flowchart of a method for a defender to find an optimal defense strategy in an embodiment of the present invention.
[0043] The present invention can improve the authenticity and accuracy of robustness detection of multi-outlet neural networks in actual adversarial scenarios, and has the following advantages: 1. By reducing the impact of AD mismatch, AIMER can more realistically reflect the robustness of multi-outlet neural networks in actual adversarial scenarios. The NEED method ensures that the defender can maintain high defense performance under the most unfavorable attack conditions by finding Nash equilibrium. This strategy not only improves the robustness of the model under a single attack, but also enhances the adaptability of the model under a variety of complex attack scenarios; 2. AIMER and NEED methods have low computational costs while maintaining high robustness. By optimizing the export combination strategy, the model can improve defense performance while reducing the computational burden; 3. AIMER and NEED methods have good scalability and can adapt to multi-outlet neural networks of different scales and complexities. This scalability allows them to be applied to various practical scenarios, from resource-constrained edge devices to data centers with powerful computing capabilities.
[0044] Example 3 Based on the same inventive concept, this embodiment discloses a multi-output neural network adversarial robustness assessment device based on game theory, comprising: A problem modeling module is used to model adversarial attacks and defenses on multi-export neural networks as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits; The profit matrix construction module is used to construct an approximate profit matrix through attack experiments on the dataset, which is used to quantify the profit relationship between the attacker and the defender under different export combinations; The attacker's optimal strategy calculation module is used to calculate the attacker's optimal strategy based on the payoff matrix under the given defender's strategy; The adversarial sample generation module is used to randomly select exit combinations to generate adversarial samples based on the attacker's optimal strategy; The adversarial robustness evaluation module is used to evaluate the adversarial robustness of multi-output neural networks using generated adversarial samples.
[0045] Since the device described in Example 3 of the present invention is the device used in the game theory-based multi-output neural network adversarial robustness assessment method in Example 1 of the present invention, those skilled in the art will be able to understand the specific structure and variations of the device based on the method described in Example 1 of the present invention, and therefore will not be described in detail here. All devices used in the method in Example 1 of the present invention fall within the scope of protection of the present invention.
[0046] Example 4 Based on the same inventive concept, this embodiment provides a defense device for a multi-output neural network based on game theory, which is implemented based on the multi-output neural network adversarial robustness assessment device based on game theory in Example 3. The defense device includes: The defender's optimal strategy calculation module is used to calculate the optimal strategy of the attacker. , the defender calculates the optimal strategy of the defender by minimizing the maximum loss that the attacker can cause :
[0047] in, is a set of probability vectors that satisfies and , and is the approximate payoff matrix of the attacker and defender, While the attacker seeks to maximize the benefit, the defender seeks the tightest upper bound in the formula; Reasoning prediction module, used to predict the attacker's optimal strategy and the defender's optimal strategy , the attacker has the probability Select export combination , the defender takes the probability Select export combination , for the input sample , by selecting the export combination and Perform inference, calculate the output of each outlet and take the average as the final prediction.
[0048] Example 5 Based on the same inventive concept, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the multi-output neural network adversarial robustness evaluation method based on game theory in embodiment one.
[0049] Since the computer-readable storage medium described in Example 5 of the present invention is the computer-readable storage medium used to implement the method of Example 1 or 2 of the present invention, those skilled in the art will be able to understand the specific structure and variations of the computer-readable storage medium based on the method described in Example 1 of the present invention, and therefore will not be described in detail here. All computer-readable storage media used in the method of Example 1 or 2 of the present invention fall within the scope of protection of the present invention.
[0050] Example 6 Based on the same inventive concept, the present invention further provides a computer device, including a memory 401, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in Embodiment 1 when executing the program.
[0051] Since the computer device described in Example 6 of the present invention is used to implement the method of Example 1 or 2 of the present invention, the specific structure and variations of the computer device are readily apparent to those skilled in the art based on the method described in Example 1 of the present invention, and therefore will not be further described here. All computer devices used in the method of Example 1 or 2 of the present invention fall within the scope of protection of the present invention.
[0052] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0053] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0054] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they are aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention. Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, the present invention is intended to include such changes and modifications to the embodiments of the present invention if they fall within the scope of the claims and their equivalents.
Claims
1. A method for evaluating the robustness of multi-output neural networks to adversarial attacks based on game theory, characterized in that: include: The adversarial attack and defense of multi-export neural networks are modeled as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits. Through attack experiments on the dataset, an approximate profit matrix is constructed to quantify the profit relationship between attackers and defenders under different export combinations; Based on the payoff matrix, calculate the attacker's optimal strategy given the defender's strategy; According to the attacker's optimal strategy, randomly select export combinations to generate adversarial samples; Evaluating the adversarial robustness of multi-output neural networks using generated adversarial examples.
2. The method for evaluating the robustness of a multi-output neural network to adversarial inference based on game theory according to claim 1, wherein: We model adversarial attacks and defenses against multi-output neural networks as a two-player zero-sum game, including: Modeling adversarial attacks and defenses against multi-export neural networks as a two-player zero-sum game , where the player set is ,in Indicates the attacker, The behavior space representing the defender, attacker, and defender is defined as , Indicates the number of network exits, Indicates the combination of exports, , the attacker and defender strategies are defined as and , satisfying the following conditions , is a set of probability vectors that satisfies and .
3. The method for evaluating the robustness of a multi-output neural network to adversarial inference based on game theory according to claim 2, wherein: Through the attack experiment of the data set, an approximate profit matrix is constructed, specifically: in, Represents the combination of exports, according to each and Down and The value of is used to construct an approximate profit matrix and , is the profit function, represents the exit combination chosen by the attacker, represents the defender's choice of export combination, represents the payoff under the exit combination selected by the attacker and the exit combination selected by the defender, represents the accuracy of the network on the test set, represents a multi-export neural network, and , each element in the payoff matrix express hour, The goal of each player is to maximize his expected profit or , is the expected return function.
4. The method for evaluating the robustness of a multi-output neural network to adversarial inference based on game theory according to claim 2, wherein: Based on the payoff matrix, the attacker's optimal strategy is calculated under the given defender's strategy, including: Given the defender's strategy , the attacker calculates the attacker's optimal strategy by maximizing his expected reward , while the defender pursues the maximum benefit, the attacker pursues the tightest lower bound in the formula : in and is the approximate payoff matrix of the attacker and defender, and the attacker’s optimal strategy is expressed as a probability vector , the attacker will not prefer any of them, , It is a set that contains the best possible attack strategies of all attackers.
5. The method for evaluating the robustness of a multi-output neural network to adversarial inference based on game theory according to claim 2, wherein: According to the attacker's optimal strategy, we randomly select export combinations to generate adversarial samples, specifically: in, is the attacker’s optimal strategy, For adversarial samples.
6. A defense method for multi-export neural networks based on game theory, characterized in that: The defense method is implemented based on the game theory-based multi-output neural network adversarial robustness evaluation method described in any one of claims 2 to 5, and includes: Given the attacker's strategy , the defender calculates the optimal strategy of the defender by minimizing the maximum loss that the attacker can cause : in, is a set of probability vectors that satisfies and , and is the approximate payoff matrix of the attacker and defender, While the attacker seeks to maximize the benefit, the defender seeks the tightest upper bound in the formula; According to the attacker's optimal strategy and the defender's optimal strategy , the attacker has the probability Select export combination , the defender takes the probability Select export combination , for the input sample , by selecting the export combination and Perform inference, calculate the output of each outlet and take the average as the final prediction.
7. A multi-output neural network adversarial robustness evaluation device based on game theory, characterized in that: include: A problem modeling module is used to model adversarial attacks and defenses on multi-export neural networks as a two-player zero-sum game, where the players include attackers and defenders, and the action spaces of attackers and defenders are defined as the combinatorial set of network exits; The profit matrix construction module is used to construct an approximate profit matrix through attack experiments on the dataset, which is used to quantify the profit relationship between the attacker and the defender under different export combinations; The attacker's optimal strategy calculation module is used to calculate the attacker's optimal strategy based on the payoff matrix under the given defender's strategy; The adversarial sample generation module is used to randomly select exit combinations to generate adversarial samples based on the attacker's optimal strategy; The adversarial robustness evaluation module is used to evaluate the adversarial robustness of multi-output neural networks using generated adversarial samples.
8. A multi-export neural network defense device based on game theory, characterized in that: Based on the game theory-based multi-output neural network adversarial robustness evaluation device of claim 6, the defense device includes: The defender's optimal strategy calculation module is used to calculate the optimal strategy of the attacker. , the defender calculates the optimal strategy of the defender by minimizing the maximum loss that the attacker can cause : in, is a set of probability vectors that satisfies and , and is the approximate payoff matrix of the attacker and defender, While the attacker seeks to maximize the benefit, the defender seeks the tightest upper bound in the formula; Reasoning prediction module, used to predict the attacker's optimal strategy and the defender's optimal strategy , the attacker has the probability Select export combination , the defender takes the probability Select export combination , for the input sample , by selecting the export combination and Perform inference, calculate the output of each outlet and take the average as the final prediction.
9. A computer-readable storage medium, characterized in that A computer program is stored thereon, which, when executed by a processor, implements the multi-output neural network adversarial robustness evaluation method based on game theory as described in any one of claims 1 to 5 or the multi-output neural network defense method based on game theory as described in claim 6.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, it implements the multi-output neural network adversarial robustness evaluation method based on game theory as described in any one of claims 1 to 5 or the multi-output neural network defense method based on game theory as described in claim 6.