Malicious sample purification-based model test adaptive method and system

By calculating the sample significance index, paired samples are selected and purified samples are generated, which solves the problem of insufficient utilization of test data in existing technologies, achieves more efficient model parameter optimization and data utilization, and improves the adaptability of the model in dynamic environments.

CN120766055APending Publication Date: 2025-10-10HUAZHONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510792208.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

The existing adaptive method for model testing results in a large amount of test data not being fully utilized after distinguishing between benign and malicious samples, resulting in data waste and making it difficult to strike a balance between stable optimization and full utilization.

Method used

By calculating the significance index of the sample, the benign sample with the largest significance distance from the malicious sample is selected as the paired sample, and the image fusion technology is used to generate the purified sample. The model parameters are optimized by minimizing the total loss function to generate the purified sample and its pseudo label.

Benefits of technology

It improves the utilization rate of test data, reduces the pressure of data collection, achieves better model parameter optimization effect, and improves the generalization performance of the model in a dynamically changing environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120766055A_ABST
    Figure CN120766055A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field related to computer vision, and discloses a self-adaption method and system during model testing based on malicious sample purification, and the method comprises the steps: dividing a current sample batch into benign samples and malicious samples; calculating a significance index of each sample; determining to-be-purified samples in the current sample batch, wherein the to-be-purified samples comprise malicious samples; for each to-be-purified sample, selecting a benign sample with the largest significance distance from the to-be-purified sample as a paired sample, fusing the to-be-purified sample and the paired sample by using an image fusion technology, and generating a purified sample and a pseudo label of a model prediction probability of the purified sample; and in combination with the current sample batch and the obtained purified sample, performing parameter optimization on the current to-be-optimized model by taking minimization of a total loss function as an optimization target. By means of the scheme, the utilization rate of the test data can be increased, and therefore a good model parameter optimization effect can be achieved by collecting less test data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field related to computer vision, and more specifically, relates to a method and system for adaptively testing a model based on malicious sample purification. Background Art

[0002] After pre-training a machine learning model using local training data, it is deployed to the real world (test environment) for actual testing applications. Due to factors such as noise, image blur, digital compression, weather and lighting conditions, there will be a distribution offset between the test data in the test environment and the data distribution of the pre-trained training data. This will cause the prediction performance of the machine learning model in the test environment to drop significantly. The adaptive method during model testing aims to use unlabeled test samples to optimize the parameters of the pre-trained model in real time, achieve parameter fine-tuning, and enable it to quickly adapt to the dynamically changing test environment, thereby improving the generalization performance of the model in real-world scenarios.

[0003] In order to ensure better optimization results, existing research usually adopts a sample selection strategy, which distinguishes "benign" and "malicious" samples by designing sample screening criteria (such as the conditional entropy of the model output, the probability of the model prediction, and the model's prediction invariance to the enhanced samples), and focuses on using benign samples for self-adaptation when testing the model. For example, the Chinese invention patent specification CN119360123A discloses a sample screening method based on the pseudo-label probability difference score, which inputs the benign samples after screening out into an energy model, and constructs a joint optimization target in combination with the energy optimization target. For another example, the Chinese invention patent specification CN119339127A discloses a loss function weighting method, which dynamically adjusts the influence of samples on training through uncertainty scores to reduce the effect of high-uncertainty samples.

[0004] Although the above methods improve the stability of model parameter optimization by filtering or implicitly screening malicious samples, they also lead to a large amount of test data not being fully utilized, resulting in data waste. Therefore, when testing models based on sample selection, adaptive methods find it difficult to achieve a good balance between stable optimization and full utilization of test samples. Summary of the Invention

[0005] In response to the above-mentioned defects or improvement needs of the prior art, the present invention provides a model testing adaptive method and system based on malicious sample purification, which aims to improve the utilization rate of test data, thereby reducing the pressure of test data collection. By collecting less test data and executing the model testing adaptive method, better model parameter optimization effect can be achieved.

[0006] To achieve the above objectives, according to a first aspect of the present invention, a method for adaptive model testing based on malicious sample purification is provided, which includes:

[0007] Dividing a current sample batch used in a current test step into benign samples and malicious samples, wherein the samples are test images;

[0008] Calculate the significance index of each sample in the current sample batch, where the significance index represents the degree of influence of the sample on the entropy loss function of the current model to be optimized;

[0009] Determine the samples to be purified in the current sample batch, wherein the samples to be purified include the malicious samples; for each sample to be purified, select a benign sample with the largest significance distance from the sample to be purified from a memory bank storing benign samples as a paired sample; fuse the sample to be purified and its paired sample using image fusion technology to generate a pseudo label of the purified sample and its model-predicted probability;

[0010] Combining the current sample batch and the obtained purified samples, the parameters of the current model to be optimized are optimized with the optimization goal of minimizing the total loss function; the total loss function includes the superposition of a first entropy loss function part focusing on the impact of its benign samples for the current sample batch and a second entropy loss function part for the purified samples.

[0011] Optionally, the method of dividing benign samples and malicious samples includes: inputting each sample in the current sample batch into the current model to be optimized for prediction, and dividing the current sample batch into benign samples and malicious samples according to a confidence index of the prediction result.

[0012] Optionally, the saliency index is any one of an image pixel-level saliency index, a data feature-level saliency index, a model output-level saliency index, or a combination of the above.

[0013] The image pixel-level significance index is the gradient of the entropy loss function with respect to the sample image pixels;

[0014] The data feature-level significance index is the gradient of the entropy loss function with respect to the sample data feature, and the sample data feature is the data feature extracted after the image sample is input into the model to be optimized;

[0015] The model output level significance indicator is the gradient of the entropy loss function with respect to the model output.

[0016] Optionally, the database is a shared database, and each test step selects benign samples for pairing from the same memory bank. Alternatively, the memory bank is a temporary memory bank, which only temporarily stores benign samples in the current test step and is deleted at the end of the current test step. Different test steps correspond to different temporary memory banks, and each test step only selects benign samples for pairing from its temporary memory bank.

[0017] Optionally, if the data distribution of the test data is consistent with the data distribution of the training data used in model pre-training, a shared database is used and the shared database is a static database, which stores the benign samples used during model pre-training, their significance indicators, and model outputs;

[0018] If the distribution of test data changes dynamically, a shared database is used, and the shared database is a first-in-first-out dynamic queue cache. In each test step, the generated benign samples, their significance indicators, and model outputs are stored at the end of the queue, and the head of the queue is removed when the storage capacity is exceeded.

[0019] If the focus is on reducing memory or improving response speed, use a temporary memory bank.

[0020] Optionally, the calculation formula for the significance distance between any two samples is:

[0021]

[0022] Where x i and x j There are two different samples, For sample x i and x j The significance distance, ε(x i ),ε(x j ) are samples x i and x j Significance index, Cosine() is the cosine function.

[0023] Optionally, the samples to be purified include only malicious samples in the current sample batch, or the samples to be purified include all samples in the current sample batch.

[0024] Optionally, the fusion formula of the image fusion technology is:

[0025]

[0026] Where x i For the sample to be purified, is x i Paired samples of is the model prediction probability when the input is x i is the model prediction probability when the input is , the fusion coefficient λ is a set value, is the purified sample obtained by fusing x i and is the pseudo label of .

[0027] Optionally, the expression of the first entropy loss function part is as follows:

[0028]

[0029] In the formula, N bs is the number of samples in the current batch, C represents the number of predicted categories, x ti is the i-th sample in the sample batch corresponding to the t-th test step, I is a sample selection indication function, used to improve the weight of benign samples, θ is a module parameter, and p c (x ti , θ) is the prediction probability of the model for the c-th category when the input is x ti .

[0030] The expression of the second entropy loss function part is as follows:

[0031]

[0032] In the formula, N' bs is the number of purified samples, is the purified sample generated by fusing the to-be-purified sample i and its paired sample j, is the prediction probability of the c-th category in the pseudo label of the purified sample , and is the prediction probability of the model for the c-th category when the input is .

[0033] According to the second aspect of the present application, a model test self-adaptive system based on malicious sample purification is provided, which comprises a memory and a processor, and the memory stores a computer program, wherein the processor implements the steps of the method according to any one of the above when executing the computer program.

[0034] Overall, compared with the prior art, the above technical solutions conceived by the present application mainly have the following beneficial effects:

[0035] ​​In the present invention, after distinguishing benign samples from malicious samples in a sample batch, the malicious samples are not discarded directly. Instead, the benign samples with the largest significance distance from the malicious samples are calculated based on the significance index as paired samples. The paired samples can compensate for the influence of the malicious samples on the entropy loss function. Therefore, by fusing the malicious samples and the paired samples with the compensatory effect, the malicious samples can be purified, and purified samples that retain the distribution characteristics of the test data and suppress noise interference are generated, thereby compensating for the loss of model parameter optimization caused by filtering malicious samples. The obtained purified samples can participate in the model optimization together with the sample batch, and due to the addition of the purified samples, the loss function is improved. The loss function for the purified samples is added on the basis of the original loss function for the sample batch. Based on the above operations, the utilization rate of the test data can be improved, and thus better model parameter optimization effects can be achieved by collecting less test data. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 is a flowchart of the steps of the self-adaptation method during model testing in one embodiment of the present invention;

[0037] Figure 2 This is a diagram of the specific operation process of the self-adaptive method during model testing in one embodiment of the present invention. DETAILED DESCRIPTION

[0038] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below may be combined with each other as long as they do not conflict with each other.

[0039] The present invention provides a self-adaptive method for model testing based on malicious sample purification, such as Figure 1 FIG. 1 is a flow chart showing the steps of the adaptive method for model testing in one embodiment of the present invention. Figure 2 FIG. 1 is a diagram showing a specific operation process of the self-adaptation method during model testing in one embodiment of the present invention. The following is a detailed description of the steps involved.

[0040] S1. Divide the current sample batch used in the current test step into benign samples and malicious samples.

[0041] Specifically, the sample is an image, and the model to be optimized is an image processing model. Optimizing model parameters through adaptive methods during model testing is a continuous iterative process. Each test step uses a batch of test images to optimize parameters until the optimization is completed.

[0042] At each test step, the corresponding original test image samples can be divided into benign samples and malicious samples using existing methods.

[0043] In one embodiment, each test image sample in the current test step is input into the current model to be optimized for prediction, and the corresponding test image sample batches are divided into benign samples and malicious samples according to the confidence index of the prediction results.

[0044] For example, the test image sample batch of the current test step is recorded as x test , use the model to analyze each sample x i ∈x test Make predictions, calculate the confidence index of each sample prediction result, and take samples whose confidence index is greater than the confidence index threshold as benign samples x + , otherwise it is considered as a malicious sample x - Among them, the confidence indicator can be the entropy of the model output, the probability of the model prediction, or the invariance of the model's prediction to the enhanced samples.

[0045] In one embodiment, each test image sample may be preprocessed first, the input image may be adjusted to a size of 224x224, normalized, and converted into a tensor form to ensure the standardization and consistency of the data.

[0046] S2. Calculate the significance index of each sample in the current sample batch. The significance index represents the degree of influence of the sample on the entropy loss function of the current model to be optimized. Store the benign samples, their significance indexes, and model outputs in the memory bank.

[0047] Specifically, the input sample is defined as x, and its significance index is marked as ε(x). The significance index ε(x) used can be any one of the image pixel-level significance index, data feature-level significance index, model output-level significance index, or a combination of the above.

[0048] Define the input sample as x, the parameter of the current model to be optimized as θ, after the sample x is input into the current model to be optimized, the extracted sample data feature is recorded as h = φ (x), and the obtained model output is recorded as z = f θ (x), the corresponding entropy loss function is recorded as

[0049] Specifically, the entropy loss function It can be expressed as follows:

[0050]

[0051] Where p c (x,θ) is the model's predicted probability for category c when the input is x.

[0052] The image pixel-level significance indicator is the gradient of the entropy loss function with respect to the pixels of the sample image, denoted as In specific calculation, the gradient of the entropy loss function with respect to each image sample can be calculated by the chain rule to quantify the contribution of the change of a single pixel to the reduction of the conditional entropy of the model output.

[0053] The data feature-level significance indicator is the gradient of the entropy loss function with respect to the sample data feature, which is the data feature extracted after inputting the image sample into the model to be optimized. Specifically, the input feature of the fully connected layer at the end of the model can be selected as the sample data feature, denoted as In specific calculation, the gradient of the entropy loss function with respect to each sample data feature can be calculated by the chain rule to quantify the contribution of the change of the sample data feature to the reduction of the conditional entropy of the model output. The sample data feature h = φ(x) is the data feature extracted by the deep neural network model. The data feature-level significance can filter out irrelevant pixel interference and is more inclined to encode the contribution of the test sample to the optimization of the model parameters at the semantic level.

[0054] The model output-level significance indicator is the gradient of the entropy loss function with respect to the model output, denoted as where z = f θ (x) is the model output vector. In specific calculation, the gradient can be calculated by the following formula:

[0055]

[0056] In the formula, p = σ(z) is the model prediction probability obtained by normalizing the output vector z. The direct output of the model is a value without range constraint, which needs to be normalized to the 0-1 interval by the softmax function to obtain the corresponding prediction probability. ⊙ represents element-level multiplication.

[0057] The model output-level significance indicator does not need to be back-propagated to the bottom-level features, has high calculation efficiency, and is directly related to the final decision of the model.

[0058] S3, determining the sample to be purified in the current sample batch, the sample to be purified including malicious samples; for each sample to be purified, selecting a benign sample with the largest significance distance from the memory bank storing benign samples as a paired sample, and using image fusion technology to fuse the sample to be purified and its paired sample to generate a purified sample and a pseudo-label of the model prediction probability of the purified sample.

[0059] The samples to be purified include malicious samples. Specifically, the samples to be purified may be only malicious samples in the current sample batch, or all samples in the current sample batch. The specific method can be selected based on actual circumstances. If full-batch purification is implemented, that is, the entire batch of samples is used for search and matching, this method fully utilizes the distribution characteristics of all samples. Because it covers the complete statistical characteristics of the test data, it has the best performance and reflects the important role of all samples in the current batch. If only malicious samples are searched and matched, sample purification can be achieved quickly, and the performance is still better than that of model adaptive methods that do not use purification strategies.

[0060] In one embodiment, the database is a shared database, and each test step selects benign samples for pairing from the same memory bank. Alternatively, the memory bank is a temporary memory bank, which only temporarily stores benign samples in the current test step and is deleted at the end of the current test step. Different test steps correspond to different temporary memory banks, and each test step only selects benign samples for pairing from its temporary memory bank.

[0061] More specifically, when different test steps share a memory bank, the memory bank can be a static database or a first-in-first-out dynamic queue cache. For example, a static database with a size of 1000 or a first-in-first-out queue with a maximum length of 1000 can be selected.

[0062] In actual applications, different data storage methods can be selected according to the characteristics of different data domains.

[0063] If the data distribution of the test data is consistent with the data distribution of the training data used in model pre-training, and the prior knowledge during training can be quickly reused, a shared database is used and the shared database is a static database. The static database stores the benign samples used in model pre-training, their significance indicators, and model outputs. The benign samples, their significance indicators, and model outputs constitute triplet data and are stored in the static database. When the adaptive method is used when executing the model test, each test step selects a benign sample for pairing from the static database.

[0064] If the test data distribution changes dynamically, for example, in a continuously evolving test environment where the test data distribution also undergoes gradual drift, a shared database is used, and a dynamic queue cache with first-in, first-out (FIFO) is used. At each test step, the generated benign samples, their significance indicators, and model outputs are stored at the end of the queue. When the storage capacity is exceeded, the head of the queue is removed, thus ensuring that the queue always retains the latest test distribution characteristics. This mechanism enables the model to continuously adapt to the gradual changes in the test environment by dynamically updating the historical sample set, preventing outdated data from interfering with the current optimization.

[0065] If reducing memory usage or improving response speed is the priority, a temporary memory repository can be used. This approach is more suitable for real-time processing in online scenarios with low storage constraints or fast response times. Specifically, the full data for the current test batch is treated as a temporary memory repository, eliminating the need to store additional historical samples. This mechanism eliminates the overhead of maintaining historical data and enables rapid adaptation through instantaneous data interaction within a batch. It is particularly suitable for real-time tasks with stringent requirements for storage capacity and response speed.

[0066] After determining the memory library, for each sample to be purified, the benign sample with the largest significance distance from it is selected from the memory library as a paired sample.

[0067] By selecting the benign sample with the largest significance distance from the memory library, we can obtain the benign sample with the strongest objective function compensation effect with the current sample to be purified. By fusing the two, we can achieve a better purification effect.

[0068] Specifically, if a static database is used, the benign sample with the largest significance distance is selected from the static database; if a first-in-first-out dynamic queue is used, the benign sample with the largest significance distance is selected from the first-in-first-out dynamic queue; if a temporary memory library is used, the benign sample with the largest significance distance is selected from the temporary memory library.

[0069] Among them, the significance distance is the degree of difference of the significance index. Calculate the sample x i and x j The significance distance The formula is:

[0070]

[0071] Where, ε(x i ),ε(x j ) are samples x i and x j Significance indicators.

[0072] According to the calculated current sample x i The significance distance relative to the sample in the memory library Retrieve the current sample x i Matched benign samples The specific search formula is:

[0073]

[0074] in is the sample set in the memory bank.

[0075] In one embodiment, the matched sample pairs are used Combine image fusion technology to generate purified samples and its pseudo labels The fusion formula is as follows:

[0076]

[0077] Where, For input x i The model predicts the probability when For input The model prediction probability at the time is , and the fusion coefficient λ is a set value, which can be specifically 0.5. It can be understood that other commonly used image fusion technologies can also be used.

[0078] S4. Combining the current sample batch and the obtained purified samples, the parameters of the current model to be optimized are optimized with the optimization goal of minimizing the total loss function; the total loss function includes the superposition of the first entropy loss function part for the current sample batch that focuses on the impact of its benign samples and the second entropy loss function part for the purified samples.

[0079] Specifically, due to the introduction of purified samples, the final loss function also includes two parts, namely the first entropy loss function part for the current sample batch and the second entropy loss function part for the purified samples.

[0080] The first entropy loss function is actually the original adaptive loss function during model testing, which is recorded as Specifically, it can be expressed as:

[0081]

[0082] Where N bs is the number of samples in the current batch, C represents the number of predicted categories, x ti is the i-th sample in the sample batch corresponding to the t-th test step, I is the sample selection indicator function used to increase the weight of benign samples, θ is the module parameter, p c (x ti ,θ) is the input x ti The model predicts the probability of the cth category.

[0083] Where I is the sample selection indicator function, which is used to screen benign samples. For example, the sample selection indicator function can be expressed as:

[0084]

[0085] Where, Indicates that when input x ti When the calculated confidence score is higher than the set threshold S0, the indicator function returns 1, otherwise it returns 0.

[0086] On this basis, the second entropy loss function is added as the purification loss, which is recorded as The purification loss is the entropy loss function for the purified samples, which can be expressed as:

[0087]

[0088] Where N' bs is the number of purified samples, is the purified sample generated by fusing the sample to be purified i and its paired sample j, To purify the sample The predicted probability for the c-th category in the pseudo-label, For input The model predicts the probability of the cth category.

[0089] The total loss function can be expressed as:

[0090]

[0091] Where α is a hyperparameter used to balance the adaptive loss and purification loss during the original model testing.

[0092] The model parameters θ are updated using an optimizer such as stochastic gradient descent, adapting the model to the target domain during testing, thus achieving model test-time adaptation. Because model test-time adaptation involves fine-tuning the parameters of a pre-trained model, in some embodiments, only some parameters may be updated, such as those of normalization layers such as batch normalization, layer normalization, and group normalization.

[0093] The present invention also relates to an adaptive system for electronic model testing based on malicious sample purification, including a memory and a processor, the memory storing a computer program, and the processor implementing the steps of the above method when executing the computer program.

[0094] The system can be installed on computing devices such as desktop computers, notebooks, PDAs and cloud servers. The processor can be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The memory can be used to store computer programs and / or modules, and the processor can run or execute computer programs and / or modules stored in the memory, as well as call data stored in the memory, to realize various functions of the electronic device.

[0095] In general, the present invention proposes a method for model test-time adaptation based on purifying malicious samples (Purifying Malicious Samples for Test-Time Model Adaptation, PTTA). After distinguishing between "benign" and "malicious" samples, the significance distance is used to retrieve benign samples that have the greatest compensatory effect on malicious samples. Then, the purified samples are generated through image fusion technology for test-time adaptation of deep neural network models, thereby achieving efficient use of test data. Compared with existing methods, this method has greatly improved in various computer vision and machine learning tasks such as image classification, semantic segmentation, and adversarial defense. It effectively utilizes malicious samples filtered by traditional methods, improves test data utilization, and avoids data waste.

[0096] The effects of the present invention will be verified below.

[0097] In order to show the technical effect of the present application, the ImageNet-C dataset is used as the test carrier, and experiments are carried out on the highest damage level of 15 data damage modes (Gaussian noise, shot noise, impulse noise, defocus blur, glass blur, motion blur, scaling blur, snow, frost, fog, brightness change, contrast change, elastic transformation, pixelization, and JPEG compression) included in the ImageNet-C dataset. The experiment includes the results of three settings: test-time adaptation under single scene, that is, each experiment is carried out independently under each damage, and the model parameters are reset in different damage; test-time adaptation under continuous changing scene, that is, the model continuously optimizes in the dynamic changing environment of the order of 15 damages, and the model parameters are not reset; lifelong test-time adaptation, that is, longer continuous changing scene, taking the order of 15 damages as a round, and repeating 10 rounds. The experimental results are shown in Table 1, wherein SAR, EATA, and DeYO belong to the prior art, and schemes 1, 2, and 3 of the present application are schemes for improving data utilization by purifying operation on the basis of SAR, EATA, and DeYO, respectively, and the implementation method is not described again.

[0098] Table 1 Test-time adaptation results of the method of the present application under different settings

[0099]

[0100] Through experimental comparison, it can be known that, due to the high data utilization, compared with the prior art, the present application has better optimization effect on the basis of the same amount of test data, in other words, if the same optimization effect is achieved, the present application also requires less amount of test data.

[0101] The technical features of the above-described embodiments can be combined arbitrarily, and in order to make the description simple, all possible combinations of the technical features in the above-described embodiments are not described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present application. It should be noted that the "in an embodiment of the present application", "for example", "such as" and the like of the present application are intended to illustrate the present application, and are not used to limit the present application.

[0102] The above-described embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent application. It should be noted that for ordinary skilled persons in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the protection scope of the present application.

Claims

1. A model-based adaptive testing method based on malicious sample purification, characterized by: include: Dividing a current sample batch used in a current test step into benign samples and malicious samples, wherein the samples are test images; Calculate the significance index of each sample in the current sample batch, where the significance index represents the degree of influence of the sample on the entropy loss function of the current model to be optimized; Determine the samples to be purified in the current sample batch, wherein the samples to be purified include the malicious samples; for each sample to be purified, select a benign sample with the largest significance distance from the sample to be purified from a memory bank storing benign samples as a paired sample; fuse the sample to be purified and its paired sample using image fusion technology to generate a pseudo label of the purified sample and its model-predicted probability; Combining the current sample batch and the obtained purified samples, the parameters of the current model to be optimized are optimized with the optimization goal of minimizing the total loss function; the total loss function includes the superposition of a first entropy loss function part focusing on the impact of its benign samples for the current sample batch and a second entropy loss function part for the purified samples.

2. The self-adaptive method for model testing according to claim 1, wherein: The method for dividing benign samples and malicious samples includes: inputting each sample in the current sample batch into the current model to be optimized for prediction, and dividing the current sample batch into benign samples and malicious samples according to the confidence index of the prediction result.

3. The self-adaptive method during model testing according to claim 1, wherein: The saliency index is any one of an image pixel-level saliency index, a data feature-level saliency index, a model output-level saliency index, or a combination of the above; The image pixel-level significance index is the gradient of the entropy loss function with respect to the sample image pixels; The data feature-level significance index is the gradient of the entropy loss function with respect to the sample data feature, and the sample data feature is the data feature extracted after the image sample is input into the model to be optimized; The model output level significance indicator is the gradient of the entropy loss function with respect to the model output.

4. The self-adaptive method for model testing according to claim 1, wherein: The database is a shared database, and each test step selects benign samples for pairing from the same memory bank. Alternatively, the memory bank is a temporary memory bank, which only temporarily stores benign samples in the current test step and is deleted at the end of the current test step. Different test steps correspond to different temporary memory banks, and each test step only selects benign samples for pairing from its temporary memory bank.

5. The self-adaptive method during model testing according to claim 4, characterized in that: If the data distribution of the test data matches the data distribution of the training data used in model pre-training, a shared database is used and the shared database is a static database that stores the benign samples used during model pre-training, their significance indicators, and model outputs; If the distribution of test data changes dynamically, a shared database is used, and the shared database is a first-in-first-out dynamic queue cache. In each test step, the generated benign samples, their significance indicators, and model outputs are stored at the end of the queue, and the head of the queue is removed when the storage capacity is exceeded. If the focus is on reducing memory or improving response speed, use a temporary memory bank.

6. The self-adaptive method during model testing according to any one of claims 1 to 5, characterized in that: The calculation formula for the significance distance between any two samples is: Where x i and x j There are two different samples, For sample x i and x j The significance distance, ε(x i ),ε(x j ) are samples x i and x j Significance index, Cosine() is the cosine function.

7. The self-adaptive method during model testing according to any one of claims 1 to 5, characterized in that: The samples to be purified include only malicious samples in the current sample batch, or the samples to be purified include all samples in the current sample batch.

8. The self-adaptive method during model testing according to any one of claims 1 to 5, characterized in that: The fusion formula of the image fusion technology is: Where x i For the sample to be purified, is x i Paired samples of For input x i The model predicts the probability when For input The model prediction probability when , the fusion coefficient λ is the set value, is x i and The purified samples obtained by fusion, for Pseudo labels.

9. The self-adaptive method during model testing according to any one of claims 1 to 5, characterized in that: The first entropy loss function part The expression is: Where N bs is the number of samples in the current batch, C represents the number of predicted categories, x ti is the i-th sample in the sample batch corresponding to the t-th test step, I is the sample selection indicator function used to increase the weight of benign samples, θ is the module parameter, p c (x ti ,θ) is the input x ti The model predicts the probability of the cth category when The second entropy loss function The expression is: Where N' bs is the number of purified samples, is the purified sample generated by fusing the sample to be purified i and its paired sample j, To purify the sample The predicted probability for the c-th category in the pseudo-label, For input The model predicts the probability of the cth category.

10. A model-based adaptive system for malicious sample purification during testing, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 9 are implemented.

Citation Information

Patent Citations

  • Self-adaptive target identification method based on sample uncertainty estimation during online test

    CN119339127A

  • Image classification method based on test time self-adaption

    CN119360123A