A target detection adversarial robustness improvement method based on dual-domain feature enhancement

By employing a dual-domain feature enhancement method, robust features are generated by utilizing robust score mask separation and calibration features, combined with frequency domain information. This addresses the vulnerability of existing models to adversarial attacks and improves the robustness and accuracy of target detection.

CN122454147APending Publication Date: 2026-07-24UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
UNIV OF ELECTRONICS SCI & TECH OF CHINA
Filing Date
2026-04-30
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing target detection models are vulnerable to adversarial attacks due to insufficient discriminative power of spatial domain features and inadequate utilization of frequency domain information. This makes the models susceptible to adversarial attacks, making it difficult to distinguish between robust and non-robust features and easily affected by noise.

Method used

A dual-domain feature enhancement method is adopted, which combines the spatial and frequency domains, uses robust score masks to separate robust and non-robust features, performs feature deconstruction and calibration, and achieves feature fusion through a cross-attention mechanism to generate the final robust features.

Benefits of technology

It significantly improves the robustness and detection performance of the model against adversarial attacks, especially in the detection of small targets and complex backgrounds, and has strong general defense capabilities and cross-dataset generalization capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122454147A_ABST
    Figure CN122454147A_ABST
Patent Text Reader

Abstract

The application discloses a target detection anti-robustness improvement method based on double-domain feature enhancement, and relates to the technical field of artificial intelligence security. The method comprises the following steps: acquiring an original image and extracting spatial domain features; using a robustness score mask to deconstruct the features into a robust subspace and a non-robust subspace; performing bidirectional calibration on the non-robust features through an interference identification mask to suppress noise and enhance useful information; projecting the features into a frequency domain by using a discrete Fourier transform, identifying and fusing high-frequency useful components to realize functional disentanglement and high-frequency recalibration; and fusing the double-domain features through a cross-attention mechanism, generating more robust representations with stronger discrimination, and outputting detection results. Through spatial-frequency double-domain collaborative optimization, the application solves the problems that a traditional model is difficult to distinguish non-robust features and frequency information utilization is insufficient, maintains high precision of clean samples, and significantly improves the safety and reliability of the model against adversarial attacks.
Need to check novelty before this filing date? Find Prior Art