A Detection Device and Detection Method for Adversarial Attacks on Deep Neural Networks

By designing a deep neural network anti-attack detection device including filter plates, heating plates, cooling plates and shock absorption devices, the problems of insufficient heat dissipation, dust prevention and moisture prevention in the prior art are solved, and significant protection effects and improved the robustness of the neural network are achieved.

CN112839488BActive Publication Date: 2025-08-01GUANGZHOU GRG METROLOGY & TEST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110052417.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-15
Publication Date
2025-08-01
Estimated Expiration
2041-01-15

AI Technical Summary

Technical Problem

The existing deep neural network anti-attack detection devices lack effective heat dissipation, dust protection and moisture protection functions, and the existing methods cannot be applied to long-term and multi-dimensional anti-attacks, which affects the service life of the device and the robustness of the neural network.

Method used

A deep neural network anti-attack detection device is designed, including filter plates, heating plates, cooling plates and shock absorbing devices. The gas filtering, heating and cooling is carried out through the motor-driven fan blades. It combines the slidingly connected filter plates and limit columns to achieve dust prevention, moisture prevention and heat dissipation, and quickly repair attack data through an optimized anti-sample distance calculation method.

Benefits of technology

It achieves significant heat dissipation, dust protection and moisture protection effects, extends the service life of the device, and improves the robustness of the neural network by quickly repairing attack data, avoiding the recurrence of the same type of attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112839488B_ABST
    Figure CN112839488B_ABST
Patent Text Reader

Abstract

The present invention discloses a detection device and a detection method for adversarial attacks on deep neural networks, including a detection device body. On one side of the top of the detection device body, a first switch and a second switch are sequentially fixed. At the top inside the detection device body, a first filter plate is movably connected, and a second filter plate is movably connected at the top inside the detection device body, and the second filter plate is located at the bottom of the first filter plate. A fixing block is fixed on one side of the first filter plate, and a fixing column is fixed on one side of the second filter plate. This device can perform dust-proof and moisture-proof work. This detection method for adversarial attacks on deep neural networks can quickly and instantaneously repair the data chain at the attacked location, so as to ensure that the data can be quickly restored. After each attack, the attack samples can be retained, thus forming a growing adversarial attack tree, and further ensuring that each attack can avoid the same type of attack in the next time. Repeating this way can effectively improve the robustness of the neural network classifier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of detection, and more specifically, to a detection device and a detection method for adversarial attacks on deep neural networks. Background Art

[0002] Currently, the contributions of deep neural network algorithms in various fields are remarkable, successfully improving the recognition rate of traditional neural networks to a significant level. Although the accuracy of deep neural network algorithms is getting higher and higher, deep neural networks are very vulnerable to adversarial attacks, which may lead to abnormal behaviors such as misclassification of DNN models. For example, data points are deliberately constructed through an optimization process on neural networks with human-level accuracy.

[0003] Existing detection devices for this do not have a significantly effective heat dissipation function, cannot perform dust and moisture protection work, are not convenient for providing a good detection environment for the device, and greatly reduce the service life of the device.

[0004] Moreover, in existing detection methods for adversarial attacks on deep adversarial neural networks, most are targeted at specific adversaries and cannot be applied to long-term and multi-faceted adversaries.

[0005] Regarding the problems in the related art, no effective solution has been proposed yet. Summary of the Invention

[0006] An object of the present invention is to provide a detection device and a detection method for adversarial attacks on deep neural networks to solve the problems raised in the above background art.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] A detection device for adversarial attacks in deep neural networks, comprising a detection unit body. On one side of the top of the detection unit body, a first switch and a second switch are successively fixed. At the top inside the detection unit body, a first filter plate is movably connected. At the top inside the detection unit body, a second filter plate is movably connected, and the second filter plate is located at the bottom of the first filter plate. On one side of the first filter plate, a fixed block is fixed. On one side of the second filter plate, a fixed column is fixed. Inside the detection unit body, fixed rods are evenly distributed at the bottom of the first filter plate and the second filter plate. Inside the detection unit body and at the bottom of the first filter plate, a heating plate is fixedly arranged. Inside the detection unit body and at the bottom of the second filter plate, a cooling plate is fixedly arranged. At the bottom inside the detection unit body, motors are evenly distributed. The output end of the motor is fixed with a fan blade. On the top of the detection unit body, ventilation holes are evenly opened. On both sides of the bottom of the detection unit body, grooves are evenly opened. The heating plate is electrically connected to an external power supply through the first switch. The cooling plate is electrically connected to an external power supply through the second switch. The motor is electrically connected to an external power supply.

[0009] Furthermore, a shock absorption device is fixed at the bottom of the detection unit body. The shock absorption device includes a fixed box, a limit post, a fixed plate, and a spring. At the top of the fixed box, limit posts are evenly and movably connected. At the bottom of the limit post, a fixed plate is fixed. At the bottom of the fixed plate, springs are evenly fixed, and the springs are located at the bottom of the limit post.

[0010] Furthermore, a first sliding groove is opened on one side of the top of the detection unit body where the first filter plate is located. The volume of the first sliding groove matches the volume of the first filter plate. The first filter plate is slidably connected to the detection unit body through the first sliding groove.

[0011] Furthermore, a second sliding groove is opened on one side of the top of the detection unit body where the second filter plate is located. The volume of the second sliding groove matches the volume of the second filter plate. The second filter plate is slidably connected to the detection unit body through the second sliding groove.

[0012] Furthermore, the number of the limit posts is four, and the top of the limit post is fixedly connected to the detection unit body by welding.

[0013] Furthermore, a limit groove is opened at the position of the limit post on the top of the fixed box. The limit post is slidably connected to the fixed box through the limit groove.

[0014] According to another aspect of the present invention, a detection method for adversarial attacks in deep neural networks is provided. The method includes the following steps:

[0015] Input the sample data and preprocess the sample data to obtain positive data and negative data;

[0016] Organize the data, process the positive data according to the normal process, and issue a warning when it reaches the negative data;

[0017] At this time, calculate the distance of the minimum perturbation of the negative data;

[0018] Generate third-party data based on the relevant negative data and the distance of the minimum perturbation, and obtain adversarial samples through the third-party data;

[0019] Attack the positive data through the third-party data, replace it with the third-party data at the warning position, and restore the positive data.

[0020] Furthermore, the above preprocessing of the sample data is carried out in the following steps:

[0021] Clean the data, delete meaningless symbols and spaces;

[0022] Perform positive and negative processing on the data to obtain positive data and negative data.

[0023] Furthermore, the above criteria for positive and negative processing of the data are that the data beneficial to the data is labeled as positive data, and the data not beneficial to the data is labeled as negative data.

[0024] Furthermore, in the above attack on the positive data through the third-party data, the attack methods include one or more of the optimized adversarial sample distance calculation method, the greedy matching algorithm based on the Jacobian matrix, the fast gradient descent algorithm, the method of confusing deep learning, the DEEPFOOL algorithm, the CW (Carlini-Wagner Attack) algorithm, and the PGD (Project GradientDescent) algorithm.

[0025] Compared with the prior art, the present invention has the following beneficial effects:

[0026] (1). Connect the device to an external power supply, the motor can drive the fan blade to rotate, suck the external gas from the ventilation holes, the limit column can perform preliminary filtration work on the gas, filter out small particles such as dust inside it, effectively prevent the inhaled dust from adhering to the inside of the device and damaging the device. By pressing the first switch, the heating plate can heat the gas to achieve a drying effect, so that the device has a moisture-proof effect. The second filter plate can perform secondary drying work on the gas, making the moisture-proof effect of the device better. By pressing the second switch, the cooling plate can cool down the gas, making the heat dissipation effect of the device better, so that the device has a significant heat dissipation function, and at the same time can also perform dust-proof and moisture-proof work, so as to provide a good detection environment for the device.

[0027] (2) When the device receives an external collision or is being carried, it will shake, and the device will exert a certain pressure on the limit posts. At the same time, the fixed plate moves, and the fixed plate forces the spring to continuously repeat the deformation and restoration actions to absorb a certain amount of pressure, achieving the effect of shock absorption and greatly extending the service life of the device. The first filter plate is slidably connected to the main body of the detection piece through the first chute, and the second filter plate is slidably connected to the main body of the detection piece through the second chute, enabling the first filter plate and the second filter plate to be very conveniently replaced. The number of limit posts is four, and the top ends of the limit posts are fixedly connected to the main body of the detection piece by welding. The handling shock absorption device can work stably. The limit posts are slidably connected to the fixed box through the limit grooves, making the shock absorption effect of the device better.

[0028] (3) This method quickly and instantaneously repairs the data link at the attacked location, thus ensuring that the data can be quickly restored. At the same time, after each attack, the attack sample can be retained, thus forming a growing form of adversarial attack tree. Furthermore, it can ensure that each attack can avoid the same type of attack in the next time. Repeating this way can effectively improve the robustness of the neural network classifier. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0030] Figure 1 is a schematic structural diagram of the overall detection device for adversarial attacks of a deep neural network according to an embodiment of the present invention;

[0031] Figure 2 is a cross-sectional structural diagram of the main body of the detection piece of the detection device for adversarial attacks of a deep neural network according to an embodiment of the present invention;

[0032] Figure 3 is a cross-sectional structural diagram of the main body of the detection piece of the detection device for adversarial attacks of a deep neural network according to an embodiment of the present invention;

[0033] Figure 4 is a cross-sectional structural diagram of the fixed box of the detection device for adversarial attacks of a deep neural network according to an embodiment of the present invention;

[0034] Figure 5 is a flowchart of a method for detecting adversarial attacks of a deep neural network according to an embodiment of the present invention.

[0035] Reference numerals:

[0036] 1. Detection element body; 2. Shock absorption device; 3. First switch; 4. Second switch; 5. First filter plate; 6. Fixed block; 7. Second filter plate; 8. Fixed column; 9. Heating plate; 10. Cooling plate; 11. Fixed rod; 12. Motor; 13. Fan blade; 14. Fixed box; 15. Limit column; 16. Fixed plate; 17. Spring. Specific embodiments

[0037] Next, in combination with the accompanying drawings and specific embodiments, the invention will be further described:

[0038] Embodiment 1:

[0039] Please refer to Figures 1-4 , a detection device for adversarial attacks of a deep neural network according to an embodiment of the present invention includes a detection element body 1. On one side of the top of the detection element body 1, a first switch 3 and a second switch 4 are sequentially fixed. The top inside the detection element body 1 is movably connected to a first filter plate 5. The inside of the detection element body 1 is movably connected to a second filter plate 7, and the second filter plate 7 is located at the bottom of the first filter plate 5. One side of the first filter plate 5 is fixed with a fixed block 6. One side of the second filter plate 7 is fixed with a fixed column 8. Fixed rods 11 are evenly fixed at the bottom of the first filter plate 5 and the second filter plate 7 inside the detection element body 1. A heating plate 9 is fixedly provided at the bottom of the first filter plate 5 inside the detection element body 1. A cooling plate 10 is fixedly provided at the bottom of the second filter plate 7 inside the detection element body 1. Motors 12 are evenly fixed at the bottom of the detection element body 1. The output end of the motor 12 is fixed with a fan blade 13. Vent holes are evenly opened at the top of the detection element body 1. Grooves are evenly opened on both sides of the bottom of the detection element body 1. The heating plate 9 is electrically connected to an external power supply through the first switch 3. The cooling plate 10 is electrically connected to an external power supply through the second switch 4. The motor 12 is electrically connected to an external power supply.

[0040] With the above solution of the present invention, when the device is connected to an external power supply, motors 12 are evenly fixed at the bottom end inside the detection part body 1. The motors 12 can drive the fan blades 13 fixed to their output ends to rotate, sucking in external gas through the ventilation holes evenly opened at the top end of the detection part body 1. The gas first passes through the limit posts 15. The limit posts 15 can perform a preliminary filtering operation on the gas, filtering out small particles such as dust inside it, effectively preventing the inhaled dust from adhering to the inside of the device and damaging the device. Subsequently, the gas passes through the heating plate 9. By pressing the first switch 3, the heating plate 9 can heat the gas, achieving a drying effect and facilitating the device to have a moisture-proof effect. Then the gas passes through the second filter plate 7. The second filter plate 7 can perform a secondary drying operation on the gas, making the moisture-proof effect of the device better. Finally, the gas passes through the cooling plate 10. By pressing the second switch 4, the cooling plate 10 can cool down the gas, facilitating better heat dissipation of the device, enabling the device to have a remarkable heat dissipation function, and at the same time being able to perform dust-proof and moisture-proof work, facilitating the provision of a good detection environment for the device.

[0041] Embodiment Two:

[0042] Please refer to Figures 1-4 , a shock absorption device 2 is fixed to the bottom end of the detection part body 1. The shock absorption device 2 includes a fixed box 14, limit posts 15, a fixed plate 16, and springs 17. The top end of the fixed box 14 is evenly and movably connected with the limit posts 15. The bottom end of the limit posts 15 is fixed with a fixed plate 16. The bottom end of the fixed plate 16 is evenly fixed with springs 17, and the springs 17 are located at the bottom end of the limit posts 15. On one side of the first filter plate 5 at the top end of the detection part body 1, a first sliding groove is opened, and the volume of the first sliding groove matches the volume of the first filter plate 5. The first filter plate 5 is slidably connected to the detection part body 1 through the first sliding groove. On one side of the second filter plate 7 at the top end of the detection part body 1, a second sliding groove is opened. The volume of the second sliding groove matches the volume of the second filter plate 7, and the second filter plate 7 is slidably connected to the detection part body 1 through the second sliding groove. The number of the limit posts 15 is four, and the top end of the limit posts 15 is fixedly connected to the detection part body 1 by welding. At the position of the limit posts 15 on the top end of the fixed box 14, limit grooves are opened, and the limit posts 15 are slidably connected to the fixed box 14 through the limit grooves.

[0043] Through the above solution of the present invention, when the device receives an external collision or is carried, it will shake. The shock-absorbing device 2 includes a fixed box 14, a limit post 15, a fixed plate 16 and a spring 17. The device will exert a certain pressure on the limit posts 15 that are evenly and movably connected to the top end of the fixed box 14. At the same time, the limit posts 15 also drive the fixed plate 16 fixed to their bottom ends to displace. The fixed plate 16 forces the springs 17 that are evenly fixed to its bottom end to continuously repeat the deformation and restoration actions, absorbing a certain amount of pressure to achieve the shock-absorbing effect, greatly improving the service life of the device. The first filter plate 5 is slidably connected to the detection element body 1 through the first chute, and the second filter plate 7 is slidably connected to the detection element body 1 through the second chute, enabling the first filter plate 5 and the second filter plate 7 to be very conveniently replaced. The number of limit posts 15 is four, and the top ends of the limit posts 15 are fixedly connected to the detection element body 1 by welding. The handling shock-absorbing device 2 can work stably. A limit groove is provided at the position of the top end of the fixed box 14 where the limit posts 15 are located, and the limit posts 15 are slidably connected to the fixed box 14 through the limit groove, making the shock-absorbing effect of the device better.

[0044] As Figure 5 shown, according to an embodiment of the present invention, a method for detecting adversarial attacks of a deep neural network is provided, including the following steps:

[0045] Step S101: Input sample data and preprocess the sample data to obtain positive data and negative data;

[0046] Step S103: Organize the data, process the positive data according to the normal process, and issue a warning when it reaches the negative data;

[0047] Step S105: At this time, calculate the distance of the minimum perturbation of the negative data;

[0048] Step S107: Generate third-party data according to the relevant negative data and the distance of the minimum perturbation, and obtain an adversarial sample through the third-party data;

[0049] Step S109: Attack the positive data through the third-party data, replace it with the third-party data at the warning position, and restore the positive data.

[0050] In addition, when specifically implementing, the above preprocessing of the sample data includes the following steps:

[0051] Clean the data and delete meaningless symbols and spaces;

[0052] Perform positive and negative processing on the data to obtain positive data and negative data.

[0053] The standard for the above positive and negative processing of the data is to label the data beneficial to the data as positive data and the data not beneficial to the data as negative data.

[0054] Among the above-mentioned positive data for attacks using third-party data, the attack methods include one or more of an optimized adversarial sample distance calculation method, a greedy matching algorithm based on the Jacobian matrix, a fast gradient descent algorithm, a deep learning obfuscation method, a DEEPFOOL algorithm, a CW (Carlini-Wagner Attack) algorithm, and a PGD (Project Gradient Descent) algorithm.

[0055] In addition, when specifically used, in the above step S105, when calculating the distance of the minimum perturbation of the negative data, the calculation formula is:

[0056]

[0057] Among them, x represents the perturbation size. For the mnist dataset, the limit of p is (-0.3, 0.3). Among them, when p is larger, x is larger.

[0058] To facilitate the understanding of the above technical solution of the present invention, the working principle or operation method of the present invention in the actual process will be described in detail below.

[0059] In practical applications, the device is connected to an external power supply. At the bottom end inside the detection element body 1, motors 12 are evenly distributed and fixed. The motors 12 can drive the fan blades 13 fixed to their output ends to rotate, sucking in external gas from the ventilation holes evenly distributed at the top end of the detection element body 1. The gas first passes through the limit posts 15. The limit posts 15 can perform preliminary filtering of the gas, filtering out small particles such as dust inside it, effectively preventing the inhaled dust from adhering to the inside of the device and damaging the device. Subsequently, the gas passes through the heating plate 9. By pressing the first switch 3, the heating plate 9 can heat the gas, achieving a drying effect and facilitating the device to have a moisture-proof effect. Then the gas passes through the second filter plate 7. The second filter plate 7 can perform secondary drying of the gas, making the moisture-proof effect of the device better. Finally, the gas passes through the cooling plate 10. By pressing the second switch 4, the cooling plate 10 can cool down the gas, facilitating better heat dissipation of the device, enabling the device to have a significant heat dissipation function, and at the same time being able to perform dust-proof and moisture-proof work, facilitating providing a good detection environment for the device. When the device is subjected to external collision or being carried, it will shake. The shock-absorbing device 2 includes a fixed box 14, limit posts 15, a fixed plate 16, and a spring 17. The device will exert a certain pressure on the limit posts 15 that are evenly and movably connected to the top end of the fixed box 14. At the same time, the limit posts 15 also drive the fixed plate 16 fixed to their bottom ends to displace. The fixed plate 16 forces the springs 17 evenly distributed and fixed to its bottom end to continuously repeat the deformation and restoration actions, absorbing a certain amount of pressure to achieve the shock-absorbing effect, greatly improving the service life of the device. The first filter plate 5 is slidably connected to the detection element body 1 through a first sliding groove, and the second filter plate 7 is slidably connected to the detection element body 1 through a second sliding groove, enabling the first filter plate 5 and the second filter plate 7 to be very conveniently replaced. The number of limit posts 15 is four, and the top ends of the limit posts 15 are fixedly connected to the detection element body 1 by welding. The handling shock-absorbing device 2 can work stably. A limit groove is provided at the position of the top end of the fixed box 14 where the limit posts 15 are located, and the limit posts 15 are slidably connected to the fixed box 14 through the limit groove, making the shock-absorbing effect of the device better.

[0060] This method quickly and instantaneously repairs the data link at the attacked location, thus ensuring that the data can be quickly restored. At the same time, after each attack, the attack sample can be retained, thus forming a growing adversarial attack tree, and then ensuring that each attack can avoid the same type of attack in the next time. Repeating this way can effectively improve the robustness of the neural network classifier.

[0061] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirits of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A detection device for adversarial attacks on deep neural networks, characterized in that It includes a detection part body (1). On one side of the top end of the detection part body (1), a first switch (3) and a second switch (4) are successively fixed. At the top end inside the detection part body (1), a first filter plate (5) is movably connected. At the top end inside the detection part body (1), a second filter plate (7) is movably connected, and the second filter plate (7) is located at the bottom end of the first filter plate (5). On one side of the first filter plate (5), a fixed block (6) is fixed. On one side of the second filter plate (7), a fixed column (8) is fixed. Inside the detection part body (1), fixed rods (11) are evenly distributed at the bottom ends of the first filter plate (5) and the second filter plate (7). Inside the detection part body (1) and at the bottom end of the first filter plate (5), a heating plate (9) is fixedly arranged. Inside the detection part body (1) and at the bottom end of the second filter plate (7), a cooling plate (10) is fixedly arranged. At the bottom end inside the detection part body (1), motors (12) are evenly distributed. The output end of the motor (12) is fixed with a fan blade (13). On the top end of the detection part body (1), ventilation holes are evenly opened. On both sides of the bottom end of the detection part body (1), grooves are evenly opened. The heating plate (9) is electrically connected to an external power supply through the first switch (3). The cooling plate (10) is electrically connected to an external power supply through the second switch (4). The motor (12) is electrically connected to an external power supply.

2. The detection device for adversarial attacks on deep neural networks according to claim 1, characterized in that, At the bottom end of the detection part body (1), a shock absorption device (2) is fixed. The shock absorption device (2) includes a fixed box (14), a limit post (15), a fixed plate (16), and a spring (17). At the top end of the fixed box (14), limit posts (15) are evenly movably connected. At the bottom end of the limit post (15), a fixed plate (16) is fixed. At the bottom end of the fixed plate (16), springs (17) are evenly fixed, and the spring (17) is located at the bottom end of the limit post (15).

3. The detection device for adversarial attacks on deep neural networks according to claim 1, wherein On the top end of the detection part body (1) and on one side of the first filter plate (5), a first sliding groove is opened, and the volume of the first sliding groove matches the volume of the first filter plate (5). The first filter plate (5) is slidably connected to the detection part body (1) through the first sliding groove.

4. The detection device for adversarial attacks on deep neural networks according to claim 3, characterized in that, On the top end of the detection part body (1) and on one side of the second filter plate (7), a second sliding groove is opened. The volume of the second sliding groove matches the volume of the second filter plate (7), and the second filter plate (7) is slidably connected to the detection part body (1) through the second sliding groove.

5. The detection device for adversarial attacks on deep neural networks according to claim 2, wherein The number of the limit posts (15) is four, and the top ends of the limit posts (15) are fixedly connected to the detection part body (1) by welding.

6. The detection device for adversarial attacks on deep neural networks according to claim 5, wherein At the top end of the fixed box (14) and at the position of the limit post (15), a limit groove is opened, and the limit post (15) is slidably connected to the fixed box (14) through the limit groove.

7. A detection method for adversarial attacks on deep neural networks, which is used for the use of the detection component body described in any one of claims 1-6, characterized in that, It includes the following steps: Input the sample data and preprocess the sample data. The preprocessing includes performing positive and negative processing on the sample data to obtain positive data and negative data. The standard for the positive and negative processing is to label the data that is beneficial to the data as positive data and the data that is not beneficial to the data as negative data, resulting in positive data and negative data; Organize the data, process the positive data according to the normal process, and issue a warning when it reaches the negative data; At this time, calculate the distance of the minimum perturbation of the negative data; Generate third-party data based on the relevant negative data and the distance of the minimum perturbation, and obtain adversarial samples through the third-party data; Attack the positive data through the third-party data, replace it with the third-party data at the warning position, and let the positive data recover.

8. The detection method for adversarial attacks on deep neural networks according to claim 7, wherein, The preprocessing of the sample data further includes the following steps: Clean the data and delete meaningless symbols and spaces.

9. A detection method for adversarial attacks on deep neural networks according to claim 7, characterized in that, In the above attack on the positive data through the third-party data, the attack methods include one or more of an optimized adversarial sample distance calculation method, a greedy matching algorithm based on the Jacobian matrix, a fast gradient descent algorithm, a method of confusing deep learning, the DEEPFOOL algorithm, the CW algorithm, and the PGD algorithm.

Citation Information

Patent Citations

  • Detection device for attack adversarial by deep neural network

    CN214381950U