Asymmetric robustness of classification in adversarial environments

CN113011453BActive Publication Date: 2026-08-21ROBERT BOSCH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011503286.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-20
Filing Date
2020-12-18
Publication Date
2026-08-21
Estimated Expiration
2040-12-18

AI Technical Summary

Technical Problem

例如,针对输入的细微不可觉察的改变可能引起针对分类器的输出和行为的剧烈改变

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113011453B_ABST
    Figure CN113011453B_ABST
Patent Text Reader

Abstract

Asymmetric robustness to classification in adversarial environments. A computational method for training a classifier. The method includes receiving a training dataset consisting of pairs of training input signals and output signals, the classifier being parameterized by parameters, receiving a class-dependent allowed perturbation for each of at least two different classes, and including a first class-dependent allowed perturbation for a first class and a second class-dependent allowed perturbation for a second class, and receiving a loss function; the method further includes partitioning the training dataset into a first subset labeled with a first label and a second subset labeled with a second label. The method also includes computing a first loss in response to the first subset and the first class-dependent allowed perturbation, and computing a second loss in response to the second subset and the second class-dependent allowed perturbation. The method also includes updating the parameters in response to the first loss and the second loss to obtain updated parameters.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to computational methods and computer systems for providing asymmetric robustness for classification in adversarial environments, including computational methods and computer systems for training classifiers (e.g., machine learning (ML) algorithms) in adversarial environments. Background Technology

[0002] Supervised machine learning (ML) algorithms (also known as classifiers) include deep learning algorithms built on deep neural networks. ML algorithms are vulnerable to adversarial attacks on their input space. Classifiers can be used... It will be marked by The indicated feature mapping to class In the middle. To Adversarial attacks correspond to imperceptible perturbations. When this imperceptible disturbance Add to input At that time, the classifier Output different results, i.e. Imperceptibility often occurs through constraint perturbations. of Norms, or the perceived imperceptibility through forced alteration, such as by adding operators to distinguish undisturbed data. With disturbance data The difficulty is to be modeled as a set of allowed perturbations. Membership. The sensitivity of classifiers to adversarial attacks posed by malicious agents or noise sources has raised concerns about their use in mission-critical applications. For example, subtle, imperceptible changes to the input can trigger attacks against the classifier. Dramatic changes in output and behavior. Summary of the Invention

[0003] According to one embodiment, a computational method for training a classifier is disclosed. The method includes receiving a training dataset consisting of pairs of training input signals and corresponding output signals. The classifier is parameterized by parameters and configured to classify input signals obtained from a sensor into at least two distinct classes, including a first class and a second class. The method further includes receiving class-dependent allowed perturbations for each of the at least two distinct classes, including a first class-dependent allowed perturbation for the first class and a second class-dependent allowed perturbation for the second class. The method further includes receiving a loss function. The computational method also includes partitioning the training dataset into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class. The computational method further includes calculating a first loss in response to the first subset and the first class-dependent allowed perturbation, and calculating a second loss in response to the second subset and the second class-dependent allowed perturbation. The computational method also includes updating parameters in response to the first loss and the second loss to obtain updated parameters.

[0004] In a second embodiment, a non-transitory computer-readable medium is disclosed, comprising computer-executable instructions and memory for storing the computer-executable instructions. When executed by a computer's processor, the computer-executable instructions perform a function including receiving a training dataset consisting of pairs of training input signals and corresponding output signals. A classifier is parameterized by parameters and configured to classify input signals obtained from sensors into at least two distinct classes, including a first class and a second class. The function further includes receiving class-related perturbations for each of the at least two distinct classes, including a first class-related perturbation for the first class and a second class-related perturbation for the second class. The function further includes receiving a loss function. The function further includes partitioning the training dataset into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class. The function further includes calculating a first loss in response to the first subset and the first class-related perturbation, and calculating a second loss in response to the second subset and the second class-related perturbation. The function further includes updating parameters in response to the first loss and the second loss to obtain updated parameters.

[0005] In another embodiment, a computer system is disclosed, comprising a computer having a processor for executing computer-executable instructions and a memory for maintaining the computer-executable instructions. The computer-executable instructions perform a function when executed by the computer's processor. This function includes receiving a training dataset consisting of pairs of training input signals and corresponding output signals. A classifier is parameterized by parameters and configured to classify input signals obtained from sensors into at least two distinct classes, including a first class and a second class. The function further includes receiving class-related perturbations for each of the at least two distinct classes, including a first class-related perturbation for the first class and a second class-related perturbation for the second class. The function further includes receiving a loss function. The function also includes partitioning the training dataset into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class. The function further includes calculating a first loss in response to the first subset and the first class-related perturbation, and calculating a second loss in response to the second subset and the second class-related perturbation. The function also includes updating parameters in response to the first loss and the second loss to obtain updated parameters. Attached Figure Description

[0006] Figure 1 A schematic diagram depicts the interaction between a computer-controlled machine and a control system according to one embodiment.

[0007] Figure 2 Depicting Figure 1 A schematic diagram of a control system configured to control a vehicle, which may be a partially autonomous vehicle or a partially autonomous robot.

[0008] Figure 3 Depicting Figure 1 A schematic diagram of a control system configured to control manufacturing machines, such as punching and cutting machines, cutting machines, or gun drills, within a manufacturing system (such as a portion of a production line).

[0009] Figure 4 Depicting Figure 1 A schematic diagram of a control system configured to control power tools, such as drills or drives, having at least a partially autonomous mode.

[0010] Figure 5 Depicting Figure 1 A schematic diagram of the control system configured to control an automated personal assistant.

[0011] Figure 6 Depicting Figure 1 A schematic diagram of a control system configured as a control and monitoring system, such as a control access system or a monitoring system.

[0012] Figure 7 Depicting Figure 1 A schematic diagram of a control system configured to control an imaging system, such as an MRI device, an X-ray imaging device, or an ultrasound device.

[0013] Figure 8 A schematic diagram of a training system for training a classifier is depicted according to one or more embodiments.

[0014] Figure 9 A flowchart is depicted for a computational method for training a classifier according to one or more embodiments. Detailed Implementation

[0015] Embodiments of this disclosure are described herein. However, it should be understood that the disclosed embodiments are merely examples, and other embodiments may take various forms and alternatives. The figures are not necessarily drawn to scale; some features may be enlarged or minimized to show details of particular components. Therefore, the specific structural and functional details disclosed herein should not be construed as limiting, but merely as a representative basis for teaching those skilled in the art to adopt the embodiments in various ways. As will be understood by those skilled in the art, various features illustrated and described with reference to any of the figures may be combined with features illustrated in one or more other figures to produce embodiments not explicitly illustrated or described. The combinations of illustrated features provide representative embodiments for typical applications. However, for a particular application or implementation, various combinations and modifications of features consistent with the teachings of this disclosure may be expected.

[0016] Figure 1 A schematic diagram depicts the interaction between a computer-controlled machine 10 and a control system 12. The computer-controlled machine 10 includes actuators 14 and sensors 16. Actuators 14 may include one or more actuators, and sensors 16 may include one or more sensors. Sensors 16 are configured to sense the condition of the computer-controlled machine 10. Sensors 16 may be configured to encode the sensed condition into a sensor signal 18 and transmit the sensor signal 18 to the control system 12. Non-limiting examples of sensors 16 include video, radar, LiDAR, ultrasonic, and motion sensors. In one embodiment, sensor 16 is an optical sensor configured to sense an optical image of the environment in the vicinity of the computer-controlled machine 10.

[0017] The control system 12 is configured to receive sensor signals 18 from the computer control machine 10. As described below, the control system 12 may be further configured to calculate actuator control commands 20 based on the sensor signals and transmit the actuator control commands 20 to the actuator 14 of the computer control machine 10.

[0018] like Figure 1 As shown, the control system 12 includes a receiving unit 22. The receiving unit 22 can be configured to receive sensor signals 18 from the sensor 30 and transform the sensor signals 18 into input signals x. In an alternative embodiment, the sensor signals 18 are received directly as input signals x without the receiving unit 22. Each input signal x may be a portion of each sensor signal 18. The receiving unit 22 can be configured to process each sensor signal 18 to generate each input signal x. The input signals x may include data corresponding to the image recorded by the sensor 16.

[0019] The control system 12 includes a classifier 24. The classifier 24 can be configured to classify an input signal x into one or more labels using a machine learning (ML) algorithm such as a neural network. The classifier 24 is configured to be determined by parameters... Parameterization. Parameters The signal can be stored in and provided by non-volatile storage device 26. Classifier 24 is configured to determine an output signal y from an input signal x. Each output signal y includes information assigning one or more tags to each input signal x. Classifier 24 can transmit the output signal y to conversion unit 28. Conversion unit 28 is configured to convert the output signal y into an actuator control command 20. Control system 12 is configured to transmit the actuator control command 20 to actuator 14, actuator 14 being configured to actuate computer-controlled machine 10 in response to the actuator control command 20. In another embodiment, actuator 14 is configured to actuate computer-controlled machine 10 directly based on the output signal y.

[0020] Once actuator 14 receives actuator control command 20, actuator 14 is configured to perform an action corresponding to the actuator control command 20. Actuator 14 may include control logic configured to translate actuator control command 20 into a second actuator control command for controlling actuator 14. In one or more embodiments, instead of an actuator or in addition to an actuator, actuator control command 20 may also be used to control a display.

[0021] In another embodiment, instead of the computer control machine 10 including sensor 16, or in addition to the computer control machine 10 including sensor 16, the control system 12 also includes sensor 16. Instead of the computer control machine 10 including actuator 10, or in addition to the computer control machine 10 including actuator 10, the control system 12 may also include actuator 14.

[0022] like Figure 1As shown, the control system 12 also includes a processor 30 and a memory 32. The processor 30 may include one or more processors. The memory 32 may include one or more memory devices. A classifier 24 (e.g., an ML algorithm) of one or more embodiments may be implemented by the control system 12, which includes a non-volatile storage device 26, a processor 30, and a memory 32.

[0023] Non-volatile storage device 26 may include one or more persistent data storage devices, such as hard disk drives, optical disk drives, magnetic tape drives, non-volatile solid-state devices, cloud storage, or any other device capable of persistently storing information. Processor 30 may include one or more devices selected from high-performance computing (HPC) systems, including high-performance cores, microprocessors, microcontrollers, digital signal processors, microcomputers, central processing units, field-programmable gate arrays, programmable logic devices, state machines, logic circuits, analog circuits, digital circuits, or any other device that manipulates signals (analog or digital) based on computer-executable instructions residing in memory 32. Memory 32 may include a single memory device or multiple memory devices, including but not limited to: random access memory (RAM), volatile memory, non-volatile memory, static random access memory (SRAM), dynamic random access memory (DRAM), flash memory, cache memory, or any other device capable of storing information.

[0024] Processor 30 may be configured to read into memory 32 and execute computer-executable instructions residing in non-volatile storage device 26 and embodying one or more ML algorithms and / or methods of one or more embodiments. Non-volatile storage device 26 may include one or more operating systems and applications. Compilation and / or interpretation of non-volatile storage device 26 may be stored from computer programs created using various programming languages ​​and / or techniques, which, without limitation, include individually or in combination Java, C, C++, C#, Objective C, Fortran, Pascal, JavaScript, Python, Perl, and PL / SQL.

[0025] The computer-executable instructions of the non-volatile storage device 26, when executed by the processor 30, can cause the control system 12 to implement one or more of the ML algorithms and / or methods disclosed herein. The non-volatile storage device 26 may also include ML data (including data parameters) supporting the functionality, features, and processes of one or more embodiments described herein.

[0026] The program code embodying the algorithms and / or methods described herein can also be distributed individually or collectively as a program product in a variety of different forms. The program code can be distributed using a computer-readable storage medium having computer-readable program instructions thereon for inducing a processor to perform one or more embodiments. Computer-readable storage media, inherently non-transitory, can include tangible media that are volatile and non-volatile, and removable and non-removable, implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer-readable storage media may further include: RAM, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other solid-state memory technologies, portable optical disc read-only memory (CD-ROM) or other optical storage devices, magnetic tape, magnetic tape, disk storage devices or other magnetic storage devices, or any other medium that can be used to store desired information and can be read by a computer. Computer-readable program instructions can be downloaded from the computer-readable storage medium to a computer, another type of programmable data processing device, or another device, or via a network to an external computer or external storage device.

[0027] Computer-readable program instructions stored in a computer-readable medium can be used to direct a computer, other type of programmable data processing apparatus, or other device to operate in a particular manner, causing the instructions stored in the computer-readable medium to produce an article of art including instructions that implement the functions, actions, and / or operations specified in a flowchart or diagram. In some alternative embodiments, consistent with one or more embodiments, the functions, actions, and / or operations specified in the flowcharts and diagrams can be reordered, processed sequentially, and / or processed simultaneously. Furthermore, any flowchart and / or diagram may include more or fewer nodes or blocks than those illustrated consistent with one or more embodiments.

[0028] The process, method, or algorithm may be wholly or partially embodied using suitable hardware components such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), state machines, controllers, or other hardware components or devices, or a combination of hardware, software, and firmware components.

[0029] Figure 2 A schematic diagram is depicted of a control system 12 configured to control a vehicle 50, which may be at least partially autonomous or at least partially autonomous. Figure 2As shown, vehicle 50 includes actuator 14 and sensor 16. Sensor 16 may include one or more video sensors, radar sensors, ultrasonic sensors, LiDAR sensors, and / or position sensors (e.g., GPS). One or more of these specific sensors may be integrated into vehicle 50. Alternatively, or in addition to the one or more specific sensors identified above, sensor 16 may also include a software module configured to determine the state of actuator 14 upon execution. A non-limiting example of the software module includes a weather information software module configured to determine current or future weather conditions in the vicinity of vehicle 50 or elsewhere.

[0030] The classifier 24 of the control system 12 of vehicle 50 can be configured to detect objects near vehicle 50 depending on the input signal x. In such an embodiment, the output signal y may include information characterizing the area from the object to vehicle 50. An actuator control command 20 can be determined based on this information. The actuator control command 20 can be used to avoid collisions with the detected objects.

[0031] In embodiments where vehicle 50 is at least partially autonomous, actuator 14 may be embodied in the brakes, propulsion system, engine, drivetrain, or steering mechanism of vehicle 50. Actuator control command 20 may be determined to control actuator 14 so that vehicle 50 avoids collisions with detected objects. The detected objects may also be classified according to what classifier 24 deems most likely to be—such as pedestrians or trees. Actuator control command 20 may be determined based on this classification.

[0032] In other embodiments where vehicle 50 is at least partially autonomous, vehicle 50 may be a mobile robot configured to perform one or more functions—such as flying, swimming, diving, and pedaling. The mobile robot may be at least partially autonomous lawnmower or at least partially autonomous cleaning robot. In such embodiments, actuator control commands 20 may be determined to control the mobile robot's propulsion unit, steering unit, and / or braking unit so that the mobile robot can avoid collisions with identified objects.

[0033] In another embodiment, vehicle 50 is at least partially autonomous in the form of a gardening robot. In such an embodiment, vehicle 50 may use an optical sensor, as sensor 16, to determine the state of plants in the environment near vehicle 50. Actuator 14 may be a nozzle configured to spray chemicals. Depending on the identified species and / or the identified plant state, actuator control command 20 may be determined to cause actuator 14 to spray an appropriate amount of suitable chemical onto the plant.

[0034] Vehicle 50 may be a partially autonomous robot in the form of a household appliance. Non-limiting examples of household appliances include washing machines, stoves, ovens, microwave ovens, or dishwashers. In such a vehicle 50, sensor 16 may be an optical sensor configured to detect the state of an object to be processed by the household appliance. For example, in the case of a washing machine, sensor 16 may detect the state of the clothes inside the washing machine. Actuator control commands 20 may be determined based on the detected state of the clothes.

[0035] Figure 3 A schematic diagram of a control system 12 is depicted, which is configured to control manufacturing machines 100, such as punching and cutting machines, cutting machines, or gun drills, of a manufacturing system 102 (such as a portion of a production line). The control system 12 may be configured to control actuators 14, which are configured to control manufacturing machines 100.

[0036] The sensor 16 of the manufacturing machine 100 may be an optical sensor configured to capture one or more attributes of the finished product 104. The classifier 24 may be configured to determine the state of the finished product 104 based on one or more of the captured attributes. The actuator 14 may be configured to control the manufacturing machine 100 for subsequent manufacturing steps of the finished product 104, depending on the determined state of the finished product 104. The actuator 14 may also be configured to control the function of the manufacturing machine 100 for subsequent finished products 106, depending on the determined state of the finished product 104.

[0037] Figure 4 A schematic diagram of a control system 12 is depicted, which is configured to control a power tool 150, such as a drill or drive, having at least a partially autonomous mode. The control system 12 may be configured to control an actuator 14, which is configured to control the power tool 150.

[0038] The sensor 16 of the power tool 150 may be an optical sensor configured to capture one or more properties of the working surface 152 and / or the fastener 154 driven into the working surface 152. The classifier 24 may be configured to determine the state of the working surface 152 and / or the fastener 154 relative to the working surface 152 based on one or more of the captured properties. This state may be that the fastener 154 is flush with the working surface 152. Alternatively, this state may be the hardness of the working surface 154. The actuator 14 may be configured to control the power tool 150 such that the drive function of the power tool 150 is adjusted depending on the determined state of the fastener 154 relative to the working surface 152 or one or more captured properties of the working surface 154. For example, if the state of the fastener 154 is flush with the working surface 152, the actuator 14 may interrupt the drive function. As another non-limiting example, the actuator 14 may apply additional or lesser torque depending on the hardness of the working surface 152.

[0039] ] Figure 5 A schematic diagram is depicted of a control system 12 configured to control an automated personal assistant 200. The control system 12 may be configured to control an actuator 14, which is also configured to control the automated personal assistant 200. The automated personal assistant 200 may be configured to control household appliances such as a washing machine, stove, oven, microwave oven, or dishwasher.

[0040] Sensor 16 may be an optical sensor and / or an audio sensor. The optical sensor may be configured to receive video images of the gestures 204 of the user 202. The audio sensor may be configured to receive voice commands from the user 202.

[0041] The control system 12 of the automated personal assistant 200 can be configured to determine an actuator control command 20 configured as the control system 12. The control system 12 can be configured to determine the actuator control command 20 based on a sensor signal 18 from a sensor 16. The automated personal assistant 200 is configured to transmit the sensor signal 18 to the control system 12. The classifier 24 of the control system 12 can be configured to execute a gesture recognition algorithm to identify a gesture 204 made by the user 202, determine the actuator control command 20, and transmit the actuator control command 20 to the actuator 14. The classifier 24 can be configured to retrieve information from non-volatile storage in response to the gesture 204 and output the retrieved information in a form suitable for the user 202 to receive.

[0042] Figure 6A schematic diagram of a control system 12 configured to control a monitoring system 250 is depicted. The monitoring system 250 can be configured to physically control access through a door 252. A sensor 16 can be configured to detect and determine whether access is permitted in the relevant scene. The sensor 16 can be an optical sensor configured to generate and transmit image and / or video data. The control system 12 can use such data to detect a person's face.

[0043] The classifier 24 of the control system 12 of the surveillance system 250 can be configured to determine a person's identity by interpreting image and / or video data by matching it with the identities of known persons stored in non-volatile storage 26. The classifier 12 can be configured to generate and actuator control commands 20 in response to the interpretation of the image and / or video data. The control system 12 is configured to transmit the actuator control commands 20 to the actuator 12. In this embodiment, the actuator 12 can be configured to lock or unlock door 252 in response to the actuator control commands 20. In other embodiments, non-physical logical entry control is also possible.

[0044] The monitoring system 250 can also be a supervision system. In such an embodiment, sensor 16 can be an optical sensor configured to detect a scene under supervision, and control system 12 is configured to control display 254. Classifier 24 is configured to determine the classification of the scene, for example, whether the scene detected by sensor 16 is suspicious. Control system 12 is configured to transmit actuator control command 20 to display 254 in response to the classification. Display 254 can be configured to adjust the displayed content in response to actuator control command 20. For example, display 254 can highlight objects that classifier 24 considers suspicious.

[0045] Figure 7 A schematic diagram of a control system 12 is depicted, configured to control an imaging system 300, such as an MRI apparatus, an X-ray imaging apparatus, or an ultrasound apparatus. Sensor 16 may be, for example, an imaging sensor. Classifier 24 may be configured to determine a classification of all or part of the sensed image. Classifier 24 may be configured to determine or select actuator control command 20 in response to the classification. For example, classifier 24 may interpret a sensed image region as a potential anomaly. In this case, actuator control command 20 may be determined or selected to cause display 302 to display the image and highlight the potential anomalous region.

[0046] Classifiers can be vulnerable to adversarial attacks, which can cause drastic changes to their output and behavior. In supervised classification scenarios, there are defenses against adversarial attacks, as well as empirical defenses against adversarial examples (adversarial training). These defenses operate in a class-agnostic manner.

[0047] In one proposal, to mitigate this problem, a robust classifier can be trained whereby, at the cost of perturbation-free performance, the classifier exhibits a degree of robustness to changes in the input. In such a scenario, the loss function can be optimized for the worst-case scenario by optimizing the loss function for the worst possible perturbation (or an approximation thereof) applied to each sample. Therefore, the classifier can be robustly trained using equation (1).

[0048]

[0049] in Label classifier Robust parameterization, Label classifier The parameterization makes the robustness loss Compared to Minimize, X denotes the training set, and It is a permissible family of perturbations, for example .

[0050] Robust training process By finding adversarial examples And for Optimize to approximate robust loss for any Through the The loss is bounded to an upper bound, and the exact value of the robust loss version, or any other approximation of it (lower or upper bound), is found. The resulting robust classifier provides the benefit of increased robustness to perturbations across all classes at test time, but at the cost of reduced classification performance across all classes at test time.

[0051] This robustness is symmetric through design. The classifier trades performance across all K classes because... This is the same for all classes. In cases where the consequences of misclassification are uneven, this poses a significant problem. By increasing robustness to perturbations about one class, the classifier also becomes robust to perturbations across all other classes. In the specific example of fault detection, robustness to perturbations about non-faults might cause the classifier to misclassify faults as non-faults, with potentially severe consequences. On the other hand, small perturbations about faults are still faults. Therefore, the classifier should be robust to perturbations about faults. Thus, there is a need for computational methods and computer systems for asymmetrically providing robustness to the classifier.

[0052] In one or more embodiments, computational methods and computer systems for asymmetric training of robust classifiers are presented, given features. Mapping to class Classifier and a set of class-related permissible perturbations In one or more embodiments, the associated robust loss is expanded to be the sum of K individual robust losses, each with a separate set of allowed perturbations. A robust training process (empirical or provable) can be applied to the expanded robust loss.

[0053] A classifier can be trained from labeled data to create an asymmetric robust classifier. The classifier can be trained across training data derived from different classes (e.g., first and second different classes). In one or more embodiments, the adversarial examples or worst-case scenario perturbations are class-related. Therefore, different classes can have different sets of permissible perturbations. One or more embodiments have the benefit of solving classification problems with an asymmetric robust classification system in which the risk of misclassification and the consequences of such risks are asymmetric, the attacker or acquisition process has class-related characteristics, or the trade-off between classification performance and robustness is not class-agnostic (e.g., automated optical inspection, fault identification, mission-critical classification systems, etc.).

[0054] Figure 8 A schematic diagram of a training system 350 for training a classifier 24 according to one or more embodiments is depicted. A training unit 352 is configured to determine an input signal x and transmit the input signal x to the classifier 24. In one embodiment, the training unit 352 is configured to access a non-volatile storage device 354 to obtain a set of training data stored thereon. The non-volatile storage device 354 also stores a loss function. The non-volatile storage device 354 can also store class-related permissible perturbation sets. Furthermore, the training system 350 may include a processor 356 and a memory 358. The processor 356 may include one or more processors. The memory 358 may include one or more memory devices. One or more embodiments of the ML algorithm may be implemented by the training system 350, which includes a non-volatile storage device 354, a processor 356, and a memory 358.

[0055] Training system 350 is configured to perform a robust training process. To find a solution or an approximate solution to learn from Parameterized classifier This makes the robustness loss relative to Minimize. Robust training process. This could be an asymmetric robust classifier, configured to be trained by a training system 350 by extending the robust loss function to be class-separable. This training results in the computation of K distinct robust loss functions across partitions of the training set containing K distinct classes. The final classifier parameters can be obtained by solving for the sum of the K distinct loss functions across partitions of the training set.

[0056] Figure 9 A flowchart 400 depicts a computational method for training a classifier 24 according to one embodiment. The computational method can be implemented and executed using a training system 350. The computational method for training the classifier 24 can be derived from a robust training process. P show.

[0057] At step 402, input for the training method is received. In one embodiment, the input includes a training dataset consisting of pairs of training input signals and corresponding output signals. The training dataset can be represented by the following equation:

[0058] .

[0059] In this embodiment, the input further includes a classifier 24, which can be derived from... This indicates that the parameters are parameterized, and the parameters can be derived from... This indicates that classifier 24 can be configured to classify input signals obtained from one or more sensors disclosed herein into at least two distinct classes. In this embodiment, the input may further include a stopping condition S, for example, a binary stopping condition. The binary stopping condition S can be initialized to a predetermined starting value, such as false (FALSE). The input further includes class-related perturbations for each of the at least two distinct classes, which can be represented by the following equation:

[0060]

[0061] in It is a class-dependent perturbation of the first type, and This is the class-related allowed perturbation for the Kth class. The class-related allowed perturbation can be different for each of at least two distinct classes. The input can further include a loss function, which can be used... L This indicates the loss function. L The parameters of classifier 24 can be configured to optimize the ML algorithm. .

[0062] In step 404, the stopping condition S can be initialized. The stopping condition S can be a binary stopping condition. The stopping condition S can be initialized to false. In some embodiments, the classifier 24 can be a parallelizable robust training process.L In such an embodiment, the classifier 24 can be trained using the parallel training steps identified in branch 406 of the training system 350 shown in flowchart 400. In other embodiments, the classifier 24 may not be parallelizable. In such other embodiments, the classifier 24 can be trained using the training steps identified in branch 408 of the training system 350 shown in flowchart 400.

[0063] In step 410 of branch 408, the total loss function L Total loss Initialized to tend towards 0 (i.e. In one or more embodiments, when the stopping condition is a certain value or a range of values, for 1, ..., K i (in i (which is the label of each of the K classes), and steps 412 and 414 are executed iteratively within class loop 416.

[0064] In step 412, sample subsets are defined to partition the training dataset into different subsets with different labels. The training dataset can be partitioned into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class. For each label in each of the K classes... i A subset can be defined. , making Includes all tagged i The sample.

[0065] In step 414, it is possible to respond to each tag. i subset of Update total loss It can be based on the first i The corresponding perturbation set for the class is used to update the total loss to include the perturbation set for the first class. i Robust loss for the class. The update of the total loss in this way can be expressed by the following equation.

[0066]

[0067] in Indicate the total loss. It is the first i The training set of the class, and It is the first i Permissible perturbations for the class.

[0068] In step 418, the stopping condition S is updated in response to the updated total loss. Stopping rules can be used to update the stopping condition S to determine when to stop training classifier 24. The stopping condition S is updated to false in response to determining the number of stopping rules that allow training of classifier 24 to continue. The stopping condition S is updated to true (TRUE) in response to determining the number of stopping rules that allow training of classifier 24 to be interrupted. As shown in loop 416, when the stopping condition S is false, branch 408 continues execution of steps 412 and 414. As shown by arrow 420, once step 418 sets the stopping condition S to true, branch 408 interrupts the execution of steps 412 and 414.

[0069] In step 422, by using a training method (e.g., a robust training process) P This is applied to an optimization problem to update classifier parameters. In one embodiment, the optimization problem can be represented by the following equation.

[0070]

[0071] in These are the parameters of the robust classifier.

[0072] As described above, when classifier 24 can be parallelized, it can be trained using the parallel training steps identified in branch 406. In one or more embodiments, when the stopping condition is a certain value or a range of values, for 1, ..., K i (in i (which is the label of each of the K classes), and steps 424 and 426 are executed iteratively within class loop 428.

[0073] In step 424, sample subsets are defined to partition the training dataset into different subsets with different labels. The training dataset can be partitioned into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class. For each label in each of the K classes... i A subset can be defined. , making Includes all tagged i The sample.

[0074] In step 426, by using a training method (e.g., a robust training process) P This is applied to optimization problems to update classifier parameters in parallel. In one embodiment, the optimization problem can be represented by the following equation.

[0075]

[0076] in These are robustness parameters.

[0077] In step 430, the stopping condition S is updated in response to the updated classifier parameters determined in step 422. Stopping rules can be used to update the stopping condition S to determine when to stop training classifier 24. The stopping condition S is updated to false in response to determining the number of stopping rules for continuing training of classifier 26. The stopping condition S is updated to true in response to determining the number of stopping rules for interrupting training of classifier 24. As shown in loop 428, branch 406 continues execution of steps 424 and 426 when the stopping condition S is false. As shown by arrow 432, branch 406 interrupts the execution of steps 424 and 426 once step 430 sets the stopping condition S to true.

[0078] In one embodiment, the permissible disturbance can be described from a perception perspective. Collection. Disturbance It can be equal to ,in D It is configured to identify the input signal. x A discriminator that distinguishes between undisturbed (0) and disturbed (1), thereby causing disturbances The discriminator D cannot distinguish between the set of perturbed and undisturbed data. D It can be automatic or manual.

[0079] In other embodiments, the asymmetric robustness of the training process can be applied to the generative model rather than the classifier, where robustness to changes in the input is correlated with the presence of class labels on the input. In some embodiments, the generative model can be a conditional generative model.

[0080] While exemplary embodiments have been described above, they are not intended to describe all possible forms encompassed by the claims. The language used in this specification is descriptive and not restrictive, and it should be understood that various changes may be made without departing from the spirit and scope of this disclosure. As previously stated, features of various embodiments may be combined to form other embodiments of the invention that may not be explicitly described or illustrated. While various embodiments may have been described as providing an advantage or preference over other embodiments or prior art implementations with respect to one or more desired features, those skilled in the art will recognize that one or more features or characteristics may be compromised to achieve desired overall system properties depending on the specific application and implementation. These properties may include, but are not limited to, cost, strength, durability, lifecycle cost, merchantability, appearance, packaging, size, maintainability, weight, manufacturability, ease of assembly, etc. Accordingly, while any embodiment may be described as less desirable with respect to one or more features compared to other embodiments or prior art implementations, these embodiments do not exceed the scope of this disclosure and may be desirable for a particular application.

Claims

1. A computational method for training a classifier, the method comprising: The classifier receives a training dataset consisting of pairs of training input signals and corresponding output signals. The classifier is parameterized by parameters and configured to classify the input signals obtained from the sensor into at least two different classes, including a first class and a second class. For each of the at least two different classes, the class-related perturbation is received, including a first class-related perturbation for the first class and a second class-related perturbation for the second class, and a loss function is received. The training dataset is partitioned into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class; A first loss is calculated in response to a first subset and a first type of relevant allowed perturbation, and a second loss is calculated in response to a second subset and a second type of relevant allowed perturbation; as well as Update the parameters in response to the first loss and the second loss to obtain updated parameters; The input signal obtained from the sensor is sent to a classifier parameterized by updated parameters to obtain an output signal configured to characterize the classification of the input signal; as well as In response to the output signal, actuator control commands are transmitted to the actuators of the computer-controlled machine. The input signal includes data corresponding to the image recorded by the sensor.

2. The calculation method according to claim 1, wherein the update step is performed by a machine learning algorithm.

3. The calculation method according to claim 1, wherein when the stopping condition is a predetermined value, the partitioning and calculation steps are performed iteratively within a loop-like manner.

4. The calculation method according to claim 1, wherein the partitioning and update steps are performed iteratively within a loop when the stopping condition is a predetermined value.

5. The calculation method according to claim 1, wherein the first and second types of related permissible perturbations are in a set for which the discriminator cannot distinguish between perturbed data and undisturbed data.

6. The calculation method according to claim 1, wherein the first label and the second label are different.

7. A non-transitory computer-readable medium comprising computer-executable instructions and memory for storing the computer-executable instructions, the computer-executable instructions performing the following functions when executed by a processor of a computer: The classifier receives a training dataset consisting of pairs of training input signals and corresponding output signals. The classifier is parameterized by parameters and configured to classify the input signals obtained from the sensor into at least two different classes, including a first class and a second class. For each of the at least two different classes, the class-related perturbation is received, including a first class-related perturbation for the first class and a second class-related perturbation for the second class, and a loss function is received. The training dataset is partitioned into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class; A first loss is calculated in response to a first subset and a first type of relevant allowed perturbation, and a second loss is calculated in response to a second subset and a second type of relevant allowed perturbation; as well as The parameters are updated in response to the first loss and the second loss to obtain updated parameters; The input signal obtained from the sensor is sent to a classifier parameterized by updated parameters to obtain an output signal configured to characterize the classification of the input signal; as well as In response to the output signal, actuator control commands are transmitted to the actuators of the computer-controlled machine. The input signal includes data corresponding to the image recorded by the sensor.

8. The non-transitory computer-readable medium of claim 7, wherein the update function is implemented by a machine learning algorithm.

9. The non-transitory computer-readable medium of claim 7, wherein the partitioning and computation steps are performed iteratively within a loop when the stopping condition is a predetermined value.

10. The non-transitory computer-readable medium of claim 7, wherein the partitioning and updating steps are performed iteratively within a class loop when the stopping condition is a predetermined value.

11. The non-transitory computer-readable medium of claim 7, wherein the first and second class related permissible perturbations depend on a discriminator that cannot distinguish between perturbed and undisturbed data.

12. The non-transitory computer-readable medium of claim 7, wherein the first tag is different from the second tag.

13. A computer system, comprising: A computer having a processor for executing computer-executable instructions and memory for storing the computer-executable instructions, which perform the following functions when executed by the computer's processor: The classifier receives a training dataset consisting of pairs of training input signals and corresponding output signals. The classifier is parameterized by parameters and configured to classify the input signals obtained from the sensor into at least two different classes, including a first class and a second class. For each of the at least two different classes, the class-related perturbation is received, including a first class-related perturbation for the first class and a second class-related perturbation for the second class, and a loss function is received. The training dataset is partitioned into a first subset labeled with a first label corresponding to the first class and a second subset labeled with a second label corresponding to the second class; A first loss is calculated in response to a first subset and a first type of relevant allowed perturbation, and a second loss is calculated in response to a second subset and a second type of relevant allowed perturbation; as well as The parameters are updated in response to the first loss and the second loss to obtain updated parameters; The input signal obtained from the sensor is sent to a classifier parameterized by updated parameters to obtain an output signal configured to characterize the classification of the input signal; as well as In response to the output signal, actuator control commands are transmitted to the actuators of the computer-controlled machine. The input signal includes data corresponding to the image recorded by the sensor.

14. The computer system of claim 13, wherein the update function is performed by a machine learning algorithm.

15. The computer system of claim 13, wherein the partitioning and computation steps are performed iteratively within a loop when the stopping condition is a predetermined value.

16. The computer system of claim 13, wherein the partitioning and update steps are performed iteratively within a class loop when the stopping condition is a predetermined value.

17. The computer system of claim 13, wherein the first and second class of related permissible perturbations depend on a discriminator that cannot distinguish between perturbed and undisturbed data.

Citation Information

Patent Citations

  • Enhanced disturbance management of a power grid system

    CN107895954A

  • Training sample generation method and device, apparatus, and medium

    CN109272031A