A black-box attack system based on dynamic network structure learning

Through dynamic network structure learning and optimization constraints of structured infographics, black box attacks with high success rate without real data and prior knowledge are realized, solving the problems of low attack success rate and dependence on prior knowledge in the existing technology.

CN114428954BActive Publication Date: 2025-06-10FUDAN UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111629855.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-28
Publication Date
2025-06-10
Estimated Expiration
2041-12-28

AI Technical Summary

Technical Problem

The existing black box attack technology is difficult to achieve high success rate attacks without real data participation, and requires relying on prior knowledge of the target model.

Method used

The alternative model training method of dynamic network structure learning is adopted, and the alternative model structure is automatically optimized through the optimization constraints of the structured infographic to get rid of the dependence on the prior knowledge of the target model.

Benefits of technology

It realizes high-quality training of alternative models without real data and prior knowledge, improving the success rate and efficiency of black box attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114428954B_ABST
    Figure CN114428954B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer vision image processing, and specifically to a black-box attack method based on dynamic network structure learning. An attack method for an unknown-scenario target black-box model without real data participation is proposed. For diverse target black-box models, a training method for an alternative model based on dynamic network structure learning is proposed to autonomously generate an optimal alternative model structure, and an optimization constraint based on a structured information graph is proposed to improve the learning quality and efficiency of the alternative model, thereby further improving the attack performance of the adversarial samples generated by it. This method has the advantages of few query times, high learning efficiency, high attack success rate, etc., and is very suitable for black-box attack scenarios without any prior knowledge.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer vision image processing, and particularly relates to a black-box attack system based on dynamic network structure learning. Background Art

[0002] With the wide application of deep network models in various tasks in the real world, more and more researchers have begun to focus on the security and robustness of deep network models. It has gradually been found that adversarial samples generated by adding perturbations to clean images can successfully attack deep network models, thereby causing prediction errors in the models.

[0003] Adversarial attacks against deep models can be mainly divided into two categories: First, white-box attacks, that is, the attacker can obtain the specific network structure and parameters of the target deep model. Existing methods often perform reverse attacks through the gradients of the target model to directly generate adversarial samples, thereby achieving a relatively high attack success rate; Second, black-box attacks, that is, the attacker cannot directly obtain the specific network structure and parameters of the target deep model. Existing methods often improve the attack transferability of adversarial samples generated on other white-box models, or generate adversarial samples through training a surrogate model that approximates the target model to achieve the attack. However, these existing black-box attack technologies still have a low attack success rate and rely on certain prior knowledge of the target model, such as model tasks, training data, number of categories, etc.

[0004] In order to better achieve practical and high-intensity black-box attacks, existing technologies have proposed black-box attacks under data-free conditions, that is, in the black-box attack task, it is additionally required not to use real data for training the surrogate model. The first method generates a large number of samples through a noise input generator, and at the same time uses the network structure of knowledge distillation to improve the quality of attack samples by constraining the output consistency between the target model and the surrogate model. The second method focuses on improving the quality of samples generated by the generator and increasing the diversity of generated samples to further improve the efficiency of knowledge distillation training. However, they both rely on prior knowledge of the number of classifications of the target model and need to select the optimal one from surrogate models with multiple different network structures. Summary of the Invention

[0005] The present invention proposes a black-box attack system based on dynamic network structure learning under the condition of no participation of real data. For the target black-box model and privacy protection requirements in unknown scenarios, without directly obtaining the specific network structure and parameters of the target deep model, and without understanding prior knowledge such as the task requirements, training data, and number of classifications of the target black-box model, high-quality dynamic structure surrogate model training is achieved, thereby completing the black-box attack task with a high success rate.

[0006] Previously, it has been analyzed that existing related adversarial sample generation algorithms often rely on prior knowledge of the number of classifications of the target model and need to select the optimal one from alternative models with multiple different network structures, which will greatly reduce the practicability of these algorithms and consume a large amount of computing resources. Therefore, how to directly obtain the optimal alternative model through one-time training and learning without any prior knowledge of the target model is the technical key point of the present invention.

[0007] To achieve the above objectives, the present invention proposes an alternative model training method based on dynamic network structure learning, which gets rid of the limitations of the fixed static alternative model network structure, thus realizing the goal of autonomous network structure optimization generation according to different target models. At the same time, in order to further improve the quality and efficiency of knowledge distillation training, we construct a structured information graph based on multiple outputs of the target model and prompt the alternative model to learn more critical and hidden knowledge information from the structured features between multiple outputs, so as to improve the attack strength of adversarial samples based on this alternative model.

[0008] The specific steps of the present invention are as follows:

[0009] A black-box attack system based on dynamic network structure learning includes an optimization constraint based on a structured information graph and an alternative training of dynamic network structure learning. The alternative training specifically includes the following steps:

[0010] S1: Generate alternative training data;

[0011] S2: Alternative training based on the optimization constraint of the structured information graph;

[0012] S3: Generate an alternative model for dynamic network structure learning;

[0013] S4: Send the test data into the alternative model, generate adversarial samples through a white-box attack method, and conduct an attack test on the target black-box model.

[0014] The step S1 specifically includes the following steps:

[0015] S11: Randomly generate noise samples according to the Gaussian distribution;

[0016] S12: Send the noise samples into the generator to generate alternative training data.

[0017] The step S2 specifically includes the following steps:

[0018] Step 21: Send the alternative training data generated by the generator into the target model and the alternative model respectively to obtain the corresponding outputs;

[0019] Step 22: Calculate the point nodes and edge features based on the multiple outputs of the target model and the surrogate model, and construct the corresponding structured information graph;

[0020] Step 23: Calculate the optimization loss function based on the structured information graph obtained from the outputs of the target model and the surrogate model;

[0021] Step 24: Narrow the distance between the outputs of the target model and the surrogate model according to the optimization loss function based on the structured information graph, and update and optimize the network parameters of the surrogate model;

[0022] Step 25: Widen the distance between the outputs of the target model and the surrogate model according to the optimization loss function based on the structured information graph, and update and optimize the network parameters of the generator;

[0023] The structured information graph in step 22 includes point nodes and edge features. The point nodes are expressed by the outputs of the model itself, and the edge features are the Euclidean distance differences of features between two point nodes.

[0024] Step 23 uses the Kullback-Leibler divergence to measure the distance between point nodes and uses the MSE loss function to represent the distance between edge features.

[0025] Step S3 specifically includes the following steps:

[0026] Step 31: Perform simple processing on the input feature vector through an average pooling layer and a fully connected layer;

[0027] Step 32: Predict whether to skip the current residual branch through a gate function.

[0028] Step 32 uses the Hard-Sigmoid function as the gate function H and sets the threshold to 0.5 to achieve the binarization of the dynamic gate output.

[0029] In summary, the innovation of the present invention lies in:

[0030] (1) Aiming at diverse target black-box models, a training method for surrogate models with dynamic network structure learning is proposed. By using the learning of the dynamic gate structure, the optimal surrogate model structure is autonomously generated for different target models, thus avoiding the problem of consuming computational resources in selecting the optimal one from multiple surrogate models with different network structures.

[0031] (2) Based on the training method of surrogate models based on knowledge distillation, an optimization constraint based on the structured information graph is proposed. By the structured information constraint between multiple outputs, the learning quality and efficiency of the surrogate model are improved, thereby further enhancing the attack performance of the adversarial samples generated by it. Description of the Drawings

[0032] Appendix Figure 1 FIG. is a diagram of a black-box attack system based on dynamic network structure learning proposed by the present invention;

[0033] Appendix Figure 2 FIG. is a schematic diagram of an alternative model training method for dynamic network structure learning proposed by the present invention;

[0034] Appendix Figure 3 FIG. is a flowchart of a black-box attack based on dynamic network structure learning proposed by the present invention. Embodiment

[0035] In order to make the technical means, creative features, achieved purposes and effects realized by the present invention easy to understand, the technical solutions of the present invention will be described in detail below with reference to the accompanying drawings.

[0036] Figure 1 FIG. is a diagram of a black-box attack system based on dynamic network structure learning for a classification task model proposed by the present invention. The system 100 includes media data 101, a computer device 110 and a display device 191. The media data 101 can be video content, such as a movie, etc., or image content. The media data 101 can be transmitted through a television or the Internet. In some specific cases, the media data 101 can also be picture data containing a variety of categories and diversities. The computing device 110 is a computing device for processing the media data 101, mainly including a computer processor 120 and a memory 130. The processor 120 is a hardware processor for the computing device 110, such as a central processing unit CPU or a graphics processing unit GPU. The memory 130 is a non-volatile storage device for storing computer code for the computing process of the processor 120. At the same time, the memory 130 also stores various intermediate data and parameters. The memory 130 includes Gaussian random noise 135 and its related data, and executable code 140. The executable code 140 includes one or more software modules for performing the calculations of the computer processor 120. As Figure 1 shown, the executable code 140 includes a training data generation module 141, a knowledge distillation alternative training module 143, a structured information graph learning module 144 and a dynamic network structure learning module 147.

[0037] The training data generation module 141 is a code module for processing the media data 101 and generating data. By using a training data generation algorithm, it can generate large-scale data for subsequent knowledge distillation alternative model training when only Gaussian random noise is used as the input.

[0038] The knowledge distillation alternative training module 143 is based on the training data generated by the training data generation module 141. By synchronously inputting data to the target model and the alternative model, the outputs of the two are constrained to be as close as possible, thereby achieving the optimization training learning goal of the alternative model.

[0039] The structured information graph learning module 144 constructs a structured information graph based on the outputs of multiple target models and alternative models, and calculates an optimized loss function based on the structured information graph, thereby efficiently and accurately achieving the alternative training goal on the basis of having a structured output.

[0040] The dynamic network structure learning module 147, during the network training process, according to different target models, through the self-adaptive learning process of the dynamic gate, autonomously generates the corresponding optimal network structure of the alternative model, thereby improving the attack performance of the black box attack.

[0041] The display device 191 is a device suitable for playing media data 101 and displaying the predicted scores output by the computing device 110, and can be a computer, a television, or a mobile device.

[0042] The specific implementation manner of the present invention is mainly realized in 7 steps, and the specific details are as follows:

[0043] Step 1, generate alternative training data. According to the input random noise z based on the Gaussian distribution, the corresponding alternative training data x is generated through the generator network model G, and the specific expression is as follows,

[0044] z ∼ N(0, 1)

[0045] x = G(z) ∈ R 3×h×w

[0046] where h and w respectively represent the length and width dimensions of the generated data.

[0047] Step 2, alternative training with optimized constraints based on the structured information graph. The alternative training data x generated by the generator is respectively input into the target model T and the alternative model S, and the corresponding model output results are obtained. By constraining the outputs of the target model T and the alternative model S to be consistent, it helps the alternative model S better learn rich and accurate knowledge from the target model T, and thereby updates and optimizes the parameters in the alternative model S.

[0048] L S = d(T(x), S(x))

[0049] where d represents the measurement standard of the output distance between the target model T and the alternative model S.

[0050] Step 3, Optimization training of the generator. Inspired by the generative adversarial network, when training the surrogate model S, it is hoped that the distance gap between the outputs of the target model T and the surrogate model S is as small as possible. At the same time, the training objective of the generator G is to maximize the distance between the outputs of the target model T and the surrogate model S, so that the generator G continuously generates more valuable and difficult surrogate training data. Therefore, the optimization update method of the generator G is as follows,

[0051] L G = -d(T(x), S(x))

[0052] Step 4, Construct a structured information graph. According to the multiple outputs of the target model T and the surrogate model S, a corresponding structured information graph is constructed through the pairwise relationship between the outputs, including point nodes and edge features. Among them, the point nodes are mainly expressed by the outputs of the models themselves, and the edge features are represented by the Euclidean distance difference between two point nodes. The specific structured information graph can be expressed as follows,

[0053]

[0054] A(j, k) = ||x j -x k ||E, j, k = 1,..., B

[0055] where B represents the number of training data in each round of iterative training, and E represents using the Euclidean distance to measure the feature distance between two points as the expression of the edge feature.

[0056] Step 5, Calculate the optimization loss function based on the structured information graph. Based on the obtained structured information graphs Graph T and Graph S of the target model T and the surrogate model S, the proposed optimization loss function based on the structured information graph, Graph-based Structural Information Learning Constrain (GSIL), is used to calculate and optimize Steps 2 and 3. The specific expression of the optimization loss function is as follows,

[0057]

[0058] where, and are the point nodes of the target model T and the surrogate model S respectively, and A T and A S are the edge features of the target model T and the surrogate model S respectively. We use the Kullback-Leibler divergence to measure the distance between point nodes and the MSE loss function to represent the distance between edge features.

[0059] Step 6, Network structure learning of the dynamic substitution model. To generate the corresponding optimal substitution model network structure for different target models, we design a dynamic gate DG to predict the output one-hot vector to control whether to skip the current residual branch. The dynamic gate consists of a series of simple operations to achieve its function.

[0060] DG(f) = H(WP(f) + b)

[0061] where f is the input feature vector, P represents the global average pooling layer, and W and b are the network parameters of the fully connected layer respectively. To achieve the binaryization of path selection, we choose the Hard-Sigmoid function as the gate function H, which is specifically expressed as

[0062]

[0063] where we set the threshold to 0.5, so as to classify the result after passing through H into 0 or 1, and k is the approximation parameter used as the step function, which is set to 10 in the experiment.

[0064] Step 7, Train the neural network model to generate a substitution model for dynamic network structure learning. We use the SGD optimizer to train the network. In the initial state, the learning rate of the generator G is lr = 0.0001, the learning rate of the substitution model S is lr = 0.001, the coefficient betas = (0.9, 0.999), the weight decay coefficient is 0.1, the batch size of batch data is batchsize = 500, and the parameter α 1 = 1, α 2 = 1. The network converges after about 80 rounds of training.

[0065] Step 8, When evaluating the attack intensity, send the test data into the substitution model obtained in Step 7, generate adversarial samples through the white-box attack method, and conduct an attack test on the target black-box model.

[0066] Figure 2 shows our substitution model training method for dynamic network structure learning. This figure shows that during the substitution training process, by learning and updating the dynamic gate structure, the corresponding optimal substitution model network structure is generated for different target models.

[0067] Figure 3 shows our black-box attack method based on dynamic network structure learning. This figure details the data flow of the network model and includes the generation of training data for substitution training, the substitution training method based on knowledge distillation, and the optimization constraints based on the structured information graph.

Claims

1. A black-box attack system based on dynamic network structure learning, characterized in that, it includes optimization constraints based on a structured information graph and surrogate training for dynamic network structure learning. The surrogate training specifically includes the following steps: S1: Generate surrogate training data; S2: Surrogate training based on optimization constraints of the structured information graph; S3: Generate a surrogate model for dynamic network structure learning; S4: Feed the test data into the surrogate model, generate adversarial samples through a white-box attack method, and conduct an attack test on the target black-box model; The step S2 specifically includes the following steps: Step 21: Feed the surrogate training data generated by the generator into the target model and the surrogate model respectively to obtain corresponding outputs; Step 22: Calculate point nodes and edge features based on multiple outputs of the target model and the surrogate model, and construct a corresponding structured information graph; Step 23: Calculate an optimization loss function based on the structured information graph obtained from the outputs of the target model and the surrogate model; Step 24: Narrow the distance between the outputs of the target model and the surrogate model according to the optimization loss function based on the structured information graph, and update and optimize the network parameters of the surrogate model; Step 25: Widen the distance between the outputs of the target model and the surrogate model according to the optimization loss function based on the structured information graph, and update and optimize the network parameters of the generator.

2. The black-box attack system according to claim 1, characterized in that, the step S1 specifically includes the following steps: S11: Randomly generate noise samples according to a Gaussian distribution; S12: Feed the noise samples into the generator to generate surrogate training data.

3. The black-box attack system according to claim 2, characterized in that, the structured information graph in the step 22 includes point nodes and edge features. The point nodes are expressed by the outputs of the model itself, and the edge features are the Euclidean distance differences between two point nodes.

4. The black-box attack system according to claim 2, characterized in that, the step 23 uses the Kullback-Leibler divergence to measure the distance between point nodes, and uses the MSE loss function to represent the distance between edge features.

5. The black-box attack system according to claim 1, characterized in that, the step S3 specifically includes the following steps: Step 31: Perform simple processing on the input feature vector through an average pooling layer and a fully connected layer; Step 32: Predict whether to skip the current residual branch through a gate function.

6. The black-box attack system according to claim 5, characterized in that, The step 32 uses the Hard-Sigmoid function as the gate function , and sets the threshold to 0.5 to achieve the binarization of the dynamic gate output.

Citation Information

Patent Citations

  • General non-negative matrix factorization algorithm-oriented adaptive gradient integration adversarial attack method

    CN112465015A

  • Black box attack-oriented substitution model automatic selection method, storage medium and terminal

    CN113407939A