Adversarial Training Method, Image Processing Method, Apparatus, Device, and Medium
By deploying the filtering model at the front end of the image processing model and using frequency decomposition and high-frequency information training models, the security risks existing in deep learning algorithms in image processing are solved, and the accuracy of the adversarial defense and image processing effects is improved.
Patent Information
- Application Number
- CN202210260891.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-16
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-03-16
AI Technical Summary
Existing deep learning algorithms have security risks in image processing. Attackers can add specific noise to normal samples to deceive models, resulting in insufficient accuracy of the processing results of model output.
The filtering model is deployed at the front end of the image processing model, and decomposes the image into sub-images of multiple frequency regions by performing wavelet transform or Fourier transform on the image. The normal sample and adversarial sample are determined based on high-frequency information, and the filtering model is trained to detect whether the input image is an adversarial image.
High-frequency areas highlight the significant features of the image, improve the training efficiency and accuracy of the filtering model, realize adversarial defense, omit the prediction stage of the image processing model, and improve the accuracy of the image processing effect.
Smart Images

Figure CN114648675B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence or information security, and more specifically, to an adversarial training method, an image processing method, an apparatus, a device, a medium, and a program product. Background Art
[0002] With the rapid development of deep learning in image processing, natural language processing and other fields, a large number of deep learning-based models have been deployed and utilized in various fields. However, existing deep learning algorithms have security risks, and attackers can cheat deep learning models by adding specific noise to normal samples.
[0003] Adversarial training is an intuitive defense method against adversarial samples. This method improves the robustness of the model by training with adversarial samples. In related technologies, for example, image processing models are trained with normal samples and adversarial samples at the same time, so that the image processing models can avoid being deceived to a certain extent. However, the image processing model obtained by the above training method has insufficient accuracy in the processing results it outputs. Summary of the invention
[0004] In view of the above problems, the present disclosure provides an adversarial training method, image processing method, apparatus, device, medium and program product that can detect normal images or adversarial images and improve the accuracy of image processing models.
[0005] One aspect of an embodiment of the present disclosure provides an adversarial training method, comprising: adding image noise to a first image to obtain a second image, wherein the image noise includes pixels or pixel blocks; processing the first image to obtain first sub-images in multiple frequency regions, and processing the second image to obtain second sub-images in multiple frequency regions; determining at least one of the first sub-images as a normal sample based on high-frequency information, and determining at least one of the second sub-images as an adversarial sample based on the high-frequency information; training a filtering model based on the normal samples and the adversarial samples, wherein the trained filtering model is used to detect a third image, and if the third image is a normal image, the third image is input into an image processing model for processing.
[0006] According to an embodiment of the present disclosure, the processing of the first image to obtain first sub-images of multiple frequency regions, and the processing of the second image to obtain second sub-images of multiple frequency regions include: performing a wavelet transform or a Fourier transform on the first image to convert the first image to a frequency region; and / or performing a wavelet transform or a Fourier transform on the second image to convert the second image to a frequency region.
[0007] According to an embodiment of the present disclosure, the determining of at least one of the first sub-images as a normal sample based on the high-frequency information and the determining of at least one of the second sub-images as an adversarial sample based on the high-frequency information include: determining at least one of the first sub-images as a normal sample based on at least one of the horizontal high-frequency information, the vertical high-frequency information and the diagonal high-frequency information; and / or determining at least one of the second sub-images as an adversarial sample based on at least one of the horizontal high-frequency information, the vertical high-frequency information and the diagonal high-frequency information.
[0008] According to an embodiment of the present disclosure, the filtering model based on the normal sample and the adversarial sample training includes: performing convolution processing on the training sample to obtain a first feature vector, wherein the training sample is any one of the normal sample and the adversarial sample training; performing normalization processing on the first feature vector to obtain a second feature vector; processing the second feature vector using an activation function to obtain a third feature vector, wherein the third feature vector is used to train the filtering model.
[0009] According to an embodiment of the present disclosure, adding image noise to the first image to obtain the second image includes: adding the image noise based on an adversarial training algorithm, wherein the adversarial training algorithm includes at least one of a fast gradient sign method, a fast gradient method, and a mapped gradient descent method.
[0010] Another aspect of an embodiment of the present disclosure provides an image processing method, comprising: inputting a third image into a filtering model for detection to obtain a detection result, wherein the filtering model is trained by the method described above; if the detection result is a normal image, inputting the third image into an image processing model for processing.
[0011] According to an embodiment of the present disclosure, the third image is input into the filtering model for detection, and the detection result obtained includes: using the filtering model to obtain an adversarial threshold of the third image, wherein the adversarial threshold includes a probability value that the third image is an adversarial image; if the adversarial threshold is greater than or equal to a first threshold, the detection result is an adversarial image; if the adversarial threshold is less than or equal to a second threshold, the detection result is a normal image, wherein the second threshold is less than the first threshold.
[0012] According to an embodiment of the present disclosure, the method further includes: if the adversarial threshold is less than the first threshold and greater than the second threshold, the third image is smoothed and denoised and then input into the image processing model for processing.
[0013] Another aspect of an embodiment of the present disclosure provides an adversarial training device, including: an adversarial attack module, used to add image noise to a first image to obtain a second image, wherein the image noise includes pixel points or pixel blocks; a frequency domain processing module, used to process the first image to obtain first sub-images of multiple frequency regions, and to process the second image to obtain second sub-images of multiple frequency regions; a sample determination module, used to determine at least one of the first sub-images as a normal sample based on high-frequency information, and to determine at least one of the second sub-images as an adversarial sample based on high-frequency information; a model training module, used to train a filtering model based on the normal samples and the adversarial samples, wherein the filtering model after training is used to detect a third image, and if the third image is a normal image, the third image is input into the image processing model for processing.
[0014] Another aspect of an embodiment of the present disclosure provides an image processing device, comprising: an image detection module, used to input a third image into a filtering model for detection to obtain a detection result, wherein the filtering model is obtained by training the device as described above; and an image processing module, used to input the third image into the image processing model for processing if the detection result is a normal image.
[0015] Another aspect of an embodiment of the present disclosure provides an electronic device, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the method as described above.
[0016] Another aspect of the embodiments of the present disclosure further provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, causes the processor to execute the method as described above.
[0017] Another aspect of the embodiments of the present disclosure further provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0018] One or more of the above embodiments have the following beneficial effects:
[0019] Compared with the method of directly conducting adversarial training on the image processing model in the related art, the embodiment of the present disclosure trains and deploys the filtering model at the front end of the image processing model, decomposes the first image and the second image in the frequency region dimension, and can highlight the significant features of the image through the high-frequency region, so that the filtering model can learn effective information and improve the training efficiency. After the training is completed, the filtering model can also be used to determine in advance whether the input image is an adversarial image to achieve adversarial defense, thereby omitting the prediction stage of the image processing model and improving the accuracy of the image processing effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The above contents and other purposes, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0021] Figure 1 A diagram schematically shows an application scenario of an adversarial training method or an image processing method according to an embodiment of the present disclosure;
[0022] Figure 2 A flowchart of an adversarial training method according to an embodiment of the present disclosure is schematically shown;
[0023] Figure 3 The schematic diagram shows an architecture diagram for obtaining a training set according to an embodiment of the present disclosure;
[0024] Figure 4 Schematically shows a flow chart of training a filtering model according to an embodiment of the present disclosure;
[0025] Figure 5 The following schematically shows an architecture diagram of a training filtering model according to an embodiment of the present disclosure;
[0026] Figure 6 The flowchart of the image processing method according to the embodiment of the present disclosure is schematically shown;
[0027] Figure 7 A flowchart of obtaining a detection result according to an embodiment of the present disclosure is schematically shown;
[0028] Figure 8 The schematic diagram shows an architecture diagram of an image processing method according to an embodiment of the present disclosure;
[0029] Fig. 9 The structure block diagram of the adversarial training device according to an embodiment of the present disclosure is schematically shown;
[0030] Fig.10 The structure block diagram of the image processing device according to the embodiment of the present disclosure is schematically shown;
[0031] Fig.11 A block diagram of an electronic device suitable for implementing an adversarial training method or an image processing method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0032] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0033] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise", "include", etc. used herein indicate the existence of the features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.
[0034] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0035] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0036] Adversarial training adds perturbations to the original images to construct some adversarial attack samples, which are then fed to the model for training, improving the model's robustness in detecting adversarial samples and improving the model's generalization ability as a whole. In the adversarial attack process, the attacker deceives the deep learning model by constructing adversarial samples for input using perturbations that are imperceptible to humans, causing the normally trained model to output highly confident erroneous predictions, thus achieving the attack goal.
[0037] In related technologies, adversarial training is directly performed on image processing models. Although this improves the robustness of the model, it strikes a balance between robustness and accuracy in implementation, thereby achieving the goal of adversarial defense at the expense of some accuracy.
[0038] The embodiment of the present disclosure trains and deploys the filtering model at the front end of the image processing model, decomposes the first image and the second image in the frequency region dimension, and can highlight the significant features of the image through the high-frequency region, so that the filtering model can learn effective information and improve the training efficiency. After the training is completed, the filtering model can also be used to determine in advance whether the input image is an adversarial image to achieve adversarial defense, thereby omitting the prediction stage of the image processing model and improving the accuracy of the image processing effect.
[0039] Figure 1 The application scenario diagram of the adversarial training method or image processing method according to an embodiment of the present disclosure is schematically shown.
[0040] like Figure 1 As shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is used to provide a medium for a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0041] Users can use terminal devices 101, 102, 103 to interact with server 105 through network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only examples).
[0042] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.
[0043] The server 105 may be a server that provides various services, such as a background management server (only as an example) that provides support for websites browsed by users using the terminal devices 101, 102, and 103. The background management server may analyze and process the received data such as user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0044] It should be noted that the adversarial training method or image processing method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the adversarial training device or image processing device provided in the embodiment of the present disclosure can generally be set in the server 105. The adversarial training method or image processing method provided in the embodiment of the present disclosure can also be performed by a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the adversarial training device or image processing device provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105.
[0045] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0046] The following will be based on Figure 1 The scene described by Figure 2~Figure 7 The adversarial training method and image processing method of the embodiments of the present disclosure are described in detail.
[0047] Figure 2 The flowchart of the adversarial training method according to an embodiment of the present disclosure is schematically shown. Figure 3 The following schematically shows an architecture diagram for obtaining a training set according to an embodiment of the present disclosure.
[0048] like Figure 2 As shown, the adversarial training method of this embodiment includes operations S210 to S240.
[0049] In operation S210, image noise is added to a first image to obtain a second image, wherein the image noise includes pixel points or pixel blocks.
[0050] Exemplarily, adding image noise is also called adding image disturbance, and the second image is a disturbed image obtained based on the first image. A pixel block may include multiple pixels. Image noise can disturb the observable information of an image. When performing feature processing, even disturbances that are not easily perceived by the human eye can have a significant impact on the model.
[0051] Among them, adding image noise to the first image to obtain the second image includes: according to an embodiment of the present disclosure, adding image noise based on an adversarial training algorithm, wherein the adversarial training algorithm includes at least one of a fast gradient sign method, a fast gradient method, and a mapped gradient descent method.
[0052] Exemplarily, the adversarial training algorithm includes an algorithm for generating perturbations to the first image in adversarial training. The perturbation added by the Fast Gradient Sign Method (FGSM) goes along the direction of the gradient toward the maximum value of the loss function. The perturbation added by the Fast Gradient Method (FGM) takes the same step in each direction. The Projected Gradient Descent (PGD) method finds the optimal perturbation through multiple iterations. If you go out of the space within the perturbation radius, map it back to that space. In some embodiments, the adversarial training algorithm may also include FreeAT (Free Adversarial Training), YOPO (you only propagate once), FreeLB (Free large-batch), C&W, etc.
[0053] In operation S220, the first image is processed to obtain first sub-images of a plurality of frequency regions, and the second image is processed to obtain second sub-images of a plurality of frequency regions.
[0054] According to an embodiment of the present disclosure, the first image is converted to a frequency region, low-frequency information and high-frequency information of the first image are extracted, and first sub-images of multiple frequency regions are obtained. And / or the second image is converted to a frequency region, low-frequency information and high-frequency information of the second image are extracted, and second sub-images of multiple frequency regions are obtained.
[0055] Schematically, the frequency of an image is an indicator of the intensity of grayscale changes in an image, and is the gradient of grayscale in a plane space. Low-frequency information may refer to the part of an image where the grayscale component changes slowly, and high-frequency information may refer to the part of an image where the grayscale classification changes rapidly. High-frequency information can usually be obtained at the edge or noise and detail of an image. Therefore, for the second image, high-frequency information can also make the disturbance more significant to a certain extent. The frequency demarcation value can be defined according to actual needs to determine high frequency or low frequency.
[0056] According to an embodiment of the present disclosure, a wavelet transform or a Fourier transform is performed on the first image to convert the first image into a frequency domain, and / or a wavelet transform or a Fourier transform is performed on the second image to convert the second image into a frequency domain.
[0057] Exemplarily, Fourier transform can decompose an image into different components based on frequency, so that the image can be better observed through the frequency domain. Wavelet transform can also perform frequency domain decomposition, for example, Haar transform, mallat transform and other techniques can be used. In the related art, the frequency domain conversion of the image is usually used for denoising, and the embodiment of the present disclosure can be used to extract high-frequency information to construct training samples. Since the training samples have prominent high-frequency features, the training efficiency of the model is improved.
[0058] In operation S230 , at least one first sub-image is determined as a normal sample based on the high frequency information, and at least one second sub-image is determined as an adversarial sample based on the high frequency information.
[0059] According to an embodiment of the present disclosure, at least one first sub-image is determined as a normal sample based on at least one of the horizontal high-frequency information, the vertical high-frequency information, and the diagonal high-frequency information. And / or, at least one second sub-image is determined as an adversarial sample based on at least one of the horizontal high-frequency information, the vertical high-frequency information, and the diagonal high-frequency information.
[0060] Reference Figure 3 First, the first image is subjected to adversarial attack, and some typical attack methods, such as FGSM, PGD, C&W, etc., are used to generate perturbations of the input image. Secondly, it is divided into two branches: the first image branch without perturbation and the second image branch with perturbation. Then, the two branches are subjected to wavelet transform, such as Haar transform, respectively, referring to formula (1).
[0061] Formula (1)
[0062] Among them, x represents the original input and dwt2_haar represents the haar wavelet decomposition operation. is the image data in the frequency domain.
[0063] After transformation, we can obtain low-frequency information, horizontal high-frequency information, vertical high-frequency information, and diagonal high-frequency information. Refer to formula (2).
[0064] Formula (2)
[0065] in, is the result of formula (1). They are low-frequency information, horizontal high-frequency information, vertical high-frequency information, and diagonal high-frequency information.
[0066] Finally, for the two branches, three high-frequency information with significant differences are selected respectively and concatenated into a filter model input of size length × width × 3 to form positive and negative samples. Refer to formula (3).
[0067] Formula (3)
[0068] Among them, X is the result after splicing.
[0069] According to the embodiments of the present disclosure, inputting high-frequency images in three directions with significant differences into the filtering model can provide some prior information, allowing the filtering model to directly learn effective features. Compared with the method of directly processing the original image, the certainty of the filtering model learning significant features can be improved, and the situation where the filtering model learns wrong information and ignores effective information, resulting in poor training effect, can be avoided.
[0070] In operation S240, a filtering model is trained based on normal samples and adversarial samples, wherein the trained filtering model is used to detect the third image, and if the third image is a normal image, the third image is input into the image processing model for processing.
[0071] For example, refer to Figure 3 , after inputting the normal sample or adversarial sample in the training set into the filtering model. The filtering model is used to output the prediction result of the sample, and the loss function is calculated based on the prediction result and the correct result of the sample (such as the pre-labeled label). The filtering model is trained according to the value of the loss function until the loss function converges to obtain the trained filtering model.
[0072] The embodiment of the present disclosure trains and deploys the filtering model at the front end of the image processing model, decomposes the first image and the second image in the frequency region dimension, and can highlight the significant features of the image through the high-frequency region, so that the filtering model can learn effective information and improve the training efficiency. After the training is completed, the filtering model can also be used to determine in advance whether the input image is an adversarial image to achieve adversarial defense, thereby omitting the prediction stage of the image processing model and improving the accuracy of the image processing effect.
[0073] Figure 4 The flowchart of training a filtering model according to an embodiment of the present disclosure is schematically shown. Figure 5 The schematic diagram shows an architecture diagram of a training filtering model according to an embodiment of the present disclosure.
[0074] like Figure 4 As shown, training the filtering model based on normal samples and adversarial samples in operation S240 includes operations S410 to S430.
[0075] Reference Figure 5 , for different application scenarios, you can choose training sets from different sources. Figure 3The process shown processes the original data set to obtain the training set. The network structure of the filtering model can adopt the module design method of convolution layer + BN layer (normalization layer) + ReLU layer (activation layer). N represents the number of modules, which is set according to the actual scenario. Among them, each module includes convolution layer + BN layer + ReLU layer.
[0076] In operation S410, convolution processing is performed on a training sample to obtain a first feature vector, wherein the training sample is any one of a normal sample and an adversarial sample training.
[0077] For example, refer to Figure 5 , the training sample can be input into the convolution layer, and after convolution processing using the convolution layer, the first feature vector can be output.
[0078] In operation S420, the first eigenvector is normalized to obtain a second eigenvector.
[0079] For example, refer to Figure 5 , the first eigenvector can be input into the normalization layer, and after normalization, the second eigenvector can be output.
[0080] In operation S430, the second eigenvector is processed using an activation function to obtain a third eigenvector, wherein the third eigenvector is used to train a filtering model.
[0081] For example, refer to Figure 5 , the second eigenvector can be input into the activation layer, the second eigenvector can be processed by the activation function ReLU, and the third eigenvector can be output.
[0082] In some embodiments, the third feature vector may be input to the next module to continue feature extraction.
[0083] For the binary classification problem of whether it is an adversarial sample, the sigmoid+binary cross entropy loss function is used to set the network, and the model is trained by the BP algorithm. The loss function L in one embodiment is expressed as formula (4).
[0084] Formula (4)
[0085] Where N is the number of training samples, Represents training samples The label of the positive class is 1 and the negative class is 0. Representation sample The probability of predicting the positive class.
[0086] Figure 6 The flowchart of the image processing method according to the embodiment of the present disclosure is schematically shown. Figure 7The flowchart of obtaining the detection result according to the embodiment of the present disclosure is schematically shown. Figure 8 The schematic diagram shows an architecture diagram of an image processing method according to an embodiment of the present disclosure.
[0087] like Figure 6 As shown, the image processing method of this embodiment includes operations S610 to S620.
[0088] In operation S610, the third image is input into the filtering model for detection to obtain a detection result, wherein the filtering model is obtained by the training method described in the above embodiment.
[0089] For example, refer to Figure 8 ,The filtering model is deployed before the main model (i.e., the image processing model) and plays the role of a firewall. Figure 8 The unknown input is the third image, which can be subjected to wavelet transformation to obtain at least one of horizontal high-frequency information, vertical high-frequency information and diagonal high-frequency information, and input into the filtering model.
[0090] In operation S620, if the detection result is a normal image, the third image is input into the image processing model for processing.
[0091] Exemplarily, the detection result may include a normal image and an adversarial image. If it is an adversarial image, it is intercepted to avoid entering the subject model.
[0092] According to the embodiments of the present disclosure, a filtering model is used to determine in advance whether an input image is an adversarial image to achieve adversarial defense, thereby omitting the prediction stage of the image processing model and improving the accuracy of the image processing effect.
[0093] like Figure 7 As shown, obtaining the detection result of this embodiment includes operations S710 to S760.
[0094] In operation S710, an adversarial threshold of the third image is obtained using a filtering model, wherein the adversarial threshold includes a probability value that the third image is an adversarial image.
[0095] For example, if the trained filtering model is a binary classification model, a sigmoid function can be used to obtain a value between 0 and 1 based on the feature vector of the third image, that is, a probability value of predicting that the third image is an adversarial image.
[0096] In operation S720, it is determined whether the confrontation threshold is greater than or equal to the first threshold. If so, operation S730 is performed, and if not, operation S740 is performed.
[0097] In operation S730, if the adversarial threshold is greater than or equal to the first threshold, the detection result is an adversarial image.
[0098] Reference Figure 8 The first threshold is the high threshold, such as 0.8 (only as an example). If the probability value is greater than or equal to 0.8, the third image is intercepted.
[0099] In operation S740, it is determined whether the confrontation threshold is less than or equal to the second threshold. If so, operation S750 is performed, and if not, operation S760 is performed.
[0100] In operation S750, if the confrontation threshold is less than or equal to the second threshold, the detection result is a normal image.
[0101] Reference Figure 8 , the second threshold is the high threshold for confrontation, such as 0.4 (only for example). If the probability value is less than or equal to 0.4, the third image is released and input into the subject model for processing.
[0102] According to the embodiments of the present disclosure, filtering rules are set by using the low-threshold and high-threshold to process different input samples more comprehensively and reduce errors.
[0103] In operation S760, if the adversarial threshold is less than the first threshold and greater than the second threshold, the third image is smoothed and denoised and then input into the image processing model for processing.
[0104] In some embodiments, smoothing and denoising can be implemented using wavelet transform. The purpose of smoothing and denoising the third image is that the filtering model can consider that the image between the first threshold and the second threshold does not give a definite detection result. In this case, the input image may be an adversarial image of the attack or a normal image. If it is an adversarial image, the use of smoothing and denoising can remove the attack disturbance that may exist in the input image to a certain extent, thereby improving security. If it is a normal image, there is some noise on the image that affects the judgment of the filtering model, so smoothing and denoising can improve the image quality and the processing accuracy of the main model.
[0105] In some embodiments, based on the above-mentioned adversarial training method and image processing method, disturbances are generated according to methods that may attack the main model (such as FGSM, PGD, C&W, etc.), wavelet decomposition is performed to construct data sets and labels, and a filtering model is trained to determine whether it is an adversarial sample. After the training is completed, the filtering model is deployed on the firewall to decide in advance whether to enter the subsequent main model. According to the judgment of the filtering model, two thresholds are set: the high adversarial threshold and the low adversarial threshold. When it is greater than the high adversarial threshold, it is judged as an adversarial sample and intercepted by the firewall. When it is less than the low adversarial threshold, it is judged not to be an adversarial sample and enters the subsequent model. In other cases, it is passed after smoothing and enters the model.
[0106] The present disclosure also provides an adversarial training device and an image processing device. Fig. 9 and Fig.10 Describe in detail.
[0107] Fig. 9 The structural block diagram of the adversarial training device according to an embodiment of the present disclosure is schematically shown.
[0108] like Fig. 9 As shown, the adversarial training device 900 of this embodiment includes an adversarial attack module 910 , a frequency domain processing module 920 , a sample determination module 930 and a model training module 940 .
[0109] The counter-attack module 910 may perform operation S210 to add image noise to the first image to obtain a second image, wherein the image noise includes pixel points or pixel blocks.
[0110] According to an embodiment of the present disclosure, the adversarial attack module 910 can add image noise based on an adversarial training algorithm, wherein the adversarial training algorithm includes at least one of a fast gradient sign method, a fast gradient method, and a mapped gradient descent method.
[0111] The frequency domain processing module 920 may perform operation S220 for processing the first image to obtain first sub-images in multiple frequency regions, and processing the second image to obtain second sub-images in multiple frequency regions.
[0112] According to an embodiment of the present disclosure, processing a first image to obtain a first sub-image of a plurality of frequency regions, and processing a second image to obtain a second sub-image of a plurality of frequency regions include: performing a wavelet transform or a Fourier transform on the first image to convert the first image into a frequency region, and / or performing a wavelet transform or a Fourier transform on the second image to convert the second image into a frequency region.
[0113] According to an embodiment of the present disclosure, determining at least one first sub-image as a normal sample based on high-frequency information, and determining at least one second sub-image as an adversarial sample based on high-frequency information includes: determining at least one first sub-image as a normal sample based on at least one of horizontal high-frequency information, vertical high-frequency information, and diagonal high-frequency information. And / or determining at least one second sub-image as an adversarial sample based on at least one of horizontal high-frequency information, vertical high-frequency information, and diagonal high-frequency information.
[0114] The sample determination module 930 may perform operation S230 for determining at least one first sub-image as a normal sample based on the high-frequency information, and determining at least one second sub-image as an adversarial sample based on the high-frequency information.
[0115] The model training module 940 can perform operation S240 to train a filtering model based on normal samples and adversarial samples, wherein the trained filtering model is used to detect the third image. If the third image is a normal image, the third image is input into the image processing model for processing.
[0116] According to an embodiment of the present disclosure, the model training module 940 may further perform operations S410 to S430 to perform convolution processing on the training sample to obtain a first feature vector, wherein the training sample is any one of a normal sample and an adversarial sample training. The first feature vector is normalized to obtain a second feature vector. The second feature vector is processed using an activation function to obtain a third feature vector, wherein the third feature vector is used to train the filtering model.
[0117] Fig.10 The structure block diagram of the image processing device according to the embodiment of the present disclosure is schematically shown.
[0118] like Fig.10 As shown, the image processing device 1000 of this embodiment includes an image detection module 1010 and an image processing module 1020 .
[0119] The image detection module 1010 may perform operation S610 to input the third image into the filtering model for detection to obtain a detection result, wherein the filtering model is composed of Fig. 9 The adversarial training device 900 described is obtained through training.
[0120] According to an embodiment of the present disclosure, the image detection module 1010 may also perform operations S710 to S760 to obtain an adversarial threshold of the third image using a filtering model, wherein the adversarial threshold includes a probability value that the third image is an adversarial image. If the adversarial threshold is greater than or equal to the first threshold, the detection result is an adversarial image. If the adversarial threshold is less than or equal to the second threshold, the detection result is a normal image, wherein the second threshold is less than the first threshold. If the adversarial threshold is less than the first threshold and greater than the second threshold, the third image is smoothed and denoised and then input into the image processing model for processing.
[0121] The image processing module 1020 may perform operation S620 for inputting the third image into an image processing model for processing if the detection result is a normal image.
[0122] According to the embodiment of the present disclosure, the image processing device 1000 deploys a filtering model on the firewall at the front end of the image processing model, and uses wavelet transform to decompose the high and low frequency information of the image and input it into the filtering model. In this way, it is possible to more significantly and accurately determine whether the input sample is an adversarial sample, and the accuracy of the main model will not be sacrificed, thereby achieving adversarial defense. In addition, the filtering rules process different input samples more comprehensively to reduce errors.
[0123] It should be noted that the implementation methods, technical problems solved, functions realized, and technical effects achieved of each module / unit / sub-unit in the device part embodiment are the same or similar to the implementation methods, technical problems solved, functions realized, and technical effects achieved of each corresponding step in the method part embodiment, and will not be repeated here.
[0124] According to an embodiment of the present disclosure, any multiple modules in the adversarial training device 900 or the image processing device 1000 can be combined into one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module.
[0125] According to an embodiment of the present disclosure, at least one of the adversarial training device 900 or the image processing device 1000 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware and firmware or in an appropriate combination of any of them. Alternatively, at least one of the adversarial training device 900 or the image processing device 1000 may be at least partially implemented as a computer program module, which may perform corresponding functions when the computer program module is executed.
[0126] Fig.11 A block diagram of an electronic device suitable for implementing an adversarial training method or an image processing method according to an embodiment of the present disclosure is schematically shown.
[0127] like Fig.11As shown, the electronic device 1100 according to an embodiment of the present disclosure includes a processor 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage part 1108 to a random access memory (RAM) 1103. The processor 1101 may include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (for example, an application-specific integrated circuit (ASIC)), etc. The processor 1101 may also include an onboard memory for caching purposes. The processor 1101 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0128] In RAM 1103, various programs and data required for the operation of electronic device 1100 are stored. Processor 1101, ROM 1102 and RAM 1103 are connected to each other through bus 1104. Processor 1101 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 1102 and / or RAM 1103. It should be noted that the program can also be stored in one or more memories other than ROM 1102 and RAM 1103. Processor 1101 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in the one or more memories.
[0129] According to an embodiment of the present disclosure, the electronic device 1100 may further include an input / output (I / O) interface 1105, which is also connected to the bus 1104. The electronic device 1100 may further include one or more of the following components connected to the I / O interface 1105: an input portion 1106 including a keyboard, a mouse, etc.; an output portion 1107 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 1108 including a hard disk, etc.; and a communication portion 1109 including a network interface card such as a LAN card, a modem, etc. The communication portion 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the I / O interface 1105 as needed. A removable medium 1111, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1110 as needed, so that a computer program read therefrom is installed into the storage portion 1108 as needed.
[0130] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.
[0131] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus, or a device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 1102 and / or RAM 1103 described above and / or one or more memories other than ROM 1102 and RAM 1103.
[0132] The embodiment of the present disclosure also includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present disclosure.
[0133] The above functions defined in the system / device of the embodiment of the present disclosure are performed when the computer program is executed by the processor 1101. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0134] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part 1109, and / or installed from a removable medium 1111. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0135] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 1109, and / or installed from the removable medium 1111. When the computer program is executed by the processor 1101, the above functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the system, device, means, module, unit, etc. described above can be implemented by a computer program module.
[0136] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level process and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, Java, C++, python, "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).
[0137] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0138] It will be appreciated by those skilled in the art that the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations and / or combinations are not explicitly described in the present disclosure. In particular, the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways without departing from the spirit and teachings of the present disclosure. All of these combinations and / or combinations fall within the scope of the present disclosure.
[0139] The embodiments of the present disclosure are described above. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments are described above separately, this does not mean that the measures in the various embodiments cannot be used in combination to advantage. The scope of the present disclosure is defined by the attached claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make a variety of substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. An adversarial training method, comprising: adding image noise to a first image to obtain a second image, wherein the image noise includes pixel points or pixel blocks; processing the first image to obtain first sub-images in multiple frequency regions, and processing the second image to obtain second sub-images in multiple frequency regions; determining at least one of the first sub-images as a normal sample based on high-frequency information, and determining at least one of the second sub-images as an adversarial sample based on high-frequency information; training a filtering model based on the normal sample and the adversarial sample, wherein after training, the filtering model is used to detect a third image, and if the third image is a normal image, the third image is input into an image processing model for processing; wherein the filtering model includes a convolutional layer, a normalization layer, and an activation layer, and training the filtering model based on the normal sample and the adversarial sample includes: inputting a training sample into the convolutional layer, performing convolutional processing on the training sample to obtain a first feature vector, wherein the training sample is any one of the normal sample and the adversarial sample; inputting the first feature vector into the normalization layer, performing normalization processing on the first feature vector to obtain a second feature vector; inputting the second feature vector into the activation layer, processing the second feature vector using an activation function to obtain a third feature vector, wherein the third feature vector is used to train the filtering model.
2. The method according to claim 1, wherein, processing the first image to obtain first sub-images in multiple frequency regions, and processing the second image to obtain second sub-images in multiple frequency regions includes: performing wavelet transform or Fourier transform on the first image to convert the first image into the frequency region; and / or performing wavelet transform or Fourier transform on the second image to convert the second image into the frequency region.
3. The method according to claim 1, wherein, determining at least one of the first sub-images as a normal sample based on high-frequency information, and determining at least one of the second sub-images as an adversarial sample based on high-frequency information includes: determining at least one of the first sub-images as a normal sample according to at least one of horizontal high-frequency information, vertical high-frequency information, and diagonal high-frequency information; and / or determining at least one of the second sub-images as an adversarial sample according to at least one of horizontal high-frequency information, vertical high-frequency information, and diagonal high-frequency information.
4. The method according to claim 1, wherein, adding image noise to the first image includes: adding the image noise based on an adversarial training algorithm, wherein the adversarial training algorithm includes at least one of the fast gradient sign method, the fast gradient method, and the projected gradient descent method.
5. An image processing method, comprising: inputting a third image into a filtering model for detection to obtain a detection result, wherein the filtering model is trained by the method according to any one of claims 1 to 4; if the detection result is a normal image, inputting the third image into an image processing model for processing.
6. The method according to claim 5, wherein, Input the third image into a filtering model for detection, and the detection results include: Obtain the adversarial threshold of the third image by using the filtering model, where the adversarial threshold includes the probability value that the third image is an adversarial image; If the adversarial threshold is greater than or equal to the first threshold, the detection result is an adversarial image; If the adversarial threshold is less than or equal to the second threshold, the detection result is a normal image, where the second threshold is less than the first threshold.
7. The method according to claim 6, wherein, the method further includes: If the adversarial threshold is less than the first threshold and greater than the second threshold, perform smoothing and denoising processing on the third image and then input it into the image processing model for processing.
8. An adversarial training device, comprising: An adversarial attack module for adding image noise to a first image to obtain a second image, where the image noise includes pixel points or pixel blocks; A frequency domain processing module for processing the first image to obtain first sub-images in multiple frequency regions, and processing the second image to obtain second sub-images in multiple frequency regions; A sample determination module for determining at least one of the first sub-images as a normal sample based on high-frequency information, and determining at least one of the second sub-images as an adversarial sample based on high-frequency information; A model training module for training a filtering model based on the normal sample and the adversarial sample, where the trained filtering model is used to detect a third image. If the third image is a normal image, input the third image into an image processing model for processing; wherein, the filtering model includes a convolutional layer, a normalization layer, and an activation layer, and training the filtering model based on the normal sample and the adversarial sample includes: Input the training sample into the convolutional layer, perform convolutional processing on the training sample to obtain a first feature vector, where the training sample is either the normal sample or the adversarial sample; Input the first feature vector into the normalization layer, perform normalization processing on the first feature vector to obtain a second feature vector; Input the second feature vector into the activation layer, process the second feature vector using an activation function to obtain a third feature vector, where the third feature vector is used to train the filtering model.
9. An image processing device, comprising: An image detection module for inputting a third image into a filtering model for detection to obtain a detection result, where the filtering model is trained by the device according to claim 8; An image processing module for inputting the third image into an image processing model for processing if the detection result is a normal image.
10. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors execute the method according to any one of claims 1 to 7.
11. A computer-readable storage medium having executable instructions stored thereon, which when executed by a processor cause the processor to perform the method according to any one of claims 1 to 7.
12. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Anti-attack method and device, readable medium and electronic equipment
CN112488172A
Model training method and device and computer storage medium
CN113255433A