Calibrator generation method and device, adversarial robustness calibration method and device

By sampling and training network structures from the sampling space, an adversarial robust calibration is generated, and a problem of high cost and robustness neglect in the prior art is solved, and efficient adversarial robust calibration is achieved.

CN115034362BActive Publication Date: 2025-07-22BEIJING WODONG TIANJUN INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210628983.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-06
Publication Date
2025-07-22
Estimated Expiration
2042-06-06

AI Technical Summary

Technical Problem

When calibrating the adversarial robustness of neural network architectures, the prior art requires a complete training of neural networks and testing adversarial samples, which is costly and easily overlooked the impact of model structure on robustness.

Method used

By sampling the network structure from the sampling space, each network structure is trained and matrix-encoded, and an adversarial robust calibrator is generated, and a robust calibrator is built using sparse encoding and multi-layer perception mechanisms to predict the adversarial robustness accuracy of the network structure.

Benefits of technology

It improves the efficiency of counter-romantic calibration, reduces additional training costs, and can obtain calibration results with near-real robustness accuracy on uninfected network structures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115034362B_ABST
    Figure CN115034362B_ABST
Patent Text Reader

Abstract

The present disclosure provides a calibrator generation method and apparatus, relating to the field of trustworthy artificial intelligence. A specific implementation of the method includes: sampling at least one network structure from a sampling space to obtain a network structure sample set; training each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples; performing matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; and obtaining an adversarial robustness calibrator based on the encoding matrices and the adversarial robustness accuracy values of the network structures in the network structure sample set. This implementation improves the efficiency of adversarial robustness calibration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of trustworthy artificial intelligence, particularly to the field of automated machine learning, and more particularly to a calibrator generation method and apparatus, an adversarial robustness calibration method and apparatus, a calibrator, an electronic device, a computer-readable medium, and a computer program product. Background Art

[0002] To test the security of deep learning algorithms, for an existing image, by carefully constructing some special noises and then superimposing them on the original image, a deep learning model that originally performs well can be made to make mistakes. Such noisy data is called "adversarial samples", and the robustness of the deep learning model to adversarial samples is called adversarial robustness.

[0003] In the process of commercialization of deep learning, quantitatively calibrating the adversarial robustness of a neural network architecture is very important. Calibrating the adversarial robustness of a neural network architecture usually requires fully training the neural network architecture and then testing it on adversarial samples to calibrate the adversarial robustness of the neural network, which is costly and easily ignores the impact of the model structure itself on adversarial robustness. Summary of the Invention

[0004] Embodiments of the present disclosure provide a calibrator generation method and apparatus, an adversarial robustness calibration method and apparatus, a calibrator, an electronic device, a computer-readable medium, and a computer program product.

[0005] In a first aspect, embodiments of the present disclosure provide a calibrator generation method, the method including: sampling at least one network structure from a sampling space to obtain a network structure sample set; training each network structure in the network structure sample set to obtain an adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure to adversarial samples; performing matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; and obtaining an adversarial robustness calibrator based on the encoding matrices and the adversarial robustness accuracy values of the network structures in the network structure sample set.

[0006] In some embodiments, the above sampling space is constructed by the following steps: determining structural units that can form a network structure and operation types between nodes in the structural units; and performing operations corresponding to the operation types on the directed edges between the nodes of the structural units to obtain the sampling space.

[0007] In some embodiments, the above training each network structure in the network structure sample set to obtain an adversarial robustness accuracy value of each network structure includes: performing adversarial training on each network structure in the network structure sample set using an adversarial algorithm based on a preset robustness sample to obtain an adversarial robustness accuracy value of each network structure.

[0008] In some embodiments, the above matrix encoding of each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure includes: performing matrix encoding on each network structure in the network structure sample set using a sparse encoding formula to obtain an encoding matrix corresponding to each network structure; the sparse encoding formula is:

[0009] where α i,j represents whether there is an operation j on the i-th directed edge of the network structure. If so, the element in the i-th row and j-th column of the sparse encoding matrix α will be set to 1, otherwise it will be set to 0.

[0010] In some embodiments, the above obtaining an adversarial robustness calibrator based on the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set includes: constructing a perception network of the adversarial robustness calibrator using a multi-layer perceptron; training the perception network using the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set to obtain a trained adversarial robustness calibrator, and the adversarial robustness calibrator is used to perform adversarial robustness accuracy calibration on the input encoding matrix to obtain an adversarial robustness accuracy value corresponding to the input encoding matrix.

[0011] In some embodiments, the above training the perception network using the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set to obtain a trained adversarial robustness calibrator includes: for each network structure in the network structure sample set, inputting the encoding matrix of the network structure into the perception network to obtain a predicted accuracy value corresponding to the network structure output by the perception network; adjusting the parameters of the perception network based on the predicted accuracy values of all network structures in the network structure sample set and the robustness accuracy values of all network structures; in response to the perception network satisfying the training completion condition, obtaining a trained adversarial robustness calibrator.

[0012] In a second aspect, an embodiment of the present disclosure provides another adversarial robustness calibration method, which includes: obtaining a network structure to be calibrated; in response to the network structure belonging to a preset sampling space, performing calibration using an adversarial robustness calibrator corresponding to the sampling space to obtain an adversarial robustness accuracy value of the network structure, and the adversarial robustness calibrator is obtained by using the calibrator generation method described in any implementation manner of the first aspect.

[0013] In some embodiments, the above method includes: using the adversarial robustness calibrator to determine the adversarial robustness accuracy values of each network structure in the sampling space.

[0014] In a third aspect, embodiments of the present disclosure provide a calibrator generation device, which includes: a sampling unit configured to sample at least one network structure from a sampling space to obtain a network structure sample set; a training unit configured to train each network structure in the network structure sample set to obtain an adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples; an encoding unit configured to perform matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; and an obtaining unit configured to obtain an adversarial robustness calibrator based on the encoding matrices and the adversarial robustness accuracy values of each network structure in the network structure sample set.

[0015] In some embodiments, the above sampling space is constructed by a construction unit, and the construction unit is configured to determine structural units that can form a network structure and the types of operations between nodes in the structural units; perform operations corresponding to the types of operations on the directed edges between the nodes of the structural units to obtain the sampling space.

[0016] In some embodiments, the above training unit is further configured to perform adversarial training on each network structure in the network structure sample set using an adversarial algorithm based on a preset robustness sample to obtain the adversarial robustness accuracy value of each network structure.

[0017] In some embodiments, the above encoding unit is further configured to: perform matrix encoding on each network structure in the network structure sample set using a sparse coding formula to obtain an encoding matrix corresponding to each network structure;

[0018] The sparse coding formula is:

[0019] where α i,j represents whether there is an operation j on the i-th directed edge of the network structure. If so, the element in the i-th row and j-th column of the sparse coding matrix α will be set to 1, otherwise it will be set to 0.

[0020] In some embodiments, the above obtaining unit includes: a construction module configured to construct a perception network of the adversarial robustness calibrator using a multi-layer perceptron; a training module configured to train the perception network using the encoding matrices and the adversarial robustness accuracy values of each network structure in the network structure sample set to obtain a trained adversarial robustness calibrator, and the adversarial robustness calibrator is used to perform adversarial robustness accuracy calibration on the input encoding matrix to obtain an adversarial robustness accuracy value corresponding to the input encoding matrix.

[0021] In some embodiments, the above training module is further configured to: for each network structure in the network structure sample set, input the encoding matrix of the network structure into the perception network to obtain the prediction accuracy value corresponding to the network structure output by the perception network; based on the prediction accuracy values of all network structures in the network structure sample set and the robustness accuracy values of all network structures, adjust the parameters of the perception network; in response to the perception network satisfying the training completion condition, obtain a trained adversarial robustness calibrator.

[0022] Fourthly, an embodiment of the present disclosure provides another adversarial robustness calibration device, which includes: an acquisition unit configured to acquire a network structure to be calibrated; a calibration unit configured to, in response to the network structure belonging to a preset sampling space, perform calibration using an adversarial robustness calibrator corresponding to the sampling space to obtain the adversarial robustness accuracy value of the network structure, and the adversarial robustness calibrator is obtained by using the device described in any implementation manner of the second aspect.

[0023] In some embodiments, the above device further includes: a determination unit configured to use the adversarial robustness calibrator to determine the adversarial robustness accuracy values of each network structure in the sampling space.

[0024] Fifthly, an embodiment of the present disclosure provides a calibrator, which is obtained by using the method described in any implementation manner of the first aspect.

[0025] Sixthly, an embodiment of the present disclosure provides an electronic device, which includes: one or more processors; a storage device on which one or more programs are stored; when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the first aspect or the second aspect.

[0026] Seventhly, an embodiment of the present disclosure provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method described in any implementation manner of the first aspect or the second aspect.

[0027] Eighthly, an embodiment of the present disclosure provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method described in any implementation manner of the first aspect or the second aspect.

[0028] The calibration generator method and device provided by the embodiments of the present disclosure first sample at least one network structure from a sampling space to obtain a network structure sample set; secondly, train each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples; then, matrix-encode each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; finally, based on the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values, an adversarial robustness calibrator is obtained. Thus, the network structure sample set obtained from the sampling space has the same units, and the adversarial robustness calibrator obtained through the sample pairs of the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values of each network structure can obtain a calibration result close to the true adversarial robustness accuracy value on network structures that have not been encountered before, improving the efficiency of adversarial robustness calibration.

[0029] The adversarial robustness calibration method and device provided by the embodiments of the present disclosure first obtain the network structure to be calibrated, and secondly, in response to the network structure belonging to a preset sampling space, use the adversarial robustness calibrator corresponding to the sampling space for calibration to obtain the adversarial robustness accuracy value of the network structure, where the adversarial robustness calibrator is obtained by using the calibration generator method. Thus, through the pre-trained adversarial robustness calibrator, the adversarial robustness accuracy value of the network structure to be calibrated can be calibrated without additional training, improving the efficiency of obtaining the adversarial robustness accuracy value of the network structure. Description of the Drawings

[0030] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objects, and advantages of the present disclosure will become more apparent:

[0031] Figure 1 It is an exemplary system architecture diagram to which an embodiment of the present disclosure can be applied;

[0032] Figure 2 It is a flowchart of an embodiment of the calibration generator method according to the present disclosure;

[0033] Figure 3 It is a schematic diagram of a unit stacking method of a neural network in the present disclosure;

[0034] Figure 4 It is a schematic diagram of a structure of a determined unit in the present disclosure;

[0035] Figure 5 It is a flowchart of an embodiment of the adversarial robustness calibration method according to the present disclosure;

[0036] Figure 6It is a schematic structural diagram of an embodiment of a calibrator generation device according to the present disclosure;

[0037] Figure 7 It is a schematic structural diagram of an embodiment of an adversarial robustness calibration device according to the present disclosure;

[0038] Figure 8 It is a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. Detailed implementation manners

[0039] The present disclosure will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the convenience of description, only parts related to the relevant invention are shown in the drawings.

[0040] It should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The present disclosure will be described in detail below with reference to the drawings and embodiments.

[0041] Figure 1 An exemplary system architecture 100 to which the calibrator generation method or the adversarial robustness calibration method of the present disclosure can be applied is shown.

[0042] As Figure 1 shown, the system architecture 100 may include terminals 101, 102, a network 103, a database server 104, and a server 105. The network 103 is used to provide a medium for communication links between the terminals 101, 102, the database server 104, and the server 105. The network 103 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0043] The user 110 may use the terminals 101, 102 to interact with the server 105 through the network 103 to receive or send messages, etc. Various client applications may be installed on the terminals 101, 102, such as model training applications, image recognition applications, shopping applications, payment applications, web browsers, and instant messaging tools, etc.

[0044] The terminals 101 and 102 here can be hardware or software. When the terminals 101 and 102 are hardware, they can be various electronic devices with a display screen, including but not limited to smart phones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), laptop computers, desktop computers, and so on. When the terminals 101 and 102 are software, they can be installed in the above-listed electronic devices. They can be implemented as multiple software or software modules (for example, to provide distributed services), or can be implemented as a single software or software module. Specific limitations are not made here.

[0045] The database server 104 can be a database server that provides various services. For example, a sampling space can be stored in the database server. The sampling space contains a large number of network structures. In this way, the user 110 can also select a network structure from the sampling space stored in the database server 104 through the terminals 101 and 102.

[0046] The server 105 can also be a server that provides various services, such as a background server that supports various applications displayed on the terminals 101 and 102. The background server can use the network structures in the sampling space sent by the terminals 101 and 102 to generate an adversarial robustness calibrator, and can send the generated adversarial robustness calibrator to the terminals 101 and 102. In this way, the user can apply the generated adversarial robustness calibrator to determine the adversarial robustness of different network structures.

[0047] The database server 104 and the server 105 here can also be hardware or software. When they are hardware, they can be implemented as a distributed server cluster composed of multiple servers, or can be implemented as a single server. When they are software, they can be implemented as multiple software or software modules (for example, to provide distributed services), or can be implemented as a single software or software module. Specific limitations are not made here.

[0048] It should be noted that the calibrator generation method or the adversarial robustness calibration method provided by the embodiments of the present disclosure is generally executed by the server 105. Correspondingly, the calibrator generation device or the adversarial robustness calibration device is generally also set in the server 105.

[0049] It should be pointed out that in the case where the server 105 can implement the related functions of the database server 104, the database server 104 may not be provided in the system architecture 100.

[0050] It should be understood, Figure 1The numbers of terminals, networks, database servers, and servers therein are merely illustrative. According to implementation requirements, there can be any number of terminals, networks, database servers, and servers.

[0051] As Figure 2 , a flowchart 200 of an embodiment of a calibrator generation method according to the present disclosure is shown. The calibrator generation method includes the following steps:

[0052] Step 201, sample at least one network structure from a sampling space to obtain a network structure sample set.

[0053] To better complete the training and application of the adversarial robustness calibrator, it is necessary to impose a limit on the form and scope of the networks that can be calibrated. For example, when calibrating the adversarial robustness of a neural network, it is necessary to set a sampling space related to the neural network, and all network structures for training the adversarial robustness calibrator can be obtained from this sampling space.

[0054] In this embodiment, for different sampling spaces, the sampling rules for sampling the network structure sample set from the sampling space are different. For example, in a text processing task, the sampling rule is to randomly select 200 network structures from the sampling space to obtain a network structure sample set; again, in an image processing task, the sampling rule is to select network structures with a network size exceeding a set threshold from the sampling space to obtain a network structure sample set.

[0055] In this embodiment, the sampling space can be a search space for the same task (e.g., text prediction), or a search space including multiple different tasks (e.g., text prediction, image recognition).

[0056] In this embodiment, the network structure is a unit that composes a neural network. The network structure has an input end and an output end. The network structure can be a hierarchical structure, and each layer in the hierarchical structure has a specific unit (Cell). As Figure 3 The shown network structure is a hierarchical structure including a total of n + 1 layers of cell_0, cell_1... cell_n-1, and cell_n.

[0057] In this embodiment, each layer of each network structure in the sampling space has a unit, and the node structures of the units in each layer are the same. The unit includes multiple nodes, and the node distribution and node information of each node in the network structure are the same. Among them, the unit includes: an input node, an output node, and a middle. Each node is connected by different directed edges, and whether each node is connected by a directed edge and the operation represented by the directed edge may be different.

[0058] In this embodiment, the sampling space may be a DARTS (Differentiable Architecture Search) search space. Each individual network structure in the sampling space is formed by repeated stacking of specific cells. The specific stacking method is as follows: Figure 3 As shown in Figure 1. In each network structure, the input end of each intermediate unit i (i is a natural number greater than 2) is connected to the output end of the units in the previous i-1 and i-2 layers. Since the units are repeatedly stacked, the fundamental differences between different neural networks come from the differences in the internal operations of the units in each layer. The structural unit of each unit is shown in the structural unit in cell_1, which consists of 2 input nodes (such as Figure 3 In1, In2), 1 output node (such as Figure 3 Out) and 4 intermediate nodes (such as Figure 3 It is composed of z1, z2, z3, z4).

[0059] In general, there are 14 ( Figure 3 The total number of dashed lines in the middle) is a directed edge connecting the intermediate nodes, where each directed edge can have multiple possible operations to choose from, so that any one of the multiple operations can be operated as a connection relationship between the nodes.

[0060] Corresponding to different search spaces, the number of operations and operation information are different. For example, in the DARTS search space, there are 8 operations, which are: 3x3 separation convolution, 5x5 separation convolution, 3x3 expansion convolution, 5x5 expansion convolution, 3x3 global maximum pooling, 3x3 global average pooling, direct connection and no connection. For this reason, the number of all possible units in the sampling space (the size of the sampling space) does not exceed 8. 14 .

[0061] In this embodiment, after the operation of the directed edge in each unit in the network structure is determined, the unit has a determined structural unit. Figure 4 In the unit shown, the directed edges of the intermediate nodes are represented by solid lines. The identification of the directed edges of the intermediate nodes can be used to determine which operation is which from a variety of different operations. The operations represented by the directed edges may be the same or may be different.

[0062] In this embodiment, each time the structural unit (such as Figure 3 For any directed edge of the structural unit in the sample, the operation corresponding to the directed edge is performed, and the structural units obtained multiple times or all the structural units obtained are merged to obtain the sampling space.

[0063] Optionally, the sampling space can also be a search space obtained by a method of automatic neural network design based on continuous optimization (neural architecture optimization, abbreviated as NAO). In NAO, an encoder is used to map neural network nodes to a continuous space. The continuous representation of a network is used as input to a predictor to predict the accuracy of this network. Then, a decoder maps the continuous representation of a network back to the result of the network. The performance predictor and the encoder enable us to perform gradient optimization in the continuous space, so as to find the encoding of a new structure with higher accuracy, and then decode the encoding into a network structure through the decoder.

[0064] Optionally, the sampling space can also be a search space obtained by Neural Architecture Search (NAS). Neural Architecture Search is a technique for automatically designing neural networks, which can automatically design high-performance network structures according to a sample set through an algorithm. The principle of NAS is to give a set of candidate neural network structures called the search space, and search for the optimal network structure from it by a certain strategy.

[0065] Based on different ways of obtaining the sampling space, in some alternative implementation manners of this embodiment, the above sampling space can also be constructed through the following steps: determining the structural units that can form a network structure and the types of operations between nodes in the structural units; performing operations corresponding to the types of operations on the directed edges between the nodes of the structural units to obtain the sampling space.

[0066] In this alternative implementation manner, each type of operation corresponds to an operation. After determining the structural units and the types of operations between the nodes in the structural units, successively perform the operations corresponding to the types of operations on the directed edges between the nodes of the structural units, which can traverse all the directed edges and obtain the network structures in the sampling space to the greatest extent.

[0067] The method for constructing the sampling space provided in this embodiment provides a reliable basis for expanding the sampling space by obtaining the network structures in the sampling space through performing operations corresponding to the types of operations.

[0068] Optionally, the above sampling space can also be constructed through the following steps: determining all the nodes that can form a network structure; selecting different nodes from all the nodes to generate the units in each layer of different network structures.

[0069] Step 202: Train each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure.

[0070] The advantages and disadvantages, i.e., the performance, of the network structure of a neural network are measured by certain metrics such as accuracy and speed, which is called performance evaluation. In this embodiment, the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples, and the robustness against adversarial samples is also an index for evaluating the performance of the network structure. Through the adversarial robustness accuracy value, the resistance ability of the network structure to minor perturbations can be analyzed. The larger the perturbation amplitude required for the model to misjudge, the better the robustness of the model.

[0071] In this embodiment, an adversarial sample refers to an input sample that can make a machine learning algorithm output an incorrect result with a minor adjustment. In image recognition, it can be understood that a picture originally classified as a certain class (such as "panda") by a convolutional neural network (CNN) is suddenly misclassified as another class (such as "gibbon") after very subtle changes that are even imperceptible to the human eye. Among them, the generation of adversarial samples is already a mature technology and will not be elaborated in this disclosure.

[0072] In this embodiment, training each network structure in the network structure sample set means actually performing adversarial training on each network structure in the network sample set using an adversarial algorithm to obtain the adversarial robustness accuracy value of each network structure. Among them, adversarial training is an algorithm for improving the robustness of a machine learning model. By making the model use adversarial samples to train the model, the robustness of the model is improved. It should be noted that there are various adversarial algorithms. For example, the Fast Gradient Sign Method (FGSM). In a white-box environment, by calculating the derivative of the model with respect to the input, then using the sign function to obtain its specific gradient direction, and then multiplying by a step size, the "perturbation" obtained is added to the original input to obtain the adversarial sample under the FGSM attack. The network structure is trained adversarially using the obtained adversarial sample, and the adversarial robustness value of the network structure is tested.

[0073] In some alternative implementation manners of this embodiment, the above-mentioned training of each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure includes: based on a preset robustness sample, performing adversarial training on each network structure in the network structure sample set using an adversarial algorithm to obtain the adversarial robustness accuracy value of each network structure.

[0074] In this alternative implementation manner, the preset robustness sample is a pre-annotated sample. By randomly adding "interference" to the robustness sample during adversarial training, an adversarial sample of the current network structure is generated. The adversarial sample is input into the current network structure, and the current network structure is trained until the network structure converges to a value.

[0075] In this embodiment, the network parameters of the network structure can be trained by solving the max-min function shown in Equation (1) until the network structure converges.

[0076]

[0077] Where l in Equation (1) is the loss function of the network structure f θ (.), x i is the input sample, y i is the sample label, δ i is the perturbation solved in the adversarial training, and the absolute value of δ i is less than or equal to the maximum network perturbation ρ a , and θ is the network parameter of the network structure.

[0078] In this alternative implementation, during the training process, when the max-min function shown in Equation (1) no longer changes, θ is determined as the optimal network parameter of the network structure. At this time, the network structure has the strongest robustness. The robustness of the network structure corresponding to the optimal network parameter is tested to obtain the adversarial robustness accuracy value of the network structure. It should be noted that testing the robustness of the network structure is a mature technology and will not be elaborated here.

[0079] In this embodiment, the sampling adversarial algorithm is used to perform adversarial training on each network structure to obtain the robustness accuracy value of each network structure, providing a reliable data basis for training the adversarial robustness calibration.

[0080] Step 203: Matrix-encode each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure.

[0081] In this embodiment, matrix-encoding the network structure can specifically quantify each network structure, providing a reliable data basis for implementing a specific adversarial robustness calibrator.

[0082] For the sampling spaces obtained by different structure search methods, the ways of matrix-encoding the network structure are different.

[0083] For example, when the sampling space is obtained by the NAO method, digital definitions (such as data from 0 to 7) are given to the network nodes in the network structure. Since different network structures sample different network nodes, matrix encoding can gather the numbers represented by each network node together to obtain the encoding matrix corresponding to each network structure.

[0084] For the case where the sampling space is the DARTS search space, in some alternative implementations of this embodiment, the sparse coding formula shown in Equation (2) can be used to obtain the encoding matrix corresponding to each network structure.

[0085] Specifically, the sparse coding formula is used to matrix-encode each network structure in the network structure sample set, obtaining a coding matrix corresponding to each network structure.

[0086] The sparse coding formula is as follows:

[0087]

[0088] Among them, in formula (2), α i,j represents whether there is an operation j on the i-th directed edge of the network structure. If so, the element in the i-th row and j-th column of the sparse coding matrix α will be set to 1; otherwise, it will be set to 0.

[0089] In this alternative implementation, for each layer of units in the network structure, this formula (2) can be uniquely represented by a coding matrix with a dimension of 14x8.

[0090] In this alternative implementation, matrix encoding is performed on the network structure through the sparse coding formula, obtaining a coding matrix corresponding to the network structure, providing a reliable means for the digital result of the network result.

[0091] Step 204: Based on the coding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values, obtain an adversarial robustness calibrator.

[0092] In this embodiment, the adversarial robustness calibrator can be an operation expression obtained through traditional operations. The above-mentioned obtaining of the adversarial robustness calibrator based on the coding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values includes: performing a fitting operation on the coding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values of each network structure to obtain a fitting formula representing the adversarial robustness calibrator. Among them, when inputting the coding matrix of the network structure into the fitting formula, the adversarial robustness accuracy value of this network structure can be obtained, or when inputting the adversarial robustness accuracy value into the fitting formula, all network structures corresponding to this adversarial robustness accuracy value can be determined from the sampling space.

[0093] In this embodiment, the adversarial robustness calibrator can also be a regression model obtained through model training. In some alternative implementation manners of this embodiment, the above-mentioned obtaining of the adversarial robustness calibrator based on the coding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values includes: constructing a perception network of the adversarial robustness calibrator using a multi-layer perceptron; training the perception network using the coding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy values to obtain a trained adversarial robustness calibrator. The adversarial robustness calibrator is used to perform adversarial robustness accuracy calibration on the input coding matrix to obtain an adversarial robustness accuracy value corresponding to the input coding matrix.

[0094] In this alternative implementation, by training an adversarial robustness calibrator through a perception network, after giving the network structure, the adversarial robustness calibrator can directly predict the adversarial robustness accuracy value of the network structure, and the predicted adversarial robustness accuracy value is close to the true robustness accuracy.

[0095] It should be noted that when calculating or predicting the network structure through the adversarial robustness calibrator, the network structure needs to be encoded in a way suitable for the adversarial robustness calibrator to obtain the encoding matrix of the network structure.

[0096] The method for obtaining the adversarial robustness calibrator provided in this alternative implementation uses a multi-layer perceptron to obtain a perception network, which can have a relatively intelligent performance. Further training the perception network using the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set can improve the prediction accuracy of the adversarial robustness calibrator, providing a reliable basis for the robustness calibration of network structures in the sampling space.

[0097] In another alternative implementation of this embodiment, the above-mentioned training of the perception network using the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set to obtain a trained adversarial robustness calibrator includes:

[0098] For each network structure in the network structure sample set, input the encoding matrix of the network structure into the perception network to obtain the predicted accuracy value corresponding to the network structure output by the perception network; based on the predicted accuracy values of all network structures in the network structure sample set and the robustness accuracy values of all network structures, adjust the parameters of the perception network; in response to the perception network satisfying the training completion condition, obtain the trained adversarial robustness calibrator.

[0099] In this alternative implementation, the perception network can be represented by Equation (3):

[0100]

[0101] Among them, in Equation (3), f′(θ,α) is the robustness accuracy calibration function of the adversarial robustness calibrator for the network structure α, used to represent the perception network, W1, b1, and b2 correspond to the model parameters θ of the adversarial robustness calibrator; σ(·) is a non-linear activation function, and α is the encoding matrix of the input network structure. l in Equation (3) is also a non-linear activation function, and non-linear activation functions include ReLU function, Sigmoid function, tanh function, etc.

[0102] By fitting the sample pairs to the data set (the sample pair data set includes at least one sample pair data, and each sample pair data includes the encoding matrix of the network structure and the adversarial robustness accuracy value corresponding to the encoding matrix) through formula (3), the robustness accuracy calibrator obtained can effectively calibrate the robustness accuracy of a new network structure sampled from the same sampling space, thereby reducing the adversarial training cost that needs to be spent on the new network structure.

[0103] In this optional implementation manner, the training completion condition includes at least one of the following: the number of training iterations of the perception network reaches a predetermined iteration threshold. For example, the number of training iterations reaches 50,000 times; the loss value of the perception network is less than a predetermined loss value threshold, where the loss value is calculated by solving the objective function. Optionally, the objective function can adopt a function as shown in formula (4).

[0104]

[0105] Among them, in formula (4), θ = (W1, b1, W2, b2), α (m) is the encoding matrix of the m-th network structure for training in the network structure sample set, and y (m) is its corresponding adversarial robustness accuracy value.

[0106] In this optional implementation manner, when the perception network does not meet the training completion condition, the loss value of the perception network can be converged by adjusting the relevant network parameters in the perception network until the perception network meets the training completion condition.

[0107] In this optional implementation manner, by adjusting the parameters of the perception network, when the entire perception network meets the training completion condition, a trained adversarial robustness calibrator is obtained, providing a reliable basis for the calibration of the network structure.

[0108] The calibrator generation method provided by the embodiments of the present disclosure first samples at least one network structure from a sampling space to obtain a network structure sample set; secondly, trains each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, and the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples; thirdly, matrix-encodes each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; finally, based on the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set, an adversarial robustness calibrator is obtained. Thus, the network structure sample set obtained from the sampling space has the same units, and the adversarial robustness calibrator obtained through the sample pairs of the encoding matrices of each network structure and the adversarial robustness accuracy values of each network structure in the network structure sample set can obtain a calibration result close to the true adversarial robustness accuracy value on network structures not encountered before, improving the efficiency of adversarial robustness calibration.

[0109] Please refer to Figure 5 , which shows the flowchart 500 of an embodiment of the adversarial robustness calibration method provided by the present disclosure. The adversarial robustness calibration method may include the following steps:

[0110] Step 501, obtain the network structure to be calibrated.

[0111] Wherein, the network structure to be calibrated is the network structure whose robustness is to be determined. The network structure to be calibrated may be a network structure in a preset sampling space or may not be a network structure in the sampling space.

[0112] In this embodiment, the execution entity on which the adversarial robustness calibration method runs can communicate with terminals (such as Figure 1 terminals 101 and 102 in

[0113] to obtain the network structure to be calibrated sent by the terminal. In this embodiment, the network structure may be a neural network for implementing different tasks (such as text processing, image recognition, etc.). The network structure may be a multi-level structure. In each layer, the network structure may include input nodes, intermediate nodes, and output nodes, and there are directed edges pointing from one node to another between the nodes. Through the directed edges, the data operations between the nodes can be determined.

[0114] Step 502, in response to the network structure belonging to the preset sampling space, perform calibration using the adversarial robustness calibrator corresponding to the sampling space to obtain the adversarial robustness accuracy value of the network structure.

[0115] Wherein, the adversarial robustness calibrator is obtained by using the calibrator generation method in the above embodiment.

[0116] In this embodiment, after obtaining the network structure to be calibrated, the operations of the nodes and the directed edges between the nodes in the network structure to be calibrated can be compared with the operations of the nodes and the directed edges between the nodes of each network structure in the preset sampling space, and it is detected whether the network structure to be calibrated belongs to the preset sampling space.

[0117] In this embodiment, for the preset sampling space, the calibrator generation method of the above embodiment is used to generate an adversarial robustness calibrator corresponding to the preset sampling space. The specific generation process of the adversarial robustness calibrator can be referred to Figure 2 the relevant descriptions of the embodiment, which will not be elaborated here.

[0118] It should be noted that the adversarial robustness calibration method in this embodiment can be used to test the adversarial robustness calibrators generated in the above embodiments. Furthermore, the adversarial robustness calibrator can be continuously optimized according to the test results. This method can also be the actual application method of the adversarial robustness calibrators generated in the above embodiments. Using the adversarial robustness calibrators generated in the above embodiments for robustness calibration helps to improve the efficiency of obtaining the adversarial robustness accuracy value of the network structure.

[0119] The adversarial robustness calibration method provided in this embodiment first obtains the network structure to be calibrated, and then, in response to the network structure belonging to the preset sampling space, uses the adversarial robustness calibrator corresponding to the sampling space for calibration to obtain the adversarial robustness accuracy value of the network structure. The adversarial robustness calibrator is obtained by using the calibrator generation method. Thus, through the pre-trained adversarial robustness calibrator, the adversarial robustness accuracy value of the network structure to be calibrated can be calibrated without additional training, improving the efficiency of obtaining the adversarial robustness accuracy value of the network structure.

[0120] In another embodiment of the present disclosure, in response to the network structure not belonging to the preset sampling space, the network is subjected to adversarial training to obtain the adversarial robustness value of the network structure.

[0121] Optionally, in response to the network structure not belonging to the preset sampling space but belonging to the first sampling space, based on the first sampling space, the calibrator generation method provided in this embodiment is used to generate a new adversarial robustness calibrator corresponding to the first sampling space, and the new adversarial robustness calibrator is used to calibrate the network structure to obtain the adversarial robustness accuracy value of the network structure. In this embodiment, the first sampling space is a search space that is completely different from the preset sampling space. For example, the preset sampling uses the search space obtained by DARTS, and the first sampling space uses the search space obtained by NAS.

[0122] In some embodiments, the above-mentioned adversarial robustness calibration method further includes: using an adversarial robustness calibrator to determine the adversarial robustness accuracy values of each network structure in the sampling space.

[0123] In this alternative implementation, an adversarial robustness calibrator can be used to calibrate the adversarial robustness of all network structures in the sampling space and label the adversarial robustness accuracy values for each network structure in the sampling space, thereby providing a reliable basis for the subsequent use of the robustness of network structures.

[0124] Further referring to Figure 6 , as an implementation of the methods shown in the above figures, an embodiment of a calibrator generation device is provided in the present disclosure. This device embodiment corresponds to Figure 2 the method embodiment shown, and this device can be specifically applied to various electronic devices.

[0125] As Figure 6 shown, an embodiment of the present disclosure provides a calibrator generation device 400. This device 600 includes: a sampling unit 601, a training unit 602, an encoding unit 603, and an obtaining unit 604. Among them, the above-mentioned sampling unit 601 can be configured to sample at least one network structure from the sampling space to obtain a network structure sample set. The above-mentioned training unit 602 can be configured to train each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure. The adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples. The above-mentioned encoding unit 603 can be configured to perform matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure. The above-mentioned obtaining unit 604 can be configured to obtain an adversarial robustness calibrator based on the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set.

[0126] In this embodiment, in the calibrator generation device 600, the specific processing of the sampling unit 601, the training unit 602, the encoding unit 603, and the obtaining unit 604 and the technical effects brought by them can be respectively referred to Figure 2 steps 201, 202, 203, and 204 in the corresponding embodiments.

[0127] In some embodiments, the above-mentioned sampling space is constructed by a construction unit. The construction unit is configured to determine the structural units that can form a network structure and the types of operations between the nodes in the structural units; perform operations corresponding to the types of operations on the directed edges between the nodes of the structural units to obtain the sampling space.

[0128] In some embodiments, the above training unit 602 is further configured to perform adversarial training on each network structure in the network structure sample set based on preset robust samples by using an adversarial algorithm, so as to obtain the adversarial robustness accuracy value of each network structure.

[0129] In some embodiments, the above encoding unit 603 is further configured to: perform matrix encoding on each network structure in the network structure sample set by using a sparse encoding formula to obtain an encoding matrix corresponding to each network structure;

[0130] The sparse encoding formula is:

[0131] where α i,j represents whether there is an operation j on the i-th directed edge of the network structure. If so, the element in the i-th row and j-th column of the sparse encoding matrix α will be set to 1, otherwise it will be set to 0.

[0132] In some embodiments, the above obtaining unit 604 includes: a construction module (not shown in the figure), a training module (not shown in the figure). Among them, the above construction module can be configured to construct the perception network of the adversarial robustness calibrator by using a multi-layer perceptron. The above training module can be configured to train the perception network by using the encoding matrix and the adversarial robustness accuracy value of each network structure in the network structure sample set to obtain a trained adversarial robustness calibrator, and the adversarial robustness calibrator is used to perform adversarial robustness accuracy calibration on the input encoding matrix to obtain the adversarial robustness accuracy value corresponding to the input encoding matrix.

[0133] In some embodiments, the above training module is further configured to: for each network structure in the network structure sample set, input the encoding matrix of the network structure into the perception network to obtain the predicted accuracy value corresponding to the network structure output by the perception network; based on the predicted accuracy values of all network structures in the network structure sample set and the robustness accuracy values of all network structures, adjust the parameters of the perception network; in response to the perception network satisfying the training completion condition, obtain a trained adversarial robustness calibrator.

[0134] The calibrator generation device provided by the embodiments of the present disclosure first samples at least one network structure from a sampling space by a sampling unit 601 to obtain a network structure sample set. Each network structure in the sampling space includes at least one unit, and the node structures of each unit are the same. Next, a training unit 602 trains each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, and the adversarial robustness accuracy value is used to characterize the robustness of the network structure to adversarial samples. Then, an encoding unit 603 performs matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure. Finally, an obtaining unit 604 obtains an adversarial robustness calibrator based on the encoding matrices and adversarial robustness accuracy values of each network structure in the network structure sample set. Thus, the network structure sample set obtained from the sampling space has the same units. The obtained adversarial robustness calibrator based on the sample pairs of the encoding matrices of each network structure and the adversarial robustness accuracy values of each network structure in the network structure sample set can obtain a calibration result close to the true adversarial robustness accuracy value on network structures not encountered before, improving the efficiency of adversarial robustness calibration.

[0135] Further referring to Figure 7 , as an implementation of the methods shown in the above figures, an embodiment of an adversarial robustness calibration device is provided by the present disclosure. This device embodiment corresponds to Figure 5 the method embodiment shown, and this device can be specifically applied to various electronic devices.

[0136] As Figure 7 shown, an embodiment of the present disclosure provides an adversarial robustness calibration device 700. The device 700 includes: an obtaining unit 701 and a calibrating unit 702. Among them, the above-mentioned obtaining unit 701 can be configured to obtain a network structure to be calibrated. The above-mentioned calibrating unit 702 can be configured to, in response to the network structure belonging to a preset sampling space, perform calibration using an adversarial robustness calibrator corresponding to the sampling space to obtain the adversarial robustness accuracy value of the network structure, and the adversarial robustness calibrator is obtained by using the calibrator generation device disclosed in the above embodiments.

[0137] In this embodiment, in the adversarial robustness calibration device 700, the specific processing of the obtaining unit 701 and the calibrating unit 702 and the technical effects brought by them can respectively refer to Figure 5 step 501 and step 502 in the corresponding embodiments.

[0138] In some embodiments, the above-mentioned device further includes: a determining unit (not shown in the figure). The above-mentioned determining unit can be configured to use the adversarial robustness calibrator to determine the adversarial robustness accuracy values of each network structure in the sampling space.

[0139] The anti-robustness calibration device provided in this embodiment first has an acquisition unit 701 acquire the network structure to be calibrated. Secondly, in response to the network structure belonging to a preset sampling space, a calibration unit 702 performs calibration using an anti-robustness calibrator corresponding to the sampling space to obtain the anti-robustness accuracy value of the network structure. The anti-robustness calibrator is obtained using a calibrator generation device. Thus, through the pre-trained anti-robustness calibrator, without additional training, the anti-robustness accuracy value of the network structure to be calibrated can be calibrated, improving the efficiency of obtaining the anti-robustness accuracy value of the network structure.

[0140] The present disclosure also provides an embodiment of a calibrator. The calibrator provided in the embodiment of the present disclosure is obtained using a calibrator generation method. By calibrating the network result to be calibrated using the calibrator of the present disclosure, the anti-robustness accuracy value of the network structure to be calibrated can be obtained quickly and conveniently, thereby improving the efficiency of obtaining the anti-robustness accuracy value of the network structure.

[0141] Reference is made below to Figure 8 , which shows a schematic structural diagram of an electronic device 800 suitable for implementing the embodiments of the present disclosure.

[0142] As Figure 8 shown, the electronic device 800 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 801, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 are also stored. The processing device 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0143] Generally, the following devices may be connected to the I / O interface 805: an input device 806 including, for example, a touch screen, a touchpad, a keyboard, a mouse, etc.; an output device 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 808 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 may allow the electronic device 800 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 8 shows the electronic device 800 having various devices, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be alternatively implemented or had. Figure 8 Each block shown in

[0144] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication device 809, or installed from the storage device 808, or installed from the ROM 802. When the computer program is executed by the processing device 801, the above-described functions defined in the method of the embodiment of the present disclosure are performed.

[0145] It should be noted that the computer-readable medium of the embodiment of the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment of the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the embodiment of the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0146] The above computer-readable medium may be included in the above server; or it may exist independently without being assembled into the server. The above computer-readable medium carries one or more programs, and when the one or more programs are executed by the server, the server is caused to: sample at least one network structure from a sampling space to obtain a network structure sample set; train each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure to adversarial samples; perform matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; and obtain an adversarial robustness calibrator based on the encoding matrices and the adversarial robustness accuracy values of the network structures in the network structure sample set.

[0147] Computer program code for performing the operations of the embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0148] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0149] The units involved in the embodiments described in this disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor including a sampling unit, a training unit, an encoding unit, and an obtaining unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the sampling unit can also be described as a unit "configured to sample at least one network structure from a sampling space to obtain a network structure sample set".

[0150] The above description is only a preferred embodiment of this disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the embodiments of this disclosure.

Claims

1. A calibrator generation method, the method comprising: Sampling at least one network structure from a sampling space to obtain a network structure sample set. For different sampling spaces, the sampling rules for sampling the network structure sample set from the sampling space are different. The sampling rule is to randomly select multiple network structures from the sampling space to obtain the network structure sample set in a text processing task; or, the sampling rule is to select network structures with a network size exceeding a set threshold from the sampling space to obtain the network structure sample set in an image processing task; Training each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples; Performing matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure; Based on the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy value, obtaining an adversarial robustness calibrator.

2. The method according to claim 1, wherein The sampling space is constructed by the following steps: Determining the structural units that can form a network structure and the types of operations between nodes in the structural units; Performing operations corresponding to the types of operations on the directed edges between the nodes of the structural units to obtain a sampling space.

3. The method according to claim 1, wherein The training of each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure includes: Based on a preset robustness sample, using an adversarial algorithm to perform adversarial training on each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure.

4. The method according to claim 2, wherein The performing matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure includes: Performing matrix encoding on each network structure in the network structure sample set using a sparse coding formula to obtain an encoding matrix corresponding to each network structure; The sparse coding formula is: where α i,j represents whether the operation j exists on the i-th directed edge of the network structure. If it exists, the element in the i-th row and j-th column of the sparse coding matrix α will be set to 1; otherwise, it will be set to 0.

5. The method according to claim 4, wherein, The obtaining an adversarial robustness calibrator based on the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy value includes: Using a multi-layer perceptron to construct a perception network of the adversarial robustness calibrator; Training the perception network using the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy value to obtain a trained adversarial robustness calibrator, where the adversarial robustness calibrator is used to calibrate the adversarial robustness accuracy of the input encoding matrix to obtain an adversarial robustness accuracy value corresponding to the input encoding matrix.

6. The method according to claim 5, wherein, The training the perception network using the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy value to obtain a trained adversarial robustness calibrator includes: For each network structure in the network structure sample set, inputting the encoding matrix of this network structure into the perception network to obtain the predicted accuracy value corresponding to this network structure output by the perception network; Adjust the parameters of the perception network based on the prediction accuracy values of all network structures in the network structure sample set and the robustness accuracy values of all network structures. In response to the perception network satisfying the training completion condition, obtain a trained adversarial robustness calibrator.

7. An adversarial robustness calibration method, the method comprising: Obtain a network structure to be calibrated. In response to the network structure belonging to a preset sampling space, perform calibration using an adversarial robustness calibrator corresponding to the sampling space to obtain the adversarial robustness accuracy value of the network structure, where the adversarial robustness calibrator is obtained by using the calibrator generation method described in any one of claims 1-6.

8. According to the method of claim 7, the method further comprises: Use the adversarial robustness calibrator to determine the adversarial robustness accuracy values of each network structure in the sampling space.

9. A calibrator generation device, the device comprising: A sampling unit configured to sample at least one network structure from a sampling space to obtain a network structure sample set, where for different sampling spaces, the sampling rules for sampling the network structure sample set from the sampling space are different. The sampling rule is to randomly select multiple network structures from the sampling space to obtain the network structure sample set in a text processing task; or, the sampling rule is to select network structures with a network size exceeding a set threshold from the sampling space to obtain the network structure sample set in an image processing task. A training unit configured to train each network structure in the network structure sample set to obtain the adversarial robustness accuracy value of each network structure, where the adversarial robustness accuracy value is used to characterize the robustness of the network structure against adversarial samples. An encoding unit configured to perform matrix encoding on each network structure in the network structure sample set to obtain an encoding matrix corresponding to each network structure. A obtaining unit configured to obtain an adversarial robustness calibrator based on the encoding matrices of each network structure in the network structure sample set and the adversarial robustness accuracy value.

10. An adversarial robustness calibration device, the device comprising: An obtaining unit configured to obtain a network structure to be calibrated. A calibration unit configured to, in response to the network structure belonging to a preset sampling space, perform calibration using an adversarial robustness calibrator corresponding to the sampling space to obtain the adversarial robustness accuracy value of the network structure, where the adversarial robustness calibrator is obtained by using the calibrator generation device described in claim 9.

11. A calibrator obtained by using the calibrator generation method described in any one of claims 1-6.

12. An electronic device, comprising: One or more processors; A storage device having stored thereon one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any one of claims 1-8.

13. A computer-readable medium having a computer program stored thereon, wherein, When the program is executed by the processor, it implements the method described in any one of claims 1-8.

14. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Robust license plate and logo recognition method

    CN106650731A

  • Unified scene visual positioning method based on generative adversarial network

    CN111724443A