Highly robust adversarial sample generation method and system for underwater acoustic intelligent camouflage

By designing adversarial perturbations with noise resistance and data expansion in underwater acoustic environments and combining iterative ensemble learning to generate optimal adversarial samples, the problems of insufficient transferability and robustness of adversarial samples in underwater acoustic environments are solved, achieving a stronger camouflage effect.

CN115169216BActive Publication Date: 2025-09-05HARBIN ENG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210574452.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-25
Publication Date
2025-09-05
Estimated Expiration
2042-05-25

AI Technical Summary

Technical Problem

Existing technologies lack the transferability and robustness of adversarial samples in underwater acoustic environments, making it difficult to effectively disguise enemy intelligent systems.

Method used

By designing anti-noise capabilities against perturbations and expanding training data, a second enhanced dataset is generated. Combined with the iterative ensemble learning method, the substitute model is trained to generate optimal adversarial samples, thereby improving the transferability and robustness of adversarial samples.

Benefits of technology

It improves the noise resistance and generalization attack capability of adversarial samples in underwater acoustic environments, enhances the success rate of deceiving enemy recognition models, resists defense methods, and improves camouflage effects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115169216B_ABST
    Figure CN115169216B_ABST
Patent Text Reader

Abstract

The present invention discloses a highly robust adversarial sample generation method and system for underwater acoustic intelligent camouflage, belonging to the fields of digital image processing and underwater acoustic signal processing. Specifically, the method comprises: designing a perturbation enhancement method based on training data expansion to enhance the noise resistance of the adversarial perturbation, thereby expanding the training dataset to obtain a second enhanced dataset; treating the enemy's recognition model as an unknown black box, performing a black box attack on it based on the second enhanced dataset, and employing an iterative ensemble learning method to train a surrogate model to obtain the optimal adversarial sample. This method further constrains the adversarial perturbation by utilizing the conversion mechanism between sound waves and various spectra, enabling it to be insensitive to the human eye but capable of deceiving machine learning models. Furthermore, a data enhancement scheme is designed for environmental and self-noise to complete the noise resistance of the adversarial sample. Furthermore, based on ensemble learning, the transferability and generalization capabilities of the adversarial sample are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of digital image processing technology and underwater acoustic signal processing technology, and in particular to a highly robust adversarial sample generation method and system for underwater acoustic intelligent camouflage. Background Art

[0002] The attack and defense environment in the ocean differs from that on land. Optical and electrical signals are severely attenuated in seawater, while acoustic waves, compared to optical and electromagnetic waves, are more resistant to attenuation in water, making them a crucial medium for underwater communications. The introduction of deep learning technology has greatly improved the ability of intelligent systems to identify underwater acoustic targets, but it is not invulnerable. Exploitation of machine learning model vulnerabilities has been a hot topic in the fields of artificial intelligence and information security. These attacks, which target the integrity and classification accuracy of machine learning models, are commonly referred to as "adversarial attacks." Based on the understanding of the enemy model, these attacks can be categorized as "black-box attacks" and "white-box attacks," differing in whether the enemy's machine learning model and its parameters are known. In underwater enemy-to-enemy confrontations, the enemy model is clearly a black box. Based on the attack target, these attacks can be categorized as "targeted attacks" and "untargeted attacks." Targeted attacks aim to induce the enemy model to make a specific misclassification, addressing multi-classification problems. Untargeted attacks simply trick the enemy model into misclassifying, regardless of the type of classification, addressing binary classification problems. This also applies to the underwater acoustic confrontation environment of this method.

[0003] Good noise immunity reflects the robustness requirements of camouflage systems from a data perspective. Furthermore, the transferability of adversarial examples is a robustness metric that many researchers are particularly interested in from the perspective of attack models. Transferability refers to the ability of adversarial examples to deceive different machine learning models and can also be understood as a universal camouflage capability across models. Chen Kai and other researchers at the Institute of Information Engineering of the Chinese Academy of Sciences trained a white-box surrogate model that approximates the attack model, enabling universal attacks without knowing the model, its parameters, or prior knowledge. Hu Xiaolin and other researchers at Tsinghua University proposed a two-step optimized adversarial perturbation generation algorithm that uses room impulse response to overcome distortion introduced by audio playback detection, hardware, and physical signal paths, enabling dual attacks in the digital and physical domains. However, the reflection characteristics of sound waves in the ocean environment differ significantly from those in indoor environments. Professor He Kun of Huazhong University of Science and Technology proposed an algorithm based on variance-adjusted iterative gradients to stabilize the update direction during the search process and avoid local optimal solutions, ultimately improving the transferability of examples to black-box models. Professor Ye Dengpan of Wuhan University proposed a method for constructing acoustic adversarial examples specifically for voice forensics, and used an ensemble model to improve the transferability of adversarial examples, enabling black-box attacks. Generally speaking, research on the transferability of adversarial examples in the acoustic field started later than in the visual field. Other researchers have studied transferability from the perspectives of model and data space. For example, scholars from Shanghai Jiaotong University and the University of California, Los Angeles, conducted a large-scale transferability study on various deep neural network architectures, concluding that "targeted attack" adversarial examples have poor transferability, and that changes in model hyperparameters can affect transferability. Researchers from Stanford and Google conducted transferability analysis based on the similar classification boundaries of different machine learning models. They found that subtle adjustments to the adversarial perturbations can achieve deceptive transfer across different models, and demonstrated that transferability is an inherent property of adversarial examples in both their feature vectors and their input space. Ilyas et al. from MIT have similarly explored the transferability of adversarial examples. Summary of the Invention

[0004] The present invention aims to solve one of the technical problems in the related art at least to a certain extent.

[0005] To this end, the first purpose of the present invention is to propose a highly robust adversarial sample generation method for underwater acoustic intelligent camouflage, which realizes intelligent camouflage against the enemy in underwater acoustic confrontation scenarios to improve the robustness of intelligent camouflage technology.

[0006] The second purpose of the present invention is to propose a highly robust adversarial sample generation system for underwater acoustic intelligent camouflage.

[0007] A third object of the present invention is to provide a computer device.

[0008] A fourth object of the present invention is to provide a non-transitory computer-readable storage medium.

[0009] To achieve the above-mentioned objectives, an embodiment of the present invention proposes a highly robust adversarial sample generation method for underwater acoustic intelligent camouflage, comprising the following steps: step S1, designing the anti-noise capability of adversarial perturbations based on a disturbance enhancement method of training data expansion to expand the training data set to obtain a second enhanced data set; step S2, treating the enemy's recognition model as an unknown black box, performing a black box attack on it according to the second enhanced data set, and adopting an iterative ensemble learning method to train the substitute model to obtain the optimal adversarial sample.

[0010] The highly robust adversarial sample generation method for underwater acoustic intelligent camouflage in an embodiment of the present invention designs a data enhancement scheme for environmental and self-noise to complete the noise resistance construction of adversarial samples, and then improves the transferability of adversarial samples and the generalization ability based on ensemble learning, thereby improving the robustness of intelligent camouflage technology.

[0011] In addition, the highly robust adversarial sample generation method for underwater acoustic intelligent camouflage according to the above embodiment of the present invention may also have the following additional technical features:

[0012] Furthermore, in one embodiment of the present invention, the step S1 specifically includes: step S101, referring to the idea of ​​"matching field" in ocean acoustics, gridding the sea area to be measured, and collecting the environmental noise in each grid in different time periods to construct an initial data set x; step S102, combining the preset known ocean big data to perform distribution rate modeling on the data set of the sea area to be measured, setting the underwater random noise ξ to obey the model distribution, and considering the environmental random noise interference ξ′ of the unfamiliar underwater scene, to obtain the first increased data set Step S104, considering the simulation amount with different Doppler effects caused by the random noise interference caused by the movement of the ship The simulation amount is expanded to the first adversarial sample data set to obtain the second enhanced data set

[0013] Furthermore, in one embodiment of the present invention, the step S102 is specifically as follows: when considering the environmental random noise interference of the underwater unfamiliar scene, it is defined as a random quantity ξ′:U(0,Ξ), ξ′ is a random quantity that obeys a uniform distribution between 0 and a maximum value Ξ, and the underwater random noise ξ and the environmental random noise interference ξ′ are introduced into the data set to obtain a first increased data set

[0014] Furthermore, in one embodiment of the present invention, step S2 specifically includes:

[0015] Step S201: preset any sample x and its sample label l of the second enhanced data set, and set the enemy's recognition model As an unknown black box, the standard cross entropy loss function and iterative attack method are used to obtain the ability to deceive the recognition model. Adversarial examples

[0016] Step S202: attack multiple avatar models simultaneously and obtain an integrated model by weighted summation. and Get other black box models f that the adversarial sample can attack k+1 The objective function of

[0017] Step S203: The adversarial sample generation method based on the integrated model inputs the underwater acoustic signal dataset containing sound waves and spectrograms as training samples into each surrogate model to obtain the output label l of each surrogate model. i Confidence

[0018] Step S204: weighted average value Calculate the loss function, then iteratively update along the gradient direction of the loss function until the loss value is stable and the iteration ends, and output the optimal adversarial sample.

[0019] Furthermore, in one embodiment of the present invention, the standard cross entropy loss function in step S201 is:

[0020]

[0021] Among them, f is the enemy's machine learning recognition model, is an adversarial sample, l is the model classification label of the original sample x, i is any one of the training samples, and f i is the i-th avatar model, l i is the output label of each avatar model.

[0022] Furthermore, in one embodiment of the present invention, the iterative attack method in step S201 is:

[0023]

[0024] in, is the initial sample, x is the original sample, is the sample that can deceive the model f(x) after t+1 iterations, is the sample obtained after t iterations, t is the number of iterations, α is the small step size, is the gradient of the loss function, f(x+h) is the output of the sample after adding the seabed reverberation and inputting it into the recognition model f, h is the seabed reverberation, and l is the sample label.

[0025] Furthermore, in one embodiment of the present invention, the objective function in step S202 is:

[0026]

[0027] Among them, l is the sample label, k is the number of substitute models f1,...,f k , is the ensemble model obtained by weighted summation, and w i is the short-time Fourier transform window function, f i is any one of the k surrogate models, x is the initial sample, h is the seabed reverberation, ∈ is the adversarial perturbation, and β is a constant.

[0028] To achieve the above-mentioned objectives, the second embodiment of the present invention proposes a highly robust adversarial sample generation system for underwater acoustic intelligent camouflage, including: constructing a dataset module for designing anti-noise capabilities against disturbances, a disturbance enhancement method based on training data expansion, so as to expand the training dataset to obtain a second enhanced dataset; an optimal adversarial sample generation module, which is used to treat the enemy's recognition model as an unknown black box, perform a black box attack on it according to the second enhanced dataset, and use an iterative ensemble learning method to train the substitute model to obtain the optimal adversarial sample.

[0029] The highly robust adversarial sample generation system for underwater acoustic intelligent camouflage of the embodiment of the present invention designs a data enhancement scheme for environmental and self-noise to complete the noise resistance construction of adversarial samples, and then improves the transferability of adversarial samples and improves the generalization ability based on ensemble learning, thereby improving the robustness of intelligent camouflage technology.

[0030] To achieve the above-mentioned objectives, an embodiment of the third aspect of the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements a highly robust adversarial sample generation method for underwater acoustic intelligent camouflage as described in the above-mentioned embodiment.

[0031] To achieve the above-mentioned objectives, an embodiment of the fourth aspect of the present invention provides a non-temporary computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements the highly robust adversarial sample generation method for underwater acoustic intelligent camouflage as described in the above-mentioned embodiment.

[0032] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0034] Figure 1 This is a flowchart of a method for generating highly robust adversarial samples for underwater acoustic intelligent camouflage according to an embodiment of the present invention;

[0035] Figure 2 This is a specific execution diagram of a highly robust adversarial sample generation method for underwater acoustic intelligent camouflage according to an embodiment of the present invention;

[0036] Figure 3 This is a schematic diagram of a design of a disturbance-resistance and noise-resistance capability for random noise according to an embodiment of the present invention;

[0037] Figure 4 Schematic diagram of the design of adversarial sample transfer capability based on ensemble learning according to one embodiment of the present invention;

[0038] Figure 5 It is a structural diagram of a highly robust adversarial sample generation device for underwater acoustic intelligent camouflage according to an embodiment of the present invention. DETAILED DESCRIPTION

[0039] The following describes embodiments of the present invention in detail, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and are not to be construed as limiting the present invention.

[0040] The following describes a highly robust adversarial sample generation method and system for underwater acoustic intelligent camouflage proposed in accordance with an embodiment of the present invention with reference to the accompanying drawings. First, the highly robust adversarial sample generation method for underwater acoustic intelligent camouflage proposed in accordance with an embodiment of the present invention will be described with reference to the accompanying drawings.

[0041] Figure 1 This is a flowchart of a method for generating highly robust adversarial samples for underwater acoustic intelligent camouflage according to an embodiment of the present invention.

[0042] like Figure 1 and 2 As shown, the method includes the following steps:

[0043] In step S1, a method for enhancing the amount of disturbance based on training data expansion is performed to design an anti-noise capability to combat disturbances, so as to expand the training data set to obtain a second enhanced data set.

[0044] Furthermore, step S1 specifically includes:

[0045] Step S101 , referring to the concept of “matched field” in ocean acoustics, the sea area to be measured is gridded, and the environmental noise in each grid is collected in different time periods to construct an initial data set x;

[0046] Step S102: Combine the preset known ocean big data to perform distribution rate modeling on the data set of the sea area to be tested, set the underwater random noise ξ to obey the model distribution, and consider the environmental random noise interference ξ′ of the unfamiliar underwater scene to obtain the first increased data set

[0047] Step S104, considering the simulation amount with different Doppler effects caused by the random noise interference caused by the movement of the ship Expand the simulation amount to the first adversarial sample dataset to obtain the second enhanced dataset

[0048] Specifically, referring to the idea of ​​"matching field" in ocean acoustics, the target sea area is gridded, and the environmental noise in each grid is collected in different time periods to construct a data set; the noise data set of the tested sea area is modeled with the distribution rate based on the existing ocean big data, and the underwater random noise ξ is set to obey the model distribution; considering the environmental random noise interference ξ′ of unfamiliar underwater scenes, it is defined as a random quantity ξ′:U(0,Ξ), ξ′ is a random quantity that obeys a uniform distribution between 0 and the maximum value Ξ (an empirical value set by humans), underwater random noise ξ and environmental random noise interference ξ′ are introduced into the data set to improve the diversity of the underwater acoustic sample data set, and the first increased data set is obtained. Among them, x is the simulation value of the ship's underwater acoustic signal, using The mixed data set of x and x is used to train the generative model of adversarial samples. It not only takes into account the reverberation of the seabed, but also enhances the quality and quantity of the original data by adding random noise, significantly reducing the impact of external and internal uncertainties of the ship on the success rate of deception in practice; finally, considering the random noise interference caused by the movement of the ship, under the premise of testing and modeling the ship's own noise in advance, the frequency offset of x and ∈ caused by the Doppler effect γ is studied. If our ship and the enemy sonar are moving in opposite directions, the frequency of the signal received by the sonar is f′ ship Than the true frequency f of the ship's underwater acoustic signal ship The relationship between the two is shown in formula (6), where c is the underwater sound speed (close to a constant), v is the radial motion speed between the ship and the sonar, and usually c>>.

[0049] f′ ship =(c / (cv))f ship

[0050] On the contrary, when the two are moving in opposite directions, the frequency relationship between them is shown in formula (7), and the received signal frequency is lower than the true frequency.

[0051] f′ ship =(c / (c+v))f ship

[0052] γ=c / (c±v)≈1±(v / c)=1±κ, κ=v / c is the relative Doppler frequency shift. In the process of generating adversarial samples, κ:U(-0.02,0.02) is usually set, that is, κ is a random number in the range of -0.02 to 0.02. Thus, a series of simulations with different Doppler effects can be generated. The frequency of the simulation quantity has a random variation value Δ κ The above simulation dataset is expanded into the training set of the adversarial sample generation model to obtain the second enhanced dataset: It can further improve the robustness of adversarial samples and enhance the performance of adversarial samples.

[0053] In step S2, the enemy's recognition model is treated as an unknown black box, and a black box attack is performed on it based on the second enhanced dataset. The substitute model is trained using an iterative ensemble learning method to obtain the optimal adversarial sample.

[0054] Furthermore, if Figure 3 and 4 As shown, in one embodiment of the present invention, step S2 specifically includes:

[0055] Step S201: preset any sample x and its sample label l of the second enhanced data set, and set the enemy's recognition model As an unknown black box, β is a constant, and the standard cross entropy loss function and iterative attack method are used to obtain the ability to deceive the recognition model. Adversarial examples Specifically,

[0056] The standard cross entropy loss function is:

[0057]

[0058] Among them, f is the enemy's machine learning recognition model, is an adversarial sample, l is the model classification label of the original sample x, i is any one of the training samples, and f i is the i-th avatar model, l iis the output label of each avatar model;

[0059] At the same time, the iterative attack method can be used to achieve adversarial sample optimization through multi-step updates, where t is the number of iterations and α is a small step size, that is:

[0060]

[0061] in is the initial sample, x is the original sample, is the sample that can deceive the model f(x) after t+1 iterations, is the sample obtained after t iterations, t is the number of iterations, α is the small step size, is the gradient of the loss function, f(x+h) is the output of the sample after adding the seabed reverberation and inputting it into the recognition model f, h is the seabed reverberation, and l is the sample label;

[0062] Through the above iterative process, a real sample x is gradually perturbed to obtain the Adversarial examples

[0063] Step S202: In order to further improve the success rate of the black box attack, multiple surrogate models are attacked at the same time. Given k surrogate models f1,...,f k , and perform weighted summation to obtain the integrated model and Get other black box models f that the adversarial sample can attack k+1 The objective function is:

[0064]

[0065] Among them, l is the sample label, k is the number of substitute models f1,...,f k , is the ensemble model obtained by weighted summation, and w i is the short-time Fourier transform window function, f i is any one of the k surrogate models, x is the initial sample, h is the seabed reverberation, ∈ is the adversarial perturbation, and β is a constant.

[0066] Step S203: The adversarial sample generation method based on the integrated model uses the underwater acoustic signal dataset containing sound waves and spectrograms as training samples x to input into each avatar model f i In the example, we get the output label l of each avatar model i Confidence

[0067] Step S204: weighted average value Calculate the loss function and then iteratively update along the gradient direction of the loss function until the loss value is stable and the optimal adversarial sample is output.

[0068] In summary, the highly robust adversarial sample generation method for underwater acoustic intelligent camouflage proposed in the embodiments of the present invention has the following beneficial effects:

[0069] (1) Since the complexity of the underwater environment usually exceeds the preset settings of many machine learning models, random noise other than seabed reverberation has potential interference with adversarial perturbations, making it possible for adversarial samples to fail in disguise in real environments, effectively improving the noise resistance of adversarial samples.

[0070] (1) It can make adversarial samples have stronger generalization attack capabilities, reduce the "paranoia" of adversarial samples in deceiving various recognition models, and effectively resist various defense methods against adversarial samples.

[0071] (3) It can ensure that the success rate of camouflage against the enemy's recognition model black box attack is improved in the real environment, thereby improving the forgery effect.

[0072] Next, a highly robust adversarial sample generation system for underwater acoustic intelligent camouflage proposed according to an embodiment of the present invention will be described with reference to the accompanying drawings.

[0073] Figure 5 It is a structural diagram of a highly robust adversarial sample generation system for underwater acoustic intelligent camouflage according to an embodiment of the present invention.

[0074] like Figure 5 As shown, the system 10 includes: a dataset construction module 100 and an optimal adversarial sample generation module 200.

[0075] The dataset construction module 100 is used to design noise immunity against perturbations using a perturbation enhancement method based on training data expansion to expand the training dataset to obtain a second enhanced dataset. The optimal adversarial example generation module 200 is used to treat the enemy's recognition model as an unknown black box, perform a black-box attack on it based on the second enhanced dataset, and train a surrogate model using an iterative ensemble learning method to obtain the optimal adversarial example.

[0076] It should be noted that the above explanation of the embodiment of the highly robust adversarial sample generation method for underwater acoustic intelligent camouflage is also applicable to the system of this embodiment and will not be repeated here.

[0077] The highly robust adversarial sample generation system for underwater acoustic intelligent camouflage proposed in an embodiment of the present invention has the following beneficial effects:

[0078] (1) Since the complexity of the underwater environment usually exceeds the preset settings of many machine learning models, random noise other than seabed reverberation has potential interference with adversarial perturbations, making it possible for adversarial samples to fail in disguise in real environments, effectively improving the noise resistance of adversarial samples.

[0079] (1) It can make adversarial samples have stronger generalization attack capabilities, reduce the "paranoia" of adversarial samples in deceiving various recognition models, and effectively resist various defense methods against adversarial samples.

[0080] (3) It can ensure that the success rate of camouflage against the enemy's recognition model black box attack is improved in the real environment, thereby improving the forgery effect.

[0081] In the description of this specification, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0082] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Thus, a feature specified as "first" or "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "N" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0083] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing a custom logical function or step of a process, and the scope of the preferred embodiments of the invention includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by those skilled in the art to which embodiments of the invention pertain.

[0084] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or N wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.

[0085] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiment, the N steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having logic gate circuits for implementing logic functions on data signals, an application-specific integrated circuit having suitable combinational logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0086] Those skilled in the art will appreciate that all or part of the steps in the method of the above-described embodiment may be accomplished by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0087] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing module, or each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium.

[0088] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present invention have been shown and described above, it should be understood that the above embodiments are exemplary and are not to be construed as limiting the present invention. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A highly robust adversarial sample generation method for underwater acoustic intelligent camouflage, characterized by: The following steps are involved: Step S1, designing an anti-noise capability to combat disturbances by using a disturbance enhancement method based on training data expansion to expand the training data set to obtain a second enhanced data set; Step S2, treating the enemy's recognition model as an unknown black box, performing a black box attack on it based on the second enhanced dataset, and using an iterative ensemble learning method to train a surrogate model to obtain an optimal adversarial sample; The step S2 specifically includes: Step S201: Preset any sample of the second enhanced data set and its sample labels , while the enemy's recognition model As an unknown black box, the standard cross entropy loss function and iterative attack method are used to obtain the ability to deceive the recognition model. Adversarial examples ; Step S202: attack multiple avatar models simultaneously and obtain an integrated model by weighted summation. ,and , get other black box models that the adversarial samples can attack The objective function of Step S203: The adversarial sample generation method based on the integrated model inputs the underwater acoustic signal dataset containing sound waves and spectrograms as training samples into each surrogate model to obtain the output label of each surrogate model. Confidence ; Step S204: weighted average value Calculate the loss function, then iteratively update along the gradient direction of the loss function until the loss value is stable and the optimal adversarial example is output; The iterative attack method in step S201 is: in, is the initial sample, For the original sample, For passing t After +1 iteration, we can deceive the model A sample of For passing t The samples obtained after iterations are is the number of iterations, For small step length, is the gradient of the loss function, Input the sample after adding seabed reverberation into the recognition model The output obtained after For the seabed reverberation, is the sample label; The objective function in step S202 is: in, is the sample label, Number of avatar models , is the ensemble model obtained by weighted summation, and , is the short-time Fourier transform window function, for Any of the avatar models, is the initial sample, For the seabed reverberation, To counteract the disturbance, is a constant.

2. The method for generating highly robust adversarial samples for underwater acoustic intelligent camouflage according to claim 1 is characterized in that: The step S1 specifically includes: Step S101, referring to the idea of ​​"matching field" in ocean acoustics, the sea area to be measured is gridded, and the environmental noise in each grid is collected in different time periods to construct an initial data set. ; Step S102: Combine the preset known ocean big data to model the distribution rate of the data set of the sea area to be tested, set the underwater random noise ξ to obey the model distribution, and consider the random noise interference of the environment of the unfamiliar underwater scene. , get the first increased data set ; Step S104, considering the simulation amount with different Doppler effects caused by the random noise interference caused by the movement of the ship , expand the simulation amount to the first adversarial sample data set to obtain the second enhanced data set .

3. The method for generating highly robust adversarial samples for underwater acoustic intelligent camouflage according to claim 2 is characterized in that: The step S102 is specifically as follows: When considering the random noise interference of the underwater unfamiliar scene, it is defined as a random quantity , From 0 to maximum value A random quantity that obeys uniform distribution between the two, introducing the underwater random noise ξ and the environmental random noise interference into the data set , get the first increased data set .

4. The method for generating highly robust adversarial samples for underwater acoustic intelligent camouflage according to claim 3 is characterized in that: The standard cross entropy loss function in step S201 is: in, Machine learning recognition model for the enemy, For adversarial samples, For the original sample The model classification label, For any one of the training samples, For the A stand-in model, is the output label of each avatar model.

5. A generation system used in the method for generating highly robust adversarial samples for underwater intelligent camouflage according to claim 1, characterized in that: include: Constructing a dataset module for designing a disturbance enhancement method based on training data expansion to improve the noise immunity against disturbances, thereby expanding the training dataset to obtain a second enhanced dataset; The optimal adversarial sample generation module is used to treat the enemy's recognition model as an unknown black box, perform a black box attack on it based on the second enhanced data set, and use an iterative ensemble learning method to train the substitute model to obtain the optimal adversarial sample.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.

7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Defense method and defense device for black box attack model of speech recognition system

    CN110992934A

  • Systems and methods for fast training of more robust models against adversarial attacks

    US20200410228A1