A Heuristic Adversarial Sample Defense Method Based on Siamese Network and Integrated Enhanced Decision Making

A dual-network system with a generator network and voting mechanism addresses the inefficiencies of existing adversarial defense methods, providing robust and efficient defense against adversarial samples in computer vision.

CN115187784BActive Publication Date: 2025-07-15NORTHWESTERN POLYTECHNICAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210577326.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-25
Publication Date
2025-07-15
Estimated Expiration
2042-05-25

AI Technical Summary

Technical Problem

The existing anti-sample defense method has a complex training process and the large neural network used is a huge size, resulting in long training time, high debugging cost, and limited performance improvement space, making it difficult to effectively defend against misjudgment of anti-samples in the field of computer vision.

Method used

The heuristic defense method of twin networks and integrated enhanced decision-making is adopted to denoise samples by generating adversarial networks, and the anti-noise denoiser is generated by combining multi-intensity adversarial sample sets. The twin networks and voting decisions are used for classification, and the twin networks F1 and F2 are constructed, and the parallel design does not increase inference time.

Benefits of technology

While retaining the ability to judge natural samples, it can effectively identify adversarial samples, have real-time classification capabilities, and has small network models, reducing storage space and inference time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115187784B_ABST
    Figure CN115187784B_ABST
Patent Text Reader

Abstract

The present invention discloses a heuristic adversarial sample defense method based on a twin network and integrated enhanced decision-making, comprising the following steps: training a network with clean samples to obtain an original network; generating adversarial samples with different attack intensities based on the original network and clean samples using multiple sets of parameters; performing adversarial training based on the adversarial samples and the original network to obtain an enhanced network; merging the original network and the enhanced network to construct a twin network; using a generative adversarial network to perform input denoising on the input samples, and randomly adding noise to destroy the possible adversarial noise to a certain extent; sending the data-augmented sample set into the twin network for analysis to obtain a batch of classification data; performing voting-based integrated enhanced decision-making on this batch of classification data to obtain a final classification result. This design does not need to detect the input samples. Whether they are clean samples or adversarial samples, the system can make correct classification results for them, thereby achieving the purpose of defending against adversarial samples.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer vision security, and particularly to a heuristic adversarial sample defense method based on a siamese network and integrated enhanced decision-making. Background Art

[0002] An adversarial sample refers to a batch of artificial samples generated by artificially modifying natural samples pre-input into a neural network in the field of computer vision. Without affecting the human visual discrimination ability (such as image classification, object detection and recognition capabilities), these samples have the ability to induce the neural network to output incorrect judgment results (such as classification errors, localization errors, etc.).

[0003] Adversarial sample defense refers to optimizing the neural network so that while retaining the judgment ability for natural samples as much as possible, it has the ability to correctly judge adversarial samples.

[0004] The existence of adversarial samples poses a huge security risk to the future application and deployment of artificial intelligence devices. The misjudgment of artificial intelligence devices may pose a certain threat to the user experience and even life safety. Due to the above problems in the field of computer vision, and the complex training process of existing adversarial sample defense methods and the large volume of neural networks used, the entire defense system has defects such as long training time, high debugging cost, and large space required to save network parameters, and there is great room for performance improvement. Therefore, the adversarial sample defense method still has great research value. Summary of the Invention

[0005] To solve the above technical problems, the present invention provides a heuristic adversarial sample defense method based on a siamese network and integrated enhanced decision-making. This method can retain the judgment ability for natural samples while having the ability to correctly judge adversarial samples, and at the same time has the advantage of a small network model. The design of two parallel sub-networks will not increase the additional inference time and can ensure the real-time performance of classification. The main innovation of the present invention lies in using a generative adversarial network specially trained with a multi-intensity adversarial sample set as an adversarial noise denoiser, and subsequent classifier systems combining sample amplification, siamese network and voting-based decision-making.

[0006] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0007] Step 1. Construct a siamese network:

[0008] Step 101: Use a clean training set with pre-labeled correct classification results In the label data Under the supervision of, the ResNet18 network is trained to have the basic ability to classify clean samples, and this network model and parameters are saved, which is the original network F1. Where c is the number of layers of the input image, h is the height of the input image, w is the width of the input image, h×w is the number of pixels of the input image, and m is the number of categories of the classification problem;

[0009] Step 102: On the basis of the original network F1 obtained in Step 101, for the clean training sample set Use the PGD algorithm to generate an adversarial sample set The adversarial sample set X1 should be a multi-intensity adversarial sample set, that is, it contains adversarial samples with multiple attack intensities generated using different noise intensities ε, iterative noise α, and the number of iterations iter, which can induce the original network F1 to make incorrect classification results. Use the multi-intensity adversarial sample set X1 to fine-tune the original network F1 (using a smaller learning rate than in the training process of Step 101) to obtain the enhanced network F2. F2 will obtain the defense ability against multi-intensity adversarial samples, that is, it can correctly classify multi-intensity adversarial samples and also has the classification ability for clean samples (which will be weakened to a certain extent compared with the original network F1);

[0010] Step 103: Connect the original network F1 and the enhanced network F2 in parallel to obtain a twin network. The stronger classification ability of the original network F1 for clean samples will be used as compensation to make up for the decline in the classification ability of the enhanced network F2 for clean samples.

[0011] Step Two: Train a generative adversarial network and use the generator to denoise samples:

[0012] Step 201: The generator network model G includes: Conv1, Conv2_x, Conv3_x, Conv4_x, Conv5_x, Conv1_d, Conv2_d. Use Conv1, which contains two 3×3 convolutional layers, to perform shallow feature extraction on the input sample to obtain a feature map For the shallow features First, use the main connection of the residual block Conv2_x to further extract deep features Then use the residual connection of the residual block Conv2_x to obtain feature sampling After merging, obtain the mixed features output by the residual block Conv2_x The subsequent residual block operations are the same. Connect two transposed convolutional layers Conv1_d, Conv2_d to compress the number of feature layers c5 of the feature map back to c to obtain the output And use the residual connection to connect the original input image to the output, and finally obtain At this time, the task of the entire main connection is to learn to output a compensated picture After the compensated image and the input image are added together, the noise signal in the input image can be offset, achieving the purpose of denoising the input. The discriminator network D uses residual blocks to extract the features of the input image and needs to learn a binary classification problem, that is, if the input image comes from the sample after denoising by the generator, it outputs 0, and if the input image is the original clean sample, it outputs 1;

[0013] Step 202: During training, first obtain a clean sample Generate an adversarial sample for this clean sample X1 first goes through the generator for denoising, and after denoising, it is denoted as The output of x passing through the discriminator is y, and the output of Gz input to the discriminator is y1;

[0014] Step 203: For the generator, first, it is expected that the output Gz of the generator is sufficient to deceive the discriminator, making the discriminator think that Gz is a clean sample rather than a denoised sample. Therefore, use the generator loss function 1 to update the generator. The smaller this loss function is, the closer the output of Gz after passing through the discriminator is to 1, indicating that Gz is closer to the clean sample. Generator loss function formula: loss G1 =-ln y1. Secondly, it is expected that the output Gz of the generator is not much different from the input sample. Therefore, use the improved peak signal-to-noise ratio as the generator loss function 2 to update the generator. Generator loss function 2 formula:

[0015] Step 204: For the discriminator, it is expected that the discriminator has the ability to distinguish, that is, to distinguish whether the input image is the real clean sample x or the sample Gz after denoising by the discriminator. Therefore, use the discriminator loss function to update the discriminator. The decrease of this loss function represents that the output of x passing through the discriminator is closer to 1, and the output of Gz passing through the discriminator is closer to 0. Discriminator loss function formula: loss D =-[logy + log(1 - y1)];

[0016] Step 3: Denoise and randomly add noise to the input image to obtain an augmented sample set:

[0017] Step 301: Normalize the pixels of the input sample by dividing the 8-bit unsigned integer pixel value by 255, so that the value range of the pixel value is between 0 and 1, and uniformly adjust the input sample to facilitate feature extraction by the neural network;

[0018] Step 302: Use the generator trained in Step 2 to perform sample denoising in an end-to-end manner, that is, the input is image data and the output is also image data. The input image is processed by the generator network to remove the possible adversarial noise to a certain extent;

[0019] Step 303: Add random noise to the denoised image processed by the generator network: Considering that adversarial examples are just special cases of clean samples after being artificially perturbed, and there is a certain probability that the generator network can eliminate the aggressiveness of adversarial examples during denoising. By adding random noise, the denoised samples are mapped to other random positions in the sample space. These augmented samples with added random noise will, with high probability, lose their original aggressiveness. Considering that the input samples and the denoised samples still have their value, the input samples, the denoised samples, and the samples with added random noise are all packaged as the augmented sample set of the input samples for subsequent processing.

[0020] Step Four: Integrated enhanced decision-making:

[0021] Step 401: For a certain sample in the augmented sample set: The sub-networks F1 and F2 of the Siamese network will independently make a judgment on this sample and respectively output a classification vector (There are m optional categories, so the vector length is m, and each element value represents the score of this category. If the value of the k-th element is the largest, then the k-th category has the highest score, indicating that this sample image is classified as the k-th category). Each element value of the classification vector y is respectively normalized So that the score values are under the same scale constraint. After processing, the element values of the classification vector will be uniformly between 0 and 1. The final classification vector is: Considering that most samples in the augmented sample set lose their adversarial nature after data denoising and random noise addition and are no longer adversarial examples, the classification vector y1 of the original network F1 is more credible, so its weight is slightly larger. If the value of the k-th element in the final classification vector y is the largest, then this sample is considered to be the k-th category;

[0022] Step 402: Obtain the classification results of each sample in the augmented sample set of the input samples. If there are n samples in the augmented sample set, then n classification results will be obtained, and the most frequent one among the classification results is taken as the final classification result of the input sample.

[0023] The beneficial effects of the present invention are as follows:

[0024] 1. Using a generative adversarial network for denoising adversarial examples, the datasets for training the generative adversarial network are the adversarial sample set and the clean sample set. The adversarial sample set is a multi-scale adversarial sample set generated using the strongest first-order attack. Therefore, the generator network will, to a certain extent, have the function of eliminating multi-scale adversarial noise.

[0025] 2. By randomly adding noise to the input samples to augment the sample set and making a voting-style decision on the classification results, whether the input sample is an adversarial example or not, the correct classification result of the input sample can be obtained with a high probability, thus having a defensive effect on adversarial examples. Brief Description of the Drawings

[0026] Figure 1 It is a schematic diagram of the defense system of the present invention;

[0027] Figure 2 It is a classification flowchart;

[0028] Figure 3 It is a sub-network structure table of the Siamese network;

[0029] Figure 4 It is a sub-network residual block structure table; Detailed Description of the Invention

[0030] The method of the present invention will be further described in detail below in conjunction with the accompanying drawings and the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0031] Figure 1 It represents a schematic diagram of a heuristic adversarial sample defense system based on a Siamese network and integrated enhanced decision-making. In the Figure 1 system, according to the Figure 2 process, the classification process of the input sample is completed.

[0032] As Figure 2 shown, the specific steps are as follows:

[0033] S1: Denoise and amplify the samples of the entire data set: Stretch the data set size to 224×224, use a generative adversarial network for data denoising, and then add multiple groups of random noise to the samples. Pack the input samples, denoised samples, and several samples after adding random noise as the augmented sample set of the input samples and send them into the Siamese network;

[0034] S2: Construct a Siamese network: Use the clean sample training set to train a convolutional neural network F1 with basic image classification functions. The sample set X generates a multi-scale adversarial sample set on the network F1 Use the sample set X1 to perform fine-tuning adversarial training on the network F1 to obtain the enhanced network F2. Connect the original network F1 and the enhanced network F2 in parallel to obtain a Siamese network, and use the high recognition rate of the original network F1 for clean samples to inspire the overall classification result;

[0035] S3: Integrated Enhanced Decision-making: The input sample set obtained in S1 is fed into the Siamese network. Each sample in the sample set will obtain two sets of parallel outputs generated by the sub-networks F1 and F2. These two sets of parallel outputs are integrated to obtain the classification result of this sample. Thereafter, the classification results of all samples in the augmented sample set are obtained, and enhanced decision-making is performed on these classification results to obtain the final classification result of the input samples.

[0036] The above-mentioned S1 includes the following steps:

[0037] S11: Normalize the input sample pixels. Divide the 8-bit unsigned integer pixel value by 255 so that the pixel value range is between 0 and 1. And uniformly adjust the size of the input sample to facilitate the neural network to extract features;

[0038] S12: The generator of the generative adversarial network adopts an end-to-end approach, that is, the input is image data and the output is also image data. The input image is processed by the generator network to remove the artificially added noise that may exist to a certain extent;

[0039] S13: Add random noise to the denoised image processed by the generator network:

[0040]

[0041] Considering that adversarial samples are just some special cases of clean samples after being artificially added with perturbations, and the denoising of the generator network has a certain probability of eliminating the aggressiveness of adversarial samples. By adding random noise, the denoised samples are mapped to other random positions in the sample space. These augmented samples with random noise added will, in all likelihood, lose their original aggressiveness. Considering that the input samples and the denoised samples still have their value, the input samples, denoised samples and the added random noise are collectively packaged as the augmented sample set of the input samples and waiting for subsequent processing.

[0042] The above-mentioned S2 includes the following steps:

[0043] S21: Construct and train the convolutional neural network ResNet18, as Figure 3 shown, including a convolutional block and four residual blocks, namely Conv1, BasicBlock1, BasicBlock2, BasicBlock3, BasicBlock4. The residual block includes two 3×3 convolutional layers. The convolutional block first extracts shallow features from the input image data. Each residual block performs feature fusion on shallow and deep features, analyzes the fused features and passes the new feature map to the next residual block. Finally, the classification result of the image data is obtained through the fully connected neural network;

[0044] S22: Train the ResNet18 network using the clean training set X with pre - labeled correct classification results, enabling it to have the basic ability to classify clean samples. Save this network model and its parameters, which is the original network F1;

[0045] S23: Based on the original network F1 obtained in S22, use the PGD algorithm to generate an adversarial sample set X1 for the clean training sample set X. The adversarial sample set X1 should contain multi - intensity adversarial samples. For example, first use a constraint distance of 0.004 to iterate 20 times in the sample space with an infinity norm of 0.03 from the clean sample to obtain the first batch of adversarial samples, then use a constraint distance of 0.007 to iterate 20 times in the sample space with an infinity norm of 0.06 from the clean sample to obtain the second batch of adversarial samples, and finally use a constraint distance of 0.010 to iterate 20 times in the sample space with an infinity norm of 0.09 from the clean sample to obtain the third batch of adversarial samples. Fine - tune (using a smaller learning rate than in the training process of S22) the original network F1 with the multi - intensity adversarial sample set X1 to obtain the enhanced network F2. F2 will acquire the ability to defend against multi - intensity adversarial samples and also retain the classification ability for clean samples (which will be somewhat weakened compared to the original network F1);

[0046] S24: Connect the original network F1 and the enhanced network F2 in parallel to obtain a twin network. The original network F1, due to its strong classification ability for clean samples, will be somewhat instructive for the final classification result of the network.

[0047] The said S3 includes the following steps:

[0048] S31: Feed the amplified sample set obtained in S1 into the twin network obtained in S2. For a certain sample in the amplified sample set: The sub - networks F1 and F2 of the twin network will independently make a judgment on this sample and respectively output a classification vector y1, y2 (there are c optional classes, so the vector length is c, and each element value represents the score of this class. If the value of the k - th element is the largest, it means this sample picture is classified as the k - th class). Normalize each element value of the classification vector y:

[0049]

[0050] The element values of the processed classification vector will be uniformly between 0 and 1. The final classification vector is:

[0051]

[0052] Considering that most of the samples in the augmented sample set lose their adversarial property after data denoising and random noise addition and are no longer adversarial samples, the classification vector y1 of the original network F1 has a higher credibility, so its weight is increased. If the value of the k-th element in the final classification vector y is the largest, then this sample is considered to be of the k-th class;

[0053] S32: Obtain the classification results of each sample in the augmented sample set. If there are n samples in the augmented sample set, then n classification results will be obtained, and the most frequent one among the classification results is taken as the final classification result. Thus, the input sample has undergone data denoising and random noise addition, the inference analysis of the Siamese network, and the integrated enhancement decision-making of the output classification vector, and its final classification result is obtained.

[0054] The S12 includes the following steps:

[0055] S121: The generator network model G includes: Conv1, Conv2_x, Conv3_x, Conv4_x, Conv5_x, Conv1_d, Conv2_d. Use Conv1, which contains two 3×3 convolutional layers, to perform shallow feature extraction on the input sample to obtain a feature map For the shallow features first use the main connection of the residual block Conv2_x to further extract deep features then use the residual connection of the residual block Conv2_x to obtain feature sampling After merging, the mixed features output by the residual block Conv2_x are obtained The subsequent residual block operations are the same. Connect two transposed convolutional layers Conv1_d and Conv2_d to compress the number of feature layers c5 of the feature map back to c to obtain the output and use the residual connection to connect the original input image to the output. Finally, at this time, the task of the entire main connection is to learn to output a compensated image After adding the compensated image and the input image, the noise signal in the input image can be offset, achieving the purpose of denoising the input;

[0056] S122: The discriminator network D uses the residual block to extract the features of the input image and finally outputs a value between 0 and 1. The discriminator needs to learn: if the input image comes from the sample after denoising by the generator, then output 0; if the input image of the discriminator is a clean sample, then output 1.

[0057] During training, first obtain a clean sample x and generate an adversarial sample x1 for this clean sample. The output of x passing through the discriminator is y. x1 first undergoes denoising by the generator and is denoted as Gz after denoising. Then Gz is input into the discriminator to obtain the output y1.

[0058] S124: For the generator, it is expected that the output Gz of the generator is sufficient to deceive the discriminator into thinking that Gz is a clean sample rather than a denoised sample. Therefore, the generator is updated using the generator loss function 1. The smaller this loss function is, the closer the output of Gz after passing through the discriminator is to 1, indicating that Gz is closer to a clean sample. The loss function formula:

[0059] loss G1 =-ln y1

[0060] Secondly, it is expected that the output Gz of the generator is not much different from the input sample. Therefore, the improved peak signal-to-noise ratio is used as the generator loss function 2 to update the generator. The loss function formula:

[0061]

[0062] S125: For the discriminator, it is expected that the discriminator has the ability to distinguish, that is, to distinguish whether the input image is a real clean sample x or a sample Gz after denoising by the discriminator. Based on this, the discriminator loss function is defined. The decrease of this loss function represents that the output of x passing through the discriminator is closer to 1, and the output of Gz passing through the discriminator is closer to 0. The loss function formula:

[0063] loss D =-[log y + log(1 - y1)].

Claims

1. A heuristic adversarial sample defense method based on a twin network and integrated enhanced decision-making, characterized in that: It includes the following steps: Step 1: Construct a twin network: Step 101: Use a clean training set with pre-annotated correct classification results Under the supervision of the labeled data Train the ResNet18 network so that it has the basic ability to classify clean samples, and save this network model and parameters, which is the original network F1; where c is the number of layers of the input image, h is the height of the input image, w is the width of the input image, h×w is the number of pixels of the input image, and m is the number of categories of the classification problem; Step 102: Based on the original network F1 obtained in Step 101, for the clean training sample set Use the PGD algorithm to generate an adversarial sample set The adversarial sample set X1 should be a multi-intensity adversarial sample set, that is, it contains adversarial samples with multiple attack intensities generated by using different noise intensities ε, iterative noise α, and the number of iterations iter at the same time, and can induce the original network F1 to make incorrect classification results; use the multi-intensity adversarial sample set X1 to fine-tune the original network F1, and its learning rate should be less than that in Step 101 to obtain the enhanced network F2; F2 will obtain the defense ability against multi-strength adversarial samples, that is, it can correctly classify multi-strength adversarial samples and also has the classification ability for clean samples; Step 103: Parallel the original network F1 and the enhanced network F2 to obtain a twin network. The strong classification ability of the original network F1 for clean samples will be used as compensation to make up for the decline in the classification ability of the enhanced network F2 for clean samples; Step 2: Train a generative adversarial network and use the generator for sample denoising: Step 201: The generator network model G includes: Conv1, Conv2_x, Conv3_x, Conv4_x, Conv5_x, Conv1_d, Conv2_d; Use Conv1, which contains two 3×3 convolutional layers, to perform shallow feature extraction on the input sample to obtain a feature map For the shallow features first use the main connection of the residual block Conv2_x to further extract deep features then use the residual connection of the residual block Conv2_x to obtain feature sampling After merging, the mixed features output by the residual block Conv2_x are obtained The subsequent residual block operations are the same; Connect two transposed convolutional layers Conv1_d, Conv2_d to compress the number of feature layers c5 of the feature map back to c to obtain the output and use the residual connection to connect the original input image to the output, and finally obtain At this time, the task of the entire main connection is to learn to output a compensated image After adding the compensated image to the input image, the noise signal in the input image can be cancelled out, achieving the purpose of denoising the input; The discriminator network D uses the residual block to extract the features of the input image and needs to learn a binary classification problem, that is, if the input image comes from the sample after denoising by the generator, it outputs 0, and if the input image is the original clean sample, it outputs 1; Step 202: During training, first obtain a clean sample Generate an adversarial sample for this clean sample X1 first passes through the generator for denoising, and after denoising it is denoted as The output of x passing through the discriminator is y, and the output of Gz input to the discriminator is y1; Step 203: For the generator, it is first expected that the output Gz of the generator is sufficient to confuse the discriminator into thinking that Gz is a clean sample rather than a denoised sample. Therefore, the generator is updated using the generator loss function 1; the smaller this loss function is, the closer the output of Gz after passing through the discriminator is to 1, indicating that Gz is closer to a clean sample; the formula for loss function 1: loss G1 = -ln y1; Secondly, it is expected that the output Gz of the generator does not differ much from the input sample. Therefore, the improved peak signal-to-noise ratio is used as the generator loss function 2 to update the generator; the formula for loss function 2: Step 204: For the discriminator, it is expected that the discriminator has the ability to distinguish, that is, to distinguish whether the input image is a real clean sample x or a sample Gz after denoising by the discriminator. Therefore, the discriminator loss function is used to update the discriminator; the decrease of this loss function means that the output of x passing through the discriminator is closer to 1, and the output of Gz passing through the discriminator is closer to 0; the formula of the discriminator loss function: loss D = -[logy + log(1 - y1)]; Step 3: Denoise and randomly add noise to the input image to obtain an augmented sample set: Step 301: Normalize the input sample pixels by dividing the 8-bit unsigned integer pixel values by 255, so that the pixel value range is between 0 and 1, and uniformly adjust the input samples to facilitate feature extraction by the neural network; Step 302: Use the generator trained in Step 2 for sample denoising in an end-to-end manner, that is, the input is image data and the output is also image data. The input image is processed by the generator network to remove the possible adversarial noise to a certain extent; Step 303: Add random noise to the denoised image processed by the generator network: Map the denoised sample to other random positions in the sample space, and with a certain probability, make the augmented sample lose its original aggressiveness; Pack the input sample, the denoised sample, and the sample with added random noise as the augmented sample set of the input sample. Step 4: Integrate and enhance the decision: Step 401: For a certain sample in the augmented sample set, the sub-networks F1 and F2 of the Siamese network will independently make a judgment on this sample and respectively output a classification vector If there are m optional categories in total, the vector length is m, and each element value represents the score of this category; each element value of the classification vector y is normalized so that the score values are under the same scale constraint; the element values of the processed classification vector will be uniformly between 0 and 1; most samples in the augmented sample set are not adversarial, and the classification vector y1 of the original network F1 has a higher credibility and a slightly larger weight. The final classification vector is: If the k-th element value in the final classification vector y is the largest, then this sample is considered to be the k-th category; Step 402: Obtain the classification results of each sample in the augmented sample set of the input sample. If there are n samples in the augmented sample set, n classification results will be obtained, and take the most frequent one of the classification results as the final classification result of the input sample.

Citation Information

Patent Citations

  • Remote sensing image classification network robustness improvement method based on self-supervised learning

    CN114067177A

  • Self-supervised attribute controllable image generation method based on deep twin network

    CN114494489A