A method for generating camouflage defense data based on inverse attention domination
Through the deep learning method of inverse attention-dominated, the transferability and semantic intelligibility of existing camouflage defense data generation technology are solved. The generated camouflage defense data can effectively bypass the reconnaissance of deep learning models, protect the equipment security and conform to human visual perception.
Patent Information
- Application Number
- CN202211175491.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-26
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-09-26
AI Technical Summary
The existing physical camouflage defense data generation technology has shortcomings in terms of migration and human semantic intelligibility, resulting in poor defense effects and easy to be recognized by human eyes.
Deep learning method based on inverse attention domination is adopted to generate camouflage defense data with strong migration and human semantic understanding by constructing inverse attention area dispersion loss, defense target loss, local perturbation optimization loss, and pixel smoothing loss.
The generated camouflage defense data can effectively bypass the reconnaissance of deep learning models, protect the security of cluster equipment, and conform to human visual perception, with good migration and defense effects.
Smart Images

Figure CN115496985B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the fields of deep learning algorithms and physical camouflage defense in artificial intelligence, and particularly relates to a method for generating deep learning physical camouflage defense data based on inverse attention domination. Background Art
[0002] Deep learning aims to construct an advanced form of pattern classification by using artificial neural networks. Modern machine learning models represented by deep neural networks have continuously made new breakthroughs in various complex tasks and have reached or exceeded the human cognitive level in many applications. Well-known applications of deep learning include image classification, autonomous driving, speech recognition, games, and so on. Although deep learning has shown excellent performance in well-defined tasks, there are still many problems in terms of reliability and quality. For example, they are also vulnerable to adversarial attacks. Adversarial attack techniques usually design some carefully crafted perturbations that are imperceptible to humans but can easily cause deep learning to make incorrect predictions, thus achieving a deception effect.
[0003] Although the existence of adversarial attacks threatens the application performance of deep learning models, studying adversarial attack techniques still has value. It can be used in physical scenarios to provide effective defense solutions for target recognition algorithms such as unmanned aerial vehicles and precision guidance, achieve camouflage defense, and ensure the security of local cluster devices.
[0004] Based on the above facts, a large number of scholars have conducted research on physical camouflage defense data generation techniques. Generally speaking, camouflage defense is achieved by modifying the visual features of real objects in the physical world, but complex physical constraints and conditions (such as lighting, distance, cameras, etc.) will generate interference and thus reduce the effectiveness of defense. Although existing work has conducted preliminary research on physical camouflage defense, it has always ignored the constraints of model-agnosticism and semantic comprehensibility, resulting in the failure of camouflage defense data to achieve good defense effects. Specifically, the limitations of existing work can be summarized as follows: (1) The transferability of camouflage defense data is very poor, which limits their ability to respond among different models in the physical world; (2) The defense data generated by existing methods have suspicious appearances and are inconsistent with human perception, which is likely to attract human attention.
[0005] In view of the above problems, an intuitive approach is to select a strategy with high generalization to extract features from a deep learning model, so that the generated data has good transferability between different models, and to make it conform to human semantic understanding through a set of preset perturbation shapes. In a physical scenario, the camouflage defense data generation technology can protect local cluster devices to cleverly avoid the detection of deep recognition models. In view of this, the present invention proposes a deep learning physical camouflage defense data generation method and device based on inverse attention domination, aiming to generate physical camouflage defense data with strong transferability and human semantic understanding in a short time, and ensure the security of cluster device deployment. Summary of the Invention
[0006] In order to overcome problems such as model agnosticism and semantic comprehensibility in the current research field, the present invention provides a deep learning physical camouflage defense data generation method based on inverse attention domination.
[0007] The technical solution adopted by the present invention to solve its technical problems is: in the first aspect of the embodiments of the present invention, a camouflage defense data generation method based on inverse attention domination is provided, and the method includes the following steps:
[0008] S1. Select an original image data set and its corresponding deep learning model;
[0009] S2. Preprocess the original image data set and train the deep learning model;
[0010] S3. Construct an attention mechanism to obtain an attention map, perform a discretization operation on the attention map to disperse the inverse attention area, and obtain an inverse attention area dispersion loss L d ;
[0011] S4. Construct a defense target loss L by setting a target area suppression loss, a confidence score suppression loss, and a target class loss function n ;
[0012] S5. Construct a local perturbation optimization loss L e and a pixel smoothing loss L s , and the formulas are as follows:
[0013]
[0014] where β·E + 1 is a weight tensor, 1 is a tensor, T def is a defense texture tensor, and T0 is a seed pixel patch;
[0015]
[0016] where is the pixel value of the input data I to be defended at the coordinate (i, j); def at the coordinate (i, j).
[0017] S6. Based on the inverse attention region dispersion loss L d , the defense target loss L n , the local perturbation optimization loss L e and the pixel smoothing loss L s Modify the input data of the deep learning model to generate camouflage defense data.
[0018] The second aspect of the embodiments of the present invention provides an electronic device, including a memory and a processor, the memory is coupled to the processor; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the above-mentioned method for generating camouflage defense data based on inverse attention domination.
[0019] The third aspect of the embodiments of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method for generating camouflage defense data based on inverse attention domination as described above.
[0020] The beneficial effects of the present invention are mainly manifested in: solving the problems of non-transferability of perturbations and easy detection by the human eye in existing physical camouflage defense technologies, and proposing a method and device for generating deep learning physical camouflage defense data based on inverse attention domination. The method of the present invention has good transferability and human semantic understandability, and can effectively generate camouflage defense images to ensure that local cluster devices can bypass deep learning model reconnaissance and recognition. Description of the Drawings
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0022] Figure 1 It is a block diagram of the method for generating deep learning physical camouflage defense data based on inverse attention domination in the embodiments of the present invention.
[0023] Figure 2 It is a schematic structural diagram of the device for generating deep learning physical camouflage defense data based on inverse attention domination provided in the embodiments of the present invention. Detailed Embodiments
[0024] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0025] The terms used in the present invention are for the purpose of describing particular embodiments only and are not intended to limit the present invention. The singular forms "a", "the", and "said" used in the present invention and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0026] It should be understood that although the terms first, second, third, etc. may be used in the present invention to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0027] The present invention will be described in detail below with reference to the accompanying drawings. Without conflict, the features in the following embodiments and implementation manners can be combined with each other.
[0028] In a first aspect, an embodiment of the present invention provides a deep learning physical camouflage defense data generation method based on inverse attention domination. Please refer to Figure 1 , including the following steps:
[0029] S1. Obtain the original image dataset and its corresponding deep learning model architecture, specifically including:
[0030] S11. Collect the MS COCO, Pascal VOC, or ImageNet datasets commonly used for image classification and save them as the original image dataset X, the true label set Y, and the bounding box information B corresponding to each image;
[0031] S12. Select a deep learning model, and for each original image dataset, its corresponding deep learning needs to be selected. Exemplarily, for the MS COCO dataset, the Faster R-CNN deep learning model architecture is used, for the Pascal VOC dataset, the YOLOv3 deep learning model architecture is used, and for the YOLOv5 dataset, the YOLOv5 deep learning model architecture is used.
[0032] S2, the deep learning model constructed in training step S1 Specifically, it includes:
[0033] S21. Divide the original image dataset into a training set and a test set according to a preset ratio, and convert the label of each sample in the original image dataset into a one-dimensional vector through one-hot encoding. Its format, such as [0,0,1,0,0,0], indicates that the label of the sample is the 3rd out of 6 categories.
[0034] S22. Input the training set divided in step S21 into the deep learning model selected in step S12, and perform training by adopting the training method of mini-batch gradient descent (the batch size is set to 32) to update the model weights θ by minimizing the triplet loss. Input the test set into the trained deep learning model to calculate its average precision until the average precision (mAP) of the deep learning model reaches more than 90% and the training is completed. Among them, the triplet loss function is:
[0035]
[0036]
[0037]
[0038] loss = l box + l cls + l obj
[0039] Among them, S represents the grid size; B represents the bounding box information; x, y, w, h represent the length, width, position width, and position height of the true bounding box in the image; represents the length, width, position width, and position height of the model-predicted bounding box; classes represents the total number of categories; p(·) represents the probability function; c i represents the true confidence score after one-hot encoding; represents the confidence score predicted by the deep learning model; indicates that there is an object in B at i, j, and its value is 1, otherwise it is 0; indicates that there is no object in B at i, j, and its value is 1, otherwise it is 0; λ coord , λ class , λ nobj , λ obj represents the balance parameter, and its value range is [0,1], and λ coord + λ class + λ nobj + λ obj = 1.
[0040] S3. Construct the inverse attention mechanism loss, specifically including:
[0041] In physical space, given a well-trained deep neural network (M, T) represents the mesh tensor M and texture tensor T of a three-dimensional object, and carries the true label y. The input image I of the deep neural network is the rendering of the real object (M, T) by the renderer R under environmental conditions d ∈ D (e.g., camera view, distance, illumination, etc.), which can be expressed as I = R((M, T), d). To generate physical camouflage defense data, usually by generating defense texture tensors T with different physical properties (e.g., color, shape) def to replace the original tensor T, and the camouflage defense object satisfies I def = R((M, T def ), d). Therefore, the definition of the physical camouflage defense data generation problem can be described as:
[0042]
[0043] where ε represents the distance constraint that the distance between texture tensors needs to satisfy, and · represents taking the 2-norm distance.
[0044] S31. Construct the attention mechanism, the specific operations include:
[0045] Input the test set into the deep learning model trained in step S2 to obtain the attention mechanism module A.
[0046] To make the generated camouflage defense data have stronger transferability and satisfy human semantic comprehensibility, the model attention mechanism is introduced. Specifically, given an object (M, T), a camouflage defense texture tensor T to be optimized def , and a specific true label y, obtain the input data I to be defended through y def , and then use the attention mechanism module A to calculate the attention map S y , as follows:
[0047] S y = A(I def , y)
[0048] where the attention mechanism module A can be expressed as:
[0049]
[0050] where is the gradient weight of the true label y, k is the activation feature map, p y is the confidence score of the true label y, is the pixel value at position (i, j) in the k-th activated feature map, and relu(·) represents the activation function. In addition, the attention mechanism module can be any model, not a specific target model.
[0051] S32. Dispersed inverse attention region, and the specific operations include:
[0052] Secondly, disperse the attention region and force the attention mechanism module to focus on the non-target region. Intuitively, the higher the heat value of the pixel value indicates the degree of contribution of the region to the prediction of the attention mechanism module. To reduce the attention weight of the significant object and disperse these attention regions, a discretization operation is introduced for the attention map, and a connected graph is obtained after discretization. This connected graph contains a path that lies between any pair of nodes in the graph. In the image, the region where the attention weight of each pixel is higher than a specific threshold can be regarded as a connected region. To utilize the connected graph to disperse the attention of the model, it includes: reducing the overall connectivity by dividing the connected graph into multiple subgraphs; reducing the weight of each node in the connected subgraph. To achieve these goals, the inverse attention region dispersion loss L d is defined as:
[0053]
[0054] where K is the total number of connected graphs, G k is the sum of the pixel values in the region corresponding to the k-th connected graph in S y , N is the total number of pixels in S y , and N k is the total number of pixels in G k . By minimizing L d , the significant region in the attention region becomes smaller (i.e., dispersed), and the pixel values of the significant region become lower (i.e., no longer "heated"), resulting in the "dispersion" of the attention map.
[0055] S4. Construct the defense target loss L n , which specifically includes:
[0056] Input the test set into the deep learning model trained in step S2 to obtain the intersection over union (IoU) of the predicted and true bounding boxes, the confidence score of the object, and the confidence of the output of the target object class.
[0057] To make the enemy deep learning model misidentify or fail to identify the detection, first, it is necessary to reduce the intersection over union (IoU) of the predicted and true bounding boxes to suppress the region of the target prediction. Then, the target region suppression loss is defined as: Then, by minimizing the object confidence, the confidence score indicating whether the prediction contains an object is reduced, and this loss is expressed as the confidence score suppression loss: Finally, in order to camouflage defense, the deep learning model needs to have a certain classification and recognition ability to ensure concealment. Select the target object class t that needs to be concealed, denoted as c t , and maximize its prediction and output confidence of the target object class, then the target class loss can be expressed as: Therefore, based on the three losses mentioned above, the defense target loss L n It can be defined as:
[0058]
[0059] Among them, λ α ,λ β ,λ γ is a balance parameter whose range is [0,1], and λ α +λ β +λ γ =1.
[0060] S5. Local optimization of defense disturbance, including:
[0061] The perturbation of the physical scene needs to satisfy the physical meaning at all angles, which requires the perturbation to be restricted. An initial perturbation image preset P0 is introduced. The patch contains a strong semantic association with the scene context to ensure that the image is more consistent with the actual physical scene and reduce the rendering violation, thereby bypassing the human eye inspection. Then, the seed pixel patch is drawn on the object (M, T) through T0 = ψ(P0, T). Among them, ψ(·) is an operation transformer, which first converts the perturbation preset pixel content into a three-dimensional tensor, and then draws the texture of the target physics through tensor addition rendering. After filling the pixels, the original perturbation preset forms a mask E. Local perturbation optimization loss L e Can be defined as:
[0062]
[0063] Among them, β·E+1 is the weight tensor, 1 is the tensor; each element in the weight tensor is 1, and its size is the same as the identity matrix E, and it is multiplied according to element-wise multiplication ⊙.
[0064] In order to ensure the naturalness of the generated camouflage defense image, a smoothness loss is introduced to reduce the inconsistency between adjacent pixels. The pixel smoothness loss L s The calculation can be written as:
[0065]
[0066] in is the input data to be defended I def The pixel value at coordinate (i, j).
[0067] S6. Based on the inverse attention region dispersion loss L d Defense target loss L n Local perturbation optimization loss
[0068] L e And pixel smoothing loss L s Modify the input data of the deep learning model to generate camouflage defense data. Specifically, it includes:
[0069] By jointly optimizing the attention dispersion loss L of the deep learning model d Defense target loss L n Local perturbation optimization loss L e And pixel smoothing loss L s To generate camouflage defense data. Specifically, the formal definition is:
[0070] minL d +L n +ηL e +L s
[0071] Among them, η balances the proportion of the local perturbation optimization loss L e The default value is 10 -5 .
[0072] Adopt gradient descent to optimize the above loss function. Specifically, it is defined as:
[0073]
[0074] I def = I + ε·ΔI
[0075] Among them, ε(ε∈(0,0.1)) balances the proportion of the pixels after optimization by the loss function and the original pixels. By optimizing the above objective, the original data I is finally used to generate the camouflage defense data I def For defending the reconnaissance and recognition of the deep learning model.
[0076] In the second aspect, the embodiment of the present invention provides a deep learning physical camouflage defense data generation system based on inverse attention domination, which is used to implement the above-mentioned camouflage defense data generation method based on inverse attention domination. Please refer to Figure 2 The system includes:
[0077] A collection module, which is used to select the original image dataset and its corresponding deep learning model.
[0078] A pre-training module, which is used to process the obtained original image dataset and then pre-train the deep learning model;
[0079] Inverse attention mechanism loss construction module, by constructing the attention mechanism of the deep learning model, extracting the attention map, performing discretization operation on the attention map to obtain a connected graph, so as to disperse the inverse attention area, and introducing the connected graph to calculate the inverse attention area dispersion loss.
[0080] Defense target loss construction module, by suppressing the intersection of the model prediction and the true bounding box, minimizing the object confidence, and maximizing the target class confidence to construct the defense target loss, making the enemy deep learning model misidentify the detection or fail to identify the detection.
[0081] Defense perturbation local optimization module, by performing pixel update on the preset patch containing strong semantic relevance of the scene context, making it meet the perturbation requirements of the physical scene, which need to have physical meaning in all angles.
[0082] Camouflage defense data generation module, by jointly optimizing the inverse attention mechanism loss construction module, the defense target loss construction module, and the local perturbation optimization loss module to generate camouflage defense image data.
[0083] Example 1: Trained the Faster R-CNN training model on the MS COCO dataset. The training parameters are: SGD optimizer, learning rate lr = 0.0001, momentum = 0.9, batch size = 64, epoch = 8. The mean average precision (mAP) on 10,000 samples in the test set is 92.20%. Using the deep learning physical camouflage defense data dominated by inverse attention, the average precision (mAP) of the enemy model recognition can be reduced to 27.80%, skillfully avoiding the reconnaissance of the deep learning model, thus effectively protecting the security of the cluster devices, and obeying the top-down observation characteristics under the observation of human eyes.
[0084] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0085] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, as well as the combination of flows and / or blocks in the flowchart and / or block diagram. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or in multiple blocks.
[0086] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or in multiple blocks.
[0087] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or in multiple blocks.
[0088] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the content disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary.
[0089] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A method for generating camouflage defense data based on inverse attention domination, characterized in that The method includes the following steps: S1. Select the original image dataset and its corresponding deep learning model; S2. Preprocess the original image dataset and train the deep learning model; S3. Construct an attention mechanism to obtain an attention map, and perform a discretization operation on the attention map to disperse the inverse attention region, thereby obtaining an inverse attention region dispersion loss L d ; The process of the attention mechanism in step S3 includes: inputting the test set into the deep learning model trained in step S2 to obtain the attention mechanism module A, expressed as: Among them, is the gradient weight of the true label y, k is the activation feature map, p y is the confidence score of the true label y, is the pixel value at the position (i, j) in the k-th activation feature map, and relu(·) represents the activation function; Step S3 includes: For an object (M, T), a camouflage defense texture tensor T to be optimized def , and a true label y, obtain I from the true label y def , and then use the attention mechanism module A to calculate the attention map S y , as follows: S y = A(I def , y) Inverse attention region dispersion loss L d The formula is defined as follows: where K is the total number of connected graphs, and G k is the sum of the pixel values in the region corresponding to the k-th connected graph in S y , N is the total number of pixels in S y , and N k is the total number of pixels in G k ; S4. Construct the defense target loss L by setting the target region suppression loss, confidence score suppression loss, and target class loss function n ; S5. Construct the local perturbation optimization loss L e and the pixel smoothing loss L s , and the formula is as follows: Among them, β·E + 1 is the weight tensor, 1 is the tensor, T def is the defense texture tensor, T0 is the seed pixel patch, and ⊙ represents the Hadamard product; Among them, is the input data I to be defended def is the pixel value at the coordinate (i, j); S6. Based on the inverse attention region dispersion loss L d , the defense target loss L n , the local perturbation optimization loss L e and the pixel smoothing loss L s Modify the input data of the deep learning model to generate camouflage defense data, which is used to ensure the security of local cluster devices.
2. The method for generating camouflage defense data based on inverse attention domination according to claim 1, wherein In step S1, the original image dataset includes the MS COCO dataset, Pascal VOC dataset or ImageNet dataset; the original image dataset and its corresponding deep learning model are specifically: for each original image dataset, its corresponding deep learning needs to be selected. Among them, the Faster R-CNN deep learning model is used for the MS COCO dataset, the YOLOv3 deep learning model is used for the Pascal VOC dataset, and the YOLOv5 deep learning model is used for the YOLOv5 dataset.
3. The method for generating camouflage defense data based on inverse attention domination according to claim 1, wherein, The preprocessing of the original image dataset in step S2 includes: dividing the original image dataset into a training set and a test set according to a preset ratio, and converting the label of each sample in the original image dataset into a one-dimensional vector format through one-hot encoding; Training the deep learning model includes: training the deep learning model using the mini-batch gradient descent training method to update the weights θ of the deep learning model by minimizing the triplet loss until the average accuracy of the deep learning model reaches a preset accuracy threshold, completing the training of the deep learning model.
4. The method for generating camouflage defense data based on inverse attention domination according to claim 1, wherein, Step S4 is specifically: The formula for the target region suppression loss is as follows: Among them, S represents the grid size; B represents the bounding box information; x, y, w, h represent the length, width, position width, and position height of the true bounding box in the image; represent the length, width, position width, and position height of the bounding box predicted by the model; The formula for the confidence score suppression loss is as follows: Among them, c i represents the true confidence score after one-hot encoding; represents the confidence score predicted by the deep learning model; The formula for the target class loss is as follows: Based on the above three losses, the defense target loss L n is defined as: Among them, λ α , λ β , λ γ is a balance parameter.
5. The method for generating camouflage defense data based on inverse attention domination according to claim 4, characterized in that, Balance parameter λ α , λ β , λ γ The value range of λ is [0, 1], and λ α + λ β + λ γ = 1.
6. The method for generating camouflage defense data based on inverse attention domination according to claim 1, wherein Step S6 is specifically: By jointly optimizing the attention dispersion loss L of the deep learning model d , the defense target loss L n , the local perturbation optimization loss L e and the pixel smoothing loss L s to generate camouflage defense data, the optimization objective is defined as: minL d +L n +ηL e +L s Among them, η is used to balance the proportion of the local perturbation optimization loss L e ; Using gradient descent to optimize the above loss function, the formula is as follows: I def = I + ε·ΔI Among them, ε is used to balance the proportion of pixels after optimization by the loss function and the original pixels. By optimizing the above objective, the camouflage defense data I is finally generated from the original data I def .
7. An electronic device, comprising a memory and a processor, characterized in that, The memory is coupled to the processor; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the method for generating camouflage defense data based on inverse attention domination according to any one of claims 1-6 above.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method for generating camouflage defense data based on inverse attention domination according to any one of claims 1-6.
Citation Information
Patent Citations
Deep learning sample level adversarial attack defense method and device based on neuron activation mode
CN113297572A
Sparse attention neural networks
EP4040339A1