Image generation method, apparatus, device, and storage medium
Patent Information
- Application Number
- CN202211273501.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-18
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2042-10-18
AI Technical Summary
[0010]根据本公开的技术方案,可以提高最终对抗图像的攻击成功率。
Smart Images

Figure CN115619691B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of artificial intelligence technology, specifically to the fields of deep learning, sample generation, and other technical fields, and particularly to an image generation method, apparatus, device, and storage medium. Background Technology
[0002] Adversarial examples are a type of sample used to attack machine learning models. They are obtained by adding perturbation information to real samples. The difference between adversarial examples and real samples is almost indistinguishable to the naked eye. However, when adversarial examples are input into a machine learning model, they cause the model to output incorrect results with high confidence. The existence of adversarial examples threatens the application of machine learning models in security-sensitive fields.
[0003] To improve the robustness of machine learning models, adversarial examples can be constructed and used to train the machine learning model, thereby obtaining a more robust machine learning model. Summary of the Invention
[0004] This disclosure provides an image generation method, apparatus, device, and storage medium.
[0005] According to one aspect of this disclosure, an image generation method is provided, comprising: for each initial adversarial image in at least one initial adversarial image, determining a confidence level that a preset target contained in each initial adversarial image is correctly identified; wherein the at least one initial adversarial image is obtained based on initial perturbation information; based on the confidence level, obtaining at least one group, each group including at least one of the confidence levels; based on the confidence levels included in each group and the weights of each group, constructing a loss function, and adjusting the initial perturbation information based on the loss function to obtain final perturbation information; generating a perturbation image based on the final perturbation information, the perturbation image being used to generate a final adversarial image.
[0006] According to another aspect of this disclosure, an image generation apparatus is provided, comprising: a determining module, configured to determine, for each initial adversarial image in at least one initial adversarial image, a confidence level that a preset target contained in each initial adversarial image is correctly identified; wherein the at least one initial adversarial image is obtained based on initial perturbation information; a grouping module, configured to obtain at least one group based on the confidence level, each group including at least one of the confidence levels; an adjusting module, configured to construct a loss function based on the confidence levels included in each group and the weights of each group, and adjust the initial perturbation information based on the loss function to obtain final perturbation information; and a generating module, configured to generate a perturbation image based on the final perturbation information, the perturbation image being used to generate a final adversarial image.
[0007] According to another aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to said at least one processor; wherein the memory stores instructions executable by said at least one processor, said instructions being executed by said at least one processor to enable said at least one processor to perform the method as described in any of the foregoing aspects.
[0008] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method according to any of the preceding aspects.
[0009] According to another aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method according to any of the preceding aspects.
[0010] According to the technical solution disclosed herein, the success rate of attacks on final adversarial images can be improved.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0012] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0013] Figure 1 This is a schematic diagram based on the first embodiment of the present disclosure;
[0014] Figure 2 This is a schematic diagram illustrating an application scenario provided according to embodiments of this disclosure;
[0015] Figure 3 This is a schematic diagram of the overall training process provided according to the embodiments of this disclosure;
[0016] Figure 4 This is a schematic diagram according to the second embodiment of the present disclosure;
[0017] Figure 5 This is a schematic diagram illustrating the addition of perturbation information to a real image according to an embodiment of this disclosure;
[0018] Figure 6 This is a schematic diagram according to the third embodiment of the present disclosure;
[0019] Figure 7 This is a schematic diagram of an electronic device used to implement the image generation method of the embodiments of this disclosure. Detailed Implementation
[0020] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0021] To improve the robustness of machine learning models, adversarial examples that are easy to attack can be selected.
[0022] A successful adversarial attack means that after the adversarial example is input into a machine learning model, the machine learning model outputs an incorrect result with high confidence, or in other words, the target in the adversarial example is correctly identified with low confidence.
[0023] In related technologies, in order to obtain adversarial samples that are easy to attack successfully, efforts are usually made to target a single adversarial sample and reduce the confidence that the target in the adversarial sample is correctly identified.
[0024] However, simply reducing the confidence level of a single adversarial sample is rather one-sided in its implementation. It cannot obtain a larger number of successfully attacked adversarial samples, or in other words, it cannot improve the overall attack success rate of all adversarial samples. The attack success rate refers to the ratio between the number of successfully attacked adversarial samples and the total number of adversarial samples.
[0025] Since the performance of a machine learning model is related not only to the performance of a single sample but also to the number of high-performing samples—that is, training the model with a larger number of high-performing samples results in a better-performing model—and for adversarial examples, high-performing samples refer to those that are easy to attack successfully. Therefore, it is necessary to obtain a larger number of easy-to-attack adversarial examples, or in other words, to solve the problem of how to improve the success rate of adversarial example attacks.
[0026] Figure 1 Based on a schematic diagram of the first embodiment of this disclosure, this embodiment provides an image generation method, the method comprising:
[0027] 101. For each initial adversarial image in at least one initial adversarial image, determine the confidence level that a preset target contained in each initial adversarial image is correctly identified; wherein, the at least one initial adversarial image is obtained based on initial perturbation information.
[0028] 102. Based on the confidence level, obtain at least one group, wherein each group in the at least one group includes at least one of the confidence levels.
[0029] 103. Based on the confidence levels included in each group and the weights of each group, a loss function is constructed, and the initial perturbation information is adjusted based on the loss function to obtain the final perturbation information.
[0030] 104. Generate a perturbation image based on the final perturbation information, and use the perturbation image to generate the final adversarial image.
[0031] This embodiment can be applied in the field of images, such as image-based target detection scenarios in autonomous driving. In this scenario, the samples are images, and correspondingly, adversarial samples can be called adversarial images.
[0032] Adversarial images can be obtained by adding perturbation information to real images. The initial perturbation information can be called the initial perturbation information, and the final perturbation information obtained after the training process can be called the final perturbation information. The perturbation information can specifically be perturbed pixel values.
[0033] A real image is an image without added perturbation information, while an initial adversarial image is an image obtained by adding perturbation information to a real image.
[0034] A real image can be obtained by using a camera to capture images of the physical environment containing a preset target. For example, if the preset target is a car, a camera can be used to capture images of the physical environment in which the car is located to obtain an image containing the car, which can be used as a real image.
[0035] There can be one or more real images. For multiple real images, multiple real images can be captured sequentially according to the distance of the camera from the preset target (e.g., a car) from near to far.
[0036] After obtaining the real images, perturbation information can be added to each real image to obtain the corresponding initial adversarial image.
[0037] Assuming there are N real images (N is a positive integer and can be set), then N initial adversarial images can be obtained. The i-th initial adversarial image X... i Based on the i-th real image I i We obtain i = 1, 2, ..., N.
[0038] For each initial adversarial image X i The confidence level that the preset target corresponding to the initial adversarial image is correctly identified can be obtained, and this confidence level can be represented as conf. i Confidence level can also be called probability.
[0039] For each initial adversarial image X iIt can be input into the object detector, and the corresponding confidence level (conf) can be obtained based on the output of the object detector. i The object detector can be a pre-trained object detection model, such as the YOLOv3 model.
[0040] Obtain the above N confidence levels (conf) i Then, based on the range of confidence values, at least one group can be obtained, and each group includes at least one confidence value.
[0041] For example, the confidence scores of values within the first value range are divided into a first group, the confidence scores of values within the second value range are divided into a second group, and the confidence scores of values within the third value range are divided into a third group. Since the confidence score is typically a value between [0,1], the three value ranges mentioned above belong to [0,1], and the first, second, and third value ranges are different.
[0042] The three numerical ranges mentioned above are ranges greater than or equal to a preset threshold. For example, if the preset threshold is 0.25, then all three numerical ranges are greater than or equal to 0.25. Values less than the preset threshold can be considered as indicating a successful adversarial attack on the corresponding image.
[0043] For example, if the first numerical range is [0.25, 0.6), the second numerical range is [0.6, 0.85), and the third numerical range is [0.85, 1], then taking the first numerical range as an example, the confidence scores greater than or equal to 0.25 and less than 0.6 can be divided into the first group. The process of obtaining the other groups is similar.
[0044] After obtaining at least one group, a loss function can be constructed based on the confidence levels included in each group and the weights of each group. For example, for each group, the sum of the confidence levels included in that group can be calculated as the total confidence level of that group, and then the total confidence level can be weighted and summed to obtain the loss function.
[0045] After obtaining the total confidence score for each group, a loss function can be determined based on the total confidence score and corresponding weights of each group. The loss function can be a weighted sum of the total confidence scores of each group.
[0046] After obtaining the loss function, the initial perturbation information can be adjusted (or trained) using the loss function to obtain the final perturbation information.
[0047] When training with a loss function, the goal is to minimize the loss function. Since the loss function is obtained based on the confidence level mentioned above, the training process can minimize the confidence level. Because the lower the confidence level, the higher the success rate of attacking the corresponding adversarial image, the success rate of attacking each final adversarial image can be improved.
[0048] Specifically, the perturbation information can be pixel values. The adjustment process for pixel values can employ common back propagation (BP) algorithms, i.e., the updated pixel value = the pixel value before the update - the preset learning rate * gradient value, where the gradient value is obtained by taking the derivative of the loss function.
[0049] The training process can be a series of iterations until a preset condition is met, at which point the iteration process ends. The preset condition can be that the number of iterations reaches a preset number, the iteration duration reaches a preset duration, or the perturbation information after iteration meets a preset convergence condition, etc.
[0050] Training ends when preset conditions are met, and the final perturbation information is obtained.
[0051] After obtaining the final perturbation information, a corresponding perturbation image can be generated. For example, if the perturbation information is a pixel value, an image with that pixel value can be generated as the perturbation image.
[0052] For example, if the disturbance image generated based on the final disturbance information is an electronic version, the electronic disturbance image can be printed out to obtain a paper disturbance image. The paper disturbance image can be pasted onto a preset target (e.g., a car). Then, multiple images can be taken according to the distance between the camera and the car from near to far. These multiple images can be used as the final adversarial images.
[0053] During testing, the success rate of attacks on the final adversarial images can be tested. For example, during testing, for each final adversarial image, it is input into a target detector. If the confidence level of the target detector's output for a preset target (e.g., a car) is less than a preset threshold (e.g., 0.25), then the final adversarial image is considered to have been successfully attacked. By statistically analyzing whether each final adversarial image in all final adversarial images was successfully attacked, the overall attack success rate can be obtained.
[0054] In this embodiment, the final perturbation information is determined based on the loss function, which is constructed based on the weights of each group. Since each group has a corresponding weight, the attention to different groups can be adjusted through the weights. Therefore, the final perturbation information can be considered as obtained by giving different attention to different groups. Giving different attention to different groups can obtain a larger number of successful final adversarial images, thus improving the success rate of the final adversarial images.
[0055] To better understand the embodiments of this disclosure, the application scenarios to which the embodiments of this disclosure are applicable are described below.
[0056] like Figure 2 As shown, the image generation method can be executed by an electronic device, which can be a terminal device or a server. This embodiment takes the execution by a server as an example.
[0057] This embodiment generates a perturbation image based on the final perturbation information. The perturbation information can specifically be the perturbation pixel values.
[0058] The final perturbation pixel value can be obtained through a training process based on the initial perturbation pixel value. The initial perturbation pixel value can be a manually set pixel value, or a random pixel value obtained through random processing.
[0059] In terms of overall architecture, such as Figure 2 As shown, the system may include an adding module 201, a training module 202, and a generation module 203. The adding module 201 adds initial perturbation pixel values to a real image to obtain an initial adversarial image. The training module 202 trains the initial perturbation pixel values based on the initial adversarial image to obtain final perturbation pixel values. The generation module 203 generates a corresponding perturbation image based on the final perturbation pixel values. The final adversarial image can then be generated using the perturbation image.
[0060] like Figure 3 As shown, the overall training process for perturbation information can include: obtaining at least one initial adversarial image based on the initial perturbation pixel values; and for each initial adversarial image in the at least one initial adversarial image, X... i The data is input into an object detector (such as a YOLOv3 model), which outputs the detection results of preset targets (e.g., cars) in each initial adversarial image. Based on these detection results, the confidence level (conf) of the correct identification of the preset target in each initial adversarial image can be obtained. i Based on the confidence level, at least one group can be obtained. For each group in the at least one group, the total confidence level of each group can be obtained. Based on the total confidence level of each group and its weight, the loss function L can be determined. Based on the loss function L, the initial perturbation pixel value is adjusted until the preset condition is met, and the final perturbation pixel value can be obtained.
[0061] In conjunction with the above application scenarios, this disclosure also provides an image generation method.
[0062] Figure 4 Based on a schematic diagram of a second embodiment of this disclosure, this embodiment provides an image generation method, the method comprising:
[0063] 401. Based on initial perturbation information and at least one real image, obtain at least one initial adversarial image, wherein each initial adversarial image contains a preset target.
[0064] Taking a car as an example, the system can capture multiple real images of the car's actual environment, in order of distance from the camera to the car, from closest to furthest.
[0065] For each real image, perturbation information can be added to each real image to obtain each initial adversarial image.
[0066] Assuming each real image is represented by I i This indicates that each initial adversarial image is represented by X. i If X represents X, then i Based on I i The obtained values are i = 1, 2, ..., N, where N is the number of real images, which is a positive integer.
[0067] Specifically, for each real image, a current perturbation region can be determined; and, based on the initial perturbation information, current perturbation information is determined, and based on the current perturbation information, the real pixel values within the current perturbation region are perturbed to obtain the at least one initial adversarial image.
[0068] In this embodiment, by obtaining each initial adversarial image based on perturbation information on each real image, the initial adversarial image can be obtained simply and effectively.
[0069] In some embodiments, determining the current disturbance region includes:
[0070] For the first real image, a preset initial disturbance region is taken as the current disturbance region in the first real image;
[0071] For the second real image, based on the location information of the preset target in the second real image, the location information of the preset target in the first real image, and the location information of the initial disturbance area, the current disturbance area in the second real image is determined;
[0072] The first real image is a real image selected from the at least one real image based on a preset rule, and the second real image is another real image from the at least one real image besides the first real image.
[0073] Specifically, the aforementioned perturbation processing can involve replacing the actual pixel values within the current perturbation area with the current perturbation information.
[0074] In this context, assuming the first real image is represented by I1, the preset rule can be to select the real image of the preset target that is closest to the camera. Due to the principle that objects appear larger when closer and smaller when farther away, the preset target (e.g., a car) in the first real image I1 will have the largest scale among all the real images.
[0075] For the first real image, the location information of the preset target can be represented as: xmin1, ymin1, xmax1, ymax1. That is, the region where the preset target is located is usually represented by a rectangle, where (xmin1, ymin1) are the coordinates of the upper left corner of the rectangle, and (xmax1, ymax1) are the coordinates of the lower right corner of the rectangle. The location information of the preset target in the first real image can be manually labeled or obtained based on the target detector.
[0076] The perturbation region on the first real image can be called the first perturbation region, denoted by pert1. Generally speaking, the perturbation region is also rectangular, and the location information of the first perturbation region can be represented as:
[0077] pert_xmin,pert_ymin,pert_xmax,pert_ymax;
[0078] (pert_xmin, pert_ymin) are the coordinates of the upper left corner of the first perturbation region;
[0079] (pert_xmax,pert_ymax) are the coordinates of the lower right corner of the first perturbation region.
[0080] The first disturbance region can be set according to actual needs; that is, the location information of the first disturbance region is a settable value and can be called the initial disturbance region. Generally speaking, the first disturbance region is located within the area where the preset target is located in the first real image, or coincides with the area where the preset target is located.
[0081] The pixel value within the first perturbation region can be called the first perturbation pixel value or the initial perturbation pixel value. This pixel value can be set according to actual needs. For example, the pixel value within the first perturbation region can be randomized to obtain a random first perturbation pixel value.
[0082] like Figure 5 As shown, after determining the first perturbation pixel value, the first perturbation pixel value can be used to replace...
[0083] The real pixel values within the corresponding region (i.e., the first perturbation region) of the first real image are used to obtain the adversarial image X1 corresponding to the first real image I1. Figure 5 (Represented by the first adversarial image in the middle).
[0084] For the second real image, a replacement method similar to that used for the first real image can be adopted.
[0085] The perturbation region on the second real image (i.e. the current perturbation region on the second real image) can be called the second perturbation region. The first perturbation region can be manually set, and the second perturbation region can be determined based on the first perturbation region.
[0086] The perturbation pixel value corresponding to the second real image can be called the second perturbation pixel value (i.e. the current perturbation pixel value corresponding to the second real image). The first perturbation information can be set manually, and the second perturbation pixel value can be determined based on the first perturbation pixel value.
[0087] For the second disturbance region, the location information of the preset target in the second real image, the location information of the preset target in the first real image, and the location information of the first disturbance region in the first real image can be used as a basis.
[0088] The specific calculation formula is as follows:
[0089] w1=xmax1-xmin1, h1=ymax1-ymin1
[0090] pert_w=pert_xmax-pert_xmin,pert_h=pert_ymax-pert_ymin
[0091] scale_w=pert_w / w1, scale_h=pert_h / h1
[0092] w2=xmax2-xmin2, h2=ymax2-ymin2
[0093] w2'=w2*scale_w, h2'=h2*scale_h
[0094] xmin2'=(pert_x-xmin1)*scale_w+xmin2
[0095] ymin2'=(pert_y-ymin1)*scale_h+ymin2
[0096] xmax2'=xmin2'+w2',ymax2'=ymin2'+h2'
[0097] Where xmin2, ymin2, xmax2, ymax2 are the location information of the preset target in the second real image. This location information can be manually annotated or obtained by using a target detector.
[0098] xmin2', ymin2', xmax2', ymax2' are the location information of the second disturbance region to be determined;
[0099] xmin1, ymin1, xmax1, ymax1 are the location information of the preset target in the first real image;
[0100] pert_xmin, pert_ymin, pert_xmax, and pert_ymax are the location information of the first perturbation region;
[0101] The remaining parameters are intermediate parameters in the calculation process.
[0102] Based on the above calculation formula, the location information of the second disturbance region can be obtained.
[0103] The second perturbation pixel value can be obtained based on the first perturbation pixel value, the size of the first perturbation region, and the size of the second perturbation region.
[0104] Specifically, the second perturbation pixel value can be obtained by downsampling the first perturbation pixel value based on the size of the first perturbation region and the size of the second perturbation region. For example, if the size of the first perturbation region is 10*10 and the size of the second perturbation region is 5*5, then a 2x downsampling can be used to obtain a second perturbation pixel value of size 5*5 from the first perturbation pixel value.
[0105] For the second real image, after obtaining the corresponding second perturbation region and the second perturbation pixel value, the real pixel value in the second perturbation region on the second real image can be replaced with the second perturbation pixel value to obtain the adversarial image corresponding to the second real image.
[0106] Therefore, by using the above process, each real image I can be obtained. i Corresponding adversarial image X i , i = 1, 2, ..., N.
[0107] In this embodiment, the first perturbation region and the first perturbation pixel value can be set based on actual needs to improve flexibility; the second perturbation region is determined based on the first perturbation region, and the second perturbation pixel value is determined based on the first perturbation pixel value, which can ensure the consistency of perturbation and thus improve the accuracy of the generated image.
[0108] In this embodiment, by replacing the real pixel values of the corresponding area with the current perturbation information, adversarial images can be effectively obtained.
[0109] 402. Using a target detector, target detection processing is performed on each of the input initial adversarial images to output the detection result of the preset target corresponding to each of the initial adversarial images.
[0110] The object detector can be obtained through pre-training, such as the YOLOv3 model.
[0111] For each initial adversarial image, it can be input into the target detector, which can then perform target detection processing on the initial adversarial image and output the detection results.
[0112] 403. Based on the detection results, obtain the confidence level that the preset target has been correctly identified.
[0113] In this embodiment, for each initial adversarial image, an object detector is used to obtain the corresponding detection result, and the corresponding confidence level is obtained based on the detection result. Since the object detector is an existing trained detector, the confidence level can be accurately obtained using the object detector.
[0114] The detection results can include information about the detection boxes and category information for a preset target. The detection box information can include the box's location and confidence level. The category information includes the confidence level of the preset target belonging to each of the preset categories (80 in YOLOv3). The box's location can be represented by four parameters: x, y, w, and h. Here, (x, y) are the coordinates of the top-left corner of the detection box, and w and h are the width and height of the detection box, respectively. Taking category 80 as an example, the output for each detection box is 85 parameters: four parameters for the box's location, one parameter for the box's confidence level, and 80 parameters for the category confidence level.
[0115] In this embodiment, the confidence level of the preset target being correctly identified can be obtained from the aforementioned category confidence level and detection box confidence level.
[0116] Specifically, the detection result includes: a first confidence level and at least one second confidence level, wherein the first confidence level is the confidence level of the detection box corresponding to the preset target, and the second confidence level is the confidence level that the preset target belongs to each category in at least one category; obtaining the confidence level that the preset target is correctly identified based on the detection result includes: obtaining a third confidence level based on the at least one second confidence level, wherein the third confidence level is the confidence level that the preset target belongs to the correct category; and determining the confidence level that the preset target is correctly identified based on the third confidence level and the first confidence level.
[0117] The specific calculation formula is as follows:
[0118] conf i =max(sigmoid(F(X) i )[:,:,5:85])[:,:,t]*F(X i)[:,:,4])
[0119] Among them, conf i It is the i-th initial adversarial image X i The confidence level that the preset target was correctly identified;
[0120] F represents the target detector, F(X) i ) is the output of the target detector;
[0121] F(X i [:,:,4] is the first confidence level, that is, the confidence level of the detection box corresponding to the preset target;
[0122] F(X i [:,:,5:85] is the second confidence level, that is, the confidence level that the target belongs to each category;
[0123] sigmoid() represents the normalization operation;
[0124] t is the correct category (ground truth) of the preset target, which can be manually labeled;
[0125] sigmoid(F(X i [:,:,5:85])[:,:,t] is the third confidence level, which is the confidence level that the target belongs to the correct category;
[0126] `max()` is a function to retrieve the maximum value. Since the object detector can output multiple bounding boxes for a preset target, this function is used to retrieve the maximum value.
[0127] In this embodiment, the confidence level of the preset target being correctly identified is determined based on the confidence level of the detection box and the confidence level of the preset target belonging to the correct category. Since the information of the detection box and the category information are taken into account, the accuracy of the confidence level of the preset target being correctly identified can be improved, thereby improving the accuracy of the generated image.
[0128] 404. Based on the confidence level, obtain at least one group, wherein each group in the at least one group includes at least one of the confidence levels.
[0129] 405. For each group in the at least one group, determine the total confidence level of each group based on the confidence level included in each group.
[0130] Grouping can be based on the numerical range to which the confidence level belongs.
[0131] For a given adversarial image, if its corresponding confidence level is less than a certain threshold, the attack can be considered successful.
[0132] The threshold mentioned above is, for example, 0.25. When grouping, groups can be formed based on confidence levels greater than this threshold.
[0133] For example, the first numerical range is [0.25, 0.6), the second numerical range is [0.6, 0.85), and the third numerical range is [0.85, 1].
[0134] Based on the above three numerical ranges, three groups can be obtained, and the corresponding total confidence level can be the sum of the confidence levels within the corresponding group.
[0135] The formula is expressed as follows:
[0136] conf 256 =sum(conf) i ≥0.25 and conf i <0.6)
[0137] conf 685 =sum(conf) i ≥0.6 and conf i <0.85)
[0138] conf 85 =sum(conf) i ≥0.85)
[0139] Among them, conf 256 ,conf 685 ,conf 85 These represent three groups.
[0140] 406. Determine the loss function based on the total confidence of each group and the weight of each group.
[0141] The loss function can be a weighted sum of the total confidence scores of each group.
[0142] For example, taking three groups as an example, with the weights corresponding to the three groups represented by a, b, and c respectively, the formula for calculating the loss function L is:
[0143] L = a * total confidence level of the first group + b * total confidence level of the second group + c * total confidence level of the third group.
[0144] Here, a, b, and c are settable values, located between [0, 1], and a + b + c = 1.
[0145] In this embodiment, a loss function is constructed based on the total confidence of each group and its corresponding weight. This allows the loss function to easily include information about each group, and each group can be assigned different weights based on actual needs, thereby obtaining more successful adversarial images.
[0146] Furthermore, for each training stage in multiple training stages, the weights of each group corresponding to each training stage can be obtained; for each training stage, a loss function corresponding to each training stage can be constructed based on the total confidence of each group and the weights of each group corresponding to each training stage.
[0147] That is, different loss functions can be constructed based on different weights for different training stages.
[0148] In this embodiment, loss functions are constructed based on different weights at different training stages, which can achieve phased training for perturbation information. During phased training, appropriate groups to focus on can be selected based on different training stages to obtain more successful final adversarial images, thereby improving the overall success rate of adversarial image attacks.
[0149] Specifically, the at least one group includes, in ascending order of total confidence, a first group, a second group, and a third group, and correspondingly, the weights of each group include a first weight, a second weight, and a third weight.
[0150] The training phases, in order from front to back, include: the first training phase, the second training phase, and the third training phase;
[0151] The step of obtaining the weights of each group corresponding to each training stage in multiple training stages includes:
[0152] In the first training phase, the first weight, the second weight, and the third weight are set to be the same.
[0153] In the second training phase, the second weight is set to be greater than the first weight and the third weight;
[0154] In the third training phase, the first weight is set to be greater than the second weight and the third weight.
[0155] That is, in the early stage of training (the first training phase), all adversarial images need to be focused on, so the first weight, the second weight, and the third weight are the same;
[0156] During the middle of training (second training phase), attention needs to be paid to adversarial images whose confidence is difficult to decrease (i.e., adversarial images corresponding to the second group). Therefore, the second weight is the largest.
[0157] In the later stages of training (the third training phase), it is necessary to focus on the adversarial image at the critical point of whether the attack is successful (i.e., the adversarial image corresponding to the first group). Therefore, the first weight is the largest.
[0158] For example, the loss functions for the three training phases can be represented by L1, L2, and L3, respectively, and the calculation formulas can be as follows:
[0159] L1 = sum(conf) i ≥0.25)=conf 256 +conf 685 +conf 85
[0160] L2 = 0.2 * conf 256 +0.5*conf 685 +0.3*conf 85
[0161] L3 = 0.5 * conf 256 +0.3*conf 685 +0.2*conf 85
[0162] In this embodiment, by selecting appropriate weights for each group in the first, second, and third training phases, the groups that need attention can be selected based on the characteristics of each training phase, thereby obtaining a larger number of successful final adversarial images and improving the overall attack success rate.
[0163] 407. Based on the loss function, adjust the initial perturbation information until a preset condition is met to obtain the final perturbation information.
[0164] The adjustment objective can be to obtain the final perturbation information by minimizing the loss function. Specific adjustment methods can include common backpropagation (BP) algorithms.
[0165] 408. Generate a perturbation image based on the final perturbation information, and use the perturbation image to generate the final adversarial image.
[0166] The final perturbation information can be the final perturbation pixel value, thus a perturbation image with the final perturbation pixel value can be generated.
[0167] During testing, a physical perturbation image can be generated based on the perturbation image (which can be considered virtual). For example, the perturbation image can be printed out; this printed image is the physical perturbation image. This physical perturbation image is then pasted onto a pre-defined physical target, such as a car in a physical environment. The car with the pasted physical perturbation image is then photographed to obtain the adversarial image to be tested, i.e., the final adversarial image. This adversarial image is input into a target detector to obtain its confidence score in the correct category (i.e., the car category). If the confidence score is less than a threshold (e.g., 0.25), the adversarial image is considered to have successfully attacked. In this case, the detection result shows that the target has disappeared or has been misclassified as another category. These final adversarial images can be combined into a video for testing. By statistically analyzing whether each final adversarial image was successfully attacked, the attack success rate of all final adversarial images can be obtained.
[0168] Figure 6 This is a schematic diagram according to the third embodiment of the present disclosure. This embodiment provides an image generation device 600, which includes: a determining module 601, a grouping module 602, an adjusting module 603, and a generation module 604.
[0169] The determining module 601 is used to determine, for each initial adversarial image, the confidence level that the preset target corresponding to each initial adversarial image is correctly identified;
[0170] Grouping module 602 is used to obtain at least one group based on the confidence level, wherein each group in the at least one group includes at least one of the confidence levels;
[0171] The adjustment module 603 is used to construct a loss function based on the confidence level included in each group and the weight of each group, and adjust the initial perturbation information based on the loss function to obtain the final perturbation information;
[0172] The generation module 604 is used to generate a perturbation image based on the final perturbation information, and the perturbation image is used to generate the final adversarial image.
[0173] In this embodiment, the final perturbation information is determined based on the loss function, which is constructed based on the weights of each group. Since each group has a corresponding weight, the attention to different groups can be adjusted through the weights. Therefore, the final perturbation information can be considered as obtained by giving different attention to different groups. Giving different attention to different groups can obtain a larger number of successful final adversarial images, thus improving the success rate of the final adversarial images.
[0174] In some embodiments, the adjustment module 604 is further configured to:
[0175] For each group, the total confidence level of each group is determined based on the confidence level included in each group;
[0176] The loss function is constructed based on the total confidence of each group and the weight of each group.
[0177] In this embodiment, a loss function is constructed based on the total confidence of each group and its corresponding weight. This allows the loss function to easily include information about each group, and each group can be assigned different weights based on actual needs, thereby obtaining more successful adversarial images.
[0178] In some embodiments, the adjustment module 603 is further configured to:
[0179] For each training stage in multiple training stages, obtain the weights of each group corresponding to each training stage;
[0180] For each training stage, a loss function is constructed based on the total confidence of each group and the weights of each group corresponding to each training stage.
[0181] In this embodiment, different loss functions are constructed at different training stages, which can realize phased training for perturbation information. During phased training, appropriate groups to focus on can be selected based on different training stages to obtain more suitable final perturbation information. Thus, more successful final adversarial images can be obtained based on the final perturbation information, thereby improving the overall success rate of the final adversarial image attack.
[0182] In some embodiments, the at least one group includes, in ascending order of the loss function, a first group, a second group, and a third group, and correspondingly, the weights of each group include a first weight, a second weight, and a third weight.
[0183] The training phases, in order from front to back, include: the first training phase, the second training phase, and the third training phase;
[0184] The adjustment module 603 is further used for:
[0185] In the first training phase, the first weight, the second weight, and the third weight are set to be the same.
[0186] In the second training phase, the second weight is set to be greater than the first weight and the third weight;
[0187] In the third training phase, the first weight is set to be greater than the second weight and the third weight.
[0188] In this embodiment, by selecting appropriate weights for each group in the first, second, and third training phases, the groups that need attention can be selected based on the characteristics of each training phase, thereby obtaining a larger number of successful final adversarial images and improving the overall attack success rate.
[0189] In some embodiments, the determining module 602 is further configured to:
[0190] A target detector is used to perform target detection processing on each of the input initial adversarial images, so as to output the detection results of the preset target contained in each of the initial adversarial images;
[0191] Based on the detection results, the confidence level that the preset target has been correctly identified is obtained.
[0192] In this embodiment, for each initial adversarial image, an object detector is used to obtain the corresponding detection result, and the corresponding confidence level is obtained based on the detection result. Since the object detector is an existing trained detector, the confidence level can be accurately obtained using the object detector.
[0193] In some embodiments, the detection result includes: a first confidence level and at least one second confidence level, wherein the first confidence level is the confidence level of the detection box corresponding to the preset target, and the second confidence level is the confidence level of the preset target belonging to each category in at least one category;
[0194] The determining module 602 is further configured to:
[0195] Based on the at least one second confidence level, a third confidence level is obtained, wherein the third confidence level is the confidence level that the preset target belongs to the correct category;
[0196] Based on the third confidence level and the first confidence level, the confidence level that the preset target has been correctly identified is determined.
[0197] In this embodiment, the confidence level of the preset target being correctly identified is determined based on the confidence level of the detection box and the confidence level of the preset target belonging to the correct category. Since the information of the detection box and the category information are taken into account, the accuracy of the confidence level of the preset target being correctly identified can be improved, thereby improving the accuracy of the generated image.
[0198] In some embodiments, the apparatus further includes an acquisition module, the acquisition module being used to:
[0199] For each real image in at least one real image, a current perturbation region is determined; and, based on the initial perturbation information, current perturbation information is determined, and the real pixel values within the current perturbation region are perturbed based on the current perturbation information to obtain the at least one initial adversarial image.
[0200] In this embodiment, initial adversarial images can be obtained simply and effectively by deriving each initial adversarial image based on each real image and perturbation information.
[0201] In some embodiments, the acquisition module is further configured to:
[0202] For the first real image, a preset initial disturbance region is taken as the current disturbance region in the first real image;
[0203] For the second real image, based on the location information of the preset target in the second real image, the location information of the preset target in the first real image, and the location information of the initial disturbance area, the current disturbance area in the second real image is determined;
[0204] The first real image is a real image selected from the at least one real image based on a preset rule, and the second real image is another real image from the at least one real image besides the first real image.
[0205] In this embodiment, the first perturbation region and the first perturbation pixel value can be set based on actual needs to improve flexibility; the second perturbation region is determined based on the first perturbation region, and the second perturbation pixel value is determined based on the first perturbation pixel value, which can ensure the consistency of perturbation and thus improve the accuracy of the generated image.
[0206] In some embodiments, the acquisition module is further configured to:
[0207] The current disturbance information is used to replace the actual pixel value within the current disturbance area.
[0208] In this embodiment, by replacing the real pixel values of the corresponding area with the current perturbation information, the initial adversarial image can be effectively obtained.
[0209] It is understood that the same or similar content in different embodiments of this disclosure can be referred to each other.
[0210] It is understood that the terms "first" and "second" in the embodiments of this disclosure are only used for distinction and do not indicate the degree of importance or the order of events.
[0211] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0212] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0213] Figure 7 A schematic block diagram of an example electronic device 700 that can be used to implement embodiments of the present disclosure is shown. Electronic device 700 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, servers, blade servers, mainframe computers, and other suitable computers. Electronic device 700 may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0214] like Figure 7 As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. The RAM 703 may also store various programs and data required for the operation of the electronic device 700. The computing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0215] Multiple components in electronic device 700 are connected to I / O interface 705, including: input unit 706, such as keyboard, mouse, etc.; output unit 707, such as various types of displays, speakers, etc.; storage unit 708, such as disk, optical disk, etc.; and communication unit 709, such as network card, modem, wireless transceiver, etc. Communication unit 709 allows electronic device 700 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0216] The computing unit 701 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as image generation methods. For example, in some embodiments, the image generation method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 700 via ROM 702 and / or communication unit 709. When the computer program is loaded into RAM 703 and executed by the computing unit 701, one or more steps of the image generation method described above may be performed. Alternatively, in other embodiments, the computing unit 701 may be configured to perform the image generation method by any other suitable means (e.g., by means of firmware).
[0217] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0218] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable retrieval device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0219] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0220] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0221] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0222] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0223] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0224] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. An image generation method, comprising: For each initial adversarial image in at least one initial adversarial image, determine the confidence level that a preset target contained in each initial adversarial image is correctly identified; wherein, the at least one initial adversarial image is obtained based on initial perturbation information; Based on the confidence level, multiple groups are obtained, and each of the multiple groups includes at least one of the confidence levels; Based on the confidence scores of each group and the weights of each group, a loss function is constructed, and the initial perturbation information is adjusted based on the loss function to obtain the final perturbation information; wherein, the loss function is a weighted sum of the total confidence scores of each group, and for each training stage in multiple training stages, the loss function corresponding to each training stage is constructed based on the total confidence scores of each group and the weights of each group corresponding to each training stage; A perturbation image is generated based on the final perturbation information, and the perturbation image is used to generate the final adversarial image; The multiple groups are arranged in ascending order of total confidence: a first group, a second group, and a third group. Correspondingly, the weights of each group include a first weight, a second weight, and a third weight. The training phases, in order from front to back, include: the first training phase, the second training phase, and the third training phase; The method further includes: In the first training phase, the first weight, the second weight, and the third weight are set to be the same. In the second training phase, the second weight is set to be greater than the first weight and the third weight; In the third training phase, the first weight is set to be greater than the second weight and the third weight.
2. The method according to claim 1, wherein, Determining the confidence level that the preset targets contained in each of the initial adversarial images are correctly identified includes: A target detector is used to perform target detection processing on each of the input initial adversarial images, so as to output the detection result of the preset target corresponding to each initial adversarial image; Based on the detection results, the confidence level that the preset target has been correctly identified is obtained.
3. The method according to claim 2, wherein, The detection result includes: a first confidence level and at least one second confidence level, wherein the first confidence level is the confidence level of the detection box corresponding to the preset target, and the second confidence level is the confidence level of the preset target belonging to each category in at least one category; The step of obtaining the confidence level that the preset target has been correctly identified based on the detection results includes: Based on the at least one second confidence level, a third confidence level is obtained, wherein the third confidence level is the confidence level that the preset target belongs to the correct category; Based on the third confidence level and the first confidence level, the confidence level that the preset target has been correctly identified is determined.
4. The method according to claim 1, further comprising: For each real image in at least one real image, determine the current disturbance region; Furthermore, based on the initial perturbation information, current perturbation information is determined, and based on the current perturbation information, the real pixel values within the current perturbation area are perturbed to obtain the at least one initial adversarial image.
5. The method according to claim 4, wherein, Determining the current disturbance area includes: For the first real image, a preset initial disturbance region is taken as the current disturbance region in the first real image; For the second real image, based on the location information of the preset target in the second real image, the location information of the preset target in the first real image, and the location information of the initial disturbance area, the current disturbance area in the second real image is determined; The first real image is a real image selected from the at least one real image based on a preset rule, and the second real image is another real image from the at least one real image besides the first real image.
6. The method according to claim 4, wherein, The perturbation processing of the real pixel values within the current perturbation region based on the current perturbation information includes: The current disturbance information is used to replace the actual pixel value within the current disturbance area.
7. An image generation apparatus, comprising: A determination module is used to determine, for each initial adversarial image in at least one initial adversarial image, the confidence level that a preset target contained in each initial adversarial image is correctly identified; wherein, the at least one initial adversarial image is obtained based on initial perturbation information; A grouping module is used to obtain multiple groups based on the confidence level, wherein each group includes at least one of the confidence levels; An adjustment module is used to construct a loss function based on the confidence levels included in each group and the weights of each group, and to adjust the initial perturbation information based on the loss function to obtain the final perturbation information; wherein, the loss function is a weighted sum of the total confidence levels of each group, and for each training stage in multiple training stages, the loss function corresponding to each training stage is constructed based on the total confidence levels of each group and the weights of each group corresponding to each training stage; A generation module is used to generate a perturbation image based on the final perturbation information, and the perturbation image is used to generate a final adversarial image; The multiple groups are ordered in ascending order of the loss function as: a first group, a second group, and a third group. Correspondingly, the weights of each group include: a first weight, a second weight, and a third weight. The training phases, in order from front to back, include: the first training phase, the second training phase, and the third training phase; The device further includes: an adjustment module, the adjustment module being used for: In the first training phase, the first weight, the second weight, and the third weight are set to be the same. In the second training phase, the second weight is set to be greater than the first weight and the third weight; In the third training phase, the first weight is set to be greater than the second weight and the third weight.
8. The apparatus according to claim 7, wherein, The determining module is further used for: A target detector is used to perform target detection processing on each of the input initial adversarial images, so as to output the detection result of the preset target corresponding to each initial adversarial image; Based on the detection results, the confidence level that the preset target has been correctly identified is obtained.
9. The apparatus according to claim 8, wherein, The detection result includes: a first confidence level and at least one second confidence level, wherein the first confidence level is the confidence level of the detection box corresponding to the preset target, and the second confidence level is the confidence level of the preset target belonging to each category in at least one category; The determining module is further used for: Based on the at least one second confidence level, a third confidence level is obtained, wherein the third confidence level is the confidence level that the preset target belongs to the correct category; Based on the third confidence level and the first confidence level, the confidence level that the preset target has been correctly identified is determined.
10. The apparatus according to claim 7, further comprising: The acquisition module is used to determine the current disturbance region for each real image in at least one real image; Furthermore, based on the initial perturbation information, current perturbation information is determined, and based on the current perturbation information, the real pixel values within the current perturbation area are perturbed to obtain the at least one adversarial image.
11. The apparatus according to claim 10, wherein, The acquisition module is further used for: For the first real image, a preset initial disturbance region is taken as the current disturbance region in the first real image; For the second real image, based on the location information of the preset target in the second real image, the location information of the preset target in the first real image, and the location information of the initial disturbance area, the current disturbance area in the second real image is determined; The first real image is a real image selected from the at least one real image based on a preset rule, and the second real image is another real image from the at least one real image besides the first real image.
12. The apparatus according to claim 10, wherein, The acquisition module is further used for: The current disturbance information is used to replace the actual pixel value within the current disturbance area.
13. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-6.
14. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-6.
15. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1-6.
Citation Information
Patent Citations
Multi-sample adversarial disturbance generation method and device, storage medium and computing equipment
CN111738374A