An adaptive parameter adversarial attack method for a three-dimensional face reconstruction system
By using an adaptive parameter adversarial attack method, the parameter weights of the 3D face reconstruction model are initialized and updated. Combined with semantic constraints, the adversarial examples are optimized, which solves the problem of insufficient defense capability of the 3D face reconstruction model and improves the robustness of the model and the concealment of the adversarial examples.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SUN YAT SEN UNIV
- Filing Date
- 2022-09-20
- Publication Date
- 2026-05-08
AI Technical Summary
Existing 3D face reconstruction models lack the ability to defend against adversarial attacks, leading to security issues, especially in 3D face reconstruction tasks where there is a lack of effective defense measures.
An adaptive parameter adversarial attack method is provided. By initializing parameter weights, updating the parameter weights using adaptive methods and gradient descent, and optimizing adversarial examples by combining semantic constraints, the attack on the target image is completed when the preset conditions are met.
It improves the robustness and generalization ability of the 3D face reconstruction model, increases the visual concealment of adversarial examples, and enhances the model's defense capabilities.
Smart Images

Figure CN115830218B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to an adaptive parameter adversarial attack method for 3D face reconstruction systems. Background Technology
[0002] Deep neural networks have demonstrated powerful capabilities in handling various computer vision tasks, such as image classification, face recognition, and 3D reconstruction. However, in recent years, deep neural networks have been shown to be vulnerable to carefully designed perturbations in images. Attackers can add subtle noise to clean data, forcing deep learning models to produce incorrect results. Therefore, in-depth research into the existence of adversarial examples and the generation of novel adversarial examples is crucial for improving the security and reliability of artificial intelligence and for the wider application and promotion of AI technologies.
[0003] Research on adversarial examples in the 2D domain is becoming increasingly abundant. However, research on 3D scenarios is relatively scarce. The latest research on adversarial attacks in the 3D domain mainly focuses on the classification of 3D point clouds or 3D meshes, lacking relevant research on 3D face reconstruction tasks. 3D face reconstruction is widely used in animation production, game development, 3D face recognition, and other fields. If 3D face reconstruction models lack the ability to defend against adversarial attacks, it will lead to serious security problems. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide an adaptive parameter adversarial attack method for 3D face reconstruction systems with high generalization ability, so as to improve the robustness of 3D face reconstruction models.
[0005] One aspect of this invention provides an adaptive parameter adversarial attack method for 3D face reconstruction systems, comprising:
[0006] The parameter weights are initialized according to the types of output parameters of the 3D face reconstruction network; wherein, the types of output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters, and camera parameters;
[0007] Based on the parameter weights, the input adversarial sample attacks the 3D face reconstruction model.
[0008] The parameter weights are continuously updated using an adaptive method;
[0009] The adversarial samples are continuously updated using gradient descent and optimized through semantic constraints until preset conditions are met, thus completing the attack on the target image.
[0010] Optionally, the step of inputting adversarial examples to attack the 3D face reconstruction model according to the parameter weights includes:
[0011] A random noise matrix is generated based on a uniform random distribution, and the adversarial sample is initialized accordingly.
[0012] Based on the output parameters of the adversarial examples and the output parameters of the clean image, the parameter loss is calculated based on the parameter weights to optimize the adversarial examples, thereby misleading the output results of the 3D face reconstruction network.
[0013] Optionally, the step of continuously updating the parameter weights using an adaptive method includes:
[0014] Based on parameter loss-driven adaptive optimization iteration, the optimal parameter weights are found each time, so that the distance between the adversarial example and the clean image increases, thereby reducing the similarity between the output parameters of the adversarial example and the output parameters of the clean image.
[0015] Optionally, the step of continuously updating the parameter weights using an adaptive method includes:
[0016] The parameter weights are adaptively updated using boundary loss and extreme value loss.
[0017] The expression for the boundary loss is as follows:
[0018] E bd = f(x0+∈) - f(x0-∈)
[0019] The expression for the extreme value loss is:
[0020]
[0021] Among them, E bd Represents the boundary loss; f() represents the output of the 3D face reconstruction system; x0 represents the clean image; ∈ represents the maximum perturbation range; E wb Represents extreme value loss; Representative adversarial example; f w () represents the output of the worst adversarial example; f b () represents the output of the current best adversarial example.
[0022] Optionally, in the step of continuously updating the adversarial examples using gradient descent, the update formula for the adversarial examples is:
[0023]
[0024] in, Represents adversarial examples; ∈ represents the maximum perturbation range; T represents the maximum number of iterations; sign represents the sign operation; Representative of adversarial examples Find the gradient; L represents the loss function.
[0025] Optionally, optimizing the adversarial example through semantic constraints includes:
[0026] The adversarial examples are projected into a small-range infinite norm space of the natural image to constrain the numerical range of the generated adversarial examples.
[0027] The expression for the constraint is:
[0028] x = Projection ∞ (x, x0, ∈)
[0029] Where Projection is the projection function; x0 is the natural image corresponding to the perturbed face parameters output after the attack; ∈ is the maximum perturbation range; and x is the constrained adversarial sample.
[0030] Another aspect of this invention provides an adaptive parameter adversarial attack device for 3D face reconstruction systems, comprising:
[0031] The first module is used to initialize the parameter weights according to the types of output parameters of the 3D face reconstruction network; wherein, the types of output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters and camera parameters;
[0032] The second module is used to attack the 3D face reconstruction model by inputting adversarial samples according to the parameter weights.
[0033] The third module is used to continuously update the parameter weights using an adaptive method;
[0034] The fourth module is used to continuously update the adversarial samples using gradient descent and optimize them through semantic constraints until preset conditions are met, thus completing the attack task on the target image.
[0035] Another aspect of the present invention provides an electronic device, including a processor and a memory;
[0036] The memory is used to store programs;
[0037] The processor executes the program to implement the method described above.
[0038] Another aspect of this invention provides a computer-readable storage medium storing a program that is executed by a processor to implement the methods described above.
[0039] This invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions, causing the computer device to perform the aforementioned method.
[0040] In embodiments of this invention, parameter weights are initialized based on the types of output parameters of the 3D face reconstruction network. These output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters, and camera parameters. Based on these parameter weights, adversarial examples are input to attack the 3D face reconstruction model. The parameter weights are continuously updated using an adaptive method. The adversarial examples are continuously updated using gradient descent and optimized through semantic constraints until preset conditions are met, thus completing the attack on the target image. This invention exhibits high generalization ability, increases the visual concealment of adversarial examples, and improves the robustness of the 3D face reconstruction model. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0042] Figure 1 A flowchart illustrating the overall steps of an embodiment of the present invention;
[0043] Figure 2 The initialization results of noise perturbation, the original image, and an example image of adversarial samples are provided for embodiments of the present invention.
[0044] Figure 3 Example diagrams showing the effects of noise disturbances of different magnitudes;
[0045] Figure 4 Example images of faces reconstructed from optimized adversarial examples and adversarial examples;
[0046] Figure 5 Example diagram illustrating the effect of extending to general attacks. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0048] To address the problems existing in the prior art, one aspect of this invention provides an adaptive parameter adversarial attack method for 3D face reconstruction systems, comprising:
[0049] The parameter weights are initialized according to the types of output parameters of the 3D face reconstruction network; wherein, the types of output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters, and camera parameters;
[0050] Based on the parameter weights, the input adversarial sample attacks the 3D face reconstruction model.
[0051] The parameter weights are continuously updated using an adaptive method;
[0052] The adversarial samples are continuously updated using gradient descent and optimized through semantic constraints until preset conditions are met, thus completing the attack on the target image.
[0053] Optionally, the step of inputting adversarial examples to attack the 3D face reconstruction model according to the parameter weights includes:
[0054] A random noise matrix is generated based on a uniform random distribution, and the adversarial sample is initialized accordingly.
[0055] Based on the output parameters of the adversarial examples and the output parameters of the clean image, the parameter loss is calculated based on the parameter weights to optimize the adversarial examples, thereby misleading the output results of the 3D face reconstruction network.
[0056] Optionally, the step of continuously updating the parameter weights using an adaptive method includes:
[0057] Based on parameter loss-driven adaptive optimization iteration, the optimal parameter weights are found each time, so that the distance between the adversarial example and the clean image increases, thereby reducing the similarity between the output parameters of the adversarial example and the output parameters of the clean image.
[0058] Optionally, the step of continuously updating the parameter weights using an adaptive method includes:
[0059] The parameter weights are adaptively updated using boundary loss and extreme value loss.
[0060] The expression for the boundary loss is as follows:
[0061] E bd = f(x0+∈) - f(x0-∈)
[0062] The expression for the extreme value loss is:
[0063]
[0064] Among them, E bd Represents the boundary loss; f() represents the output of the 3D face reconstruction system; x0 represents the clean image; ∈ represents the maximum perturbation range; E wb Represents extreme value loss; Representative adversarial example; f w () represents the output of the worst adversarial example; f b () represents the output of the current best adversarial example.
[0065] Optionally, in the step of continuously updating the adversarial examples using gradient descent, the update formula for the adversarial examples is:
[0066]
[0067] in, Represents adversarial examples; ∈ represents the maximum perturbation range; T represents the maximum number of iterations; sign represents the sign operation; Representative of adversarial examples Find the gradient; L represents the loss function.
[0068] Optionally, optimizing the adversarial example through semantic constraints includes:
[0069] The adversarial examples are projected into a small-range infinite norm space of the natural image to constrain the numerical range of the generated adversarial examples.
[0070] The expression for the constraint is:
[0071] x = Projection ∞ (x, x0, ∈)
[0072] Where Projection is the projection function; x0 is the natural image corresponding to the perturbed face parameters output after the attack; ∈ is the maximum perturbation range; and x is the constrained adversarial sample.
[0073] Another aspect of this invention provides an adaptive parameter adversarial attack device for 3D face reconstruction systems, comprising:
[0074] The first module is used to initialize the parameter weights according to the types of output parameters of the 3D face reconstruction network; wherein, the types of output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters and camera parameters;
[0075] The second module is used to attack the 3D face reconstruction model by inputting adversarial samples according to the parameter weights.
[0076] The third module is used to continuously update the parameter weights using an adaptive method;
[0077] The fourth module is used to continuously update the adversarial samples using gradient descent and optimize them through semantic constraints until preset conditions are met, thus completing the attack task on the target image.
[0078] Another aspect of the present invention provides an electronic device, including a processor and a memory;
[0079] The memory is used to store programs;
[0080] The processor executes the program to implement the method described above.
[0081] Another aspect of this invention provides a computer-readable storage medium storing a program that is executed by a processor to implement the methods described above.
[0082] This invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions, causing the computer device to perform the aforementioned method.
[0083] The specific implementation process of the present invention will now be described in detail with reference to the accompanying drawings:
[0084] like Figure 1 As shown, this invention discloses an adaptive parameter adversarial attack method for 3D face reconstruction models. It obtains a parameter loss function from the output parameters and parameter weights of the 3D face reconstruction model; then, it attacks the 3D face reconstruction model while adaptively optimizing the parameter weights and adversarial examples; finally, it combines semantic constraints of natural images to increase the visual concealment of the adversarial examples. Specifically, it mainly includes the following steps:
[0085] Step 1: Initialize the parameter weights according to the types of output parameters of the 3D face reconstruction network. The output parameters mainly include shape parameters, expression parameters, and position parameters. Some models also include material parameters, lighting parameters, and camera parameters. The weights of all parameters are initialized to 1.
[0086] Step 2 involves inputting adversarial examples to attack the 3D face reconstruction model, including the following steps:
[0087] Step 2-1: Generate a random noise matrix z of dimension h×w×c based on a random uniform distribution N(0,1), where h, w, and c are the height, width, and channel dimensions of the training image, respectively. Initialize the adversarial sample by overlaying the noise matrix with the original image. An example of the initialization results of the noise matrix and the adversarial sample is shown below. Figure 2 As shown.
[0088] Step 2-2: Based on the output parameters of the adversarial examples and clean images—mainly categorized into three types: shape parameters, expression parameters, and other parameters besides shape and expression—the parameter loss is calculated based on the parameter weights. This optimizes the adversarial examples so that the output parameters of the network after inputting the adversarial examples differ significantly from those after inputting clean images. The optimization objective is:
[0089]
[0090] Where x0 represents the clean input image. Here, f is an adversarial image, f is a 3D face reconstruction network, f(x) represents the network output, σ is noise, and L is the parameter-based 2-norm distance. G() is a fixed operation that changes the output parameters to facial landmark vertices. Since G() is a general and fixed operation across different models, The distance between and G(f(x0)) is equivalent to The distance between f(x0) and f(x0). Therefore, to simplify the attack process—remove this operation, the objective function becomes:
[0091]
[0092] L is defined by the following formula:
[0093] L=a1L o +a2L s +a3L e
[0094] Where L s ,L e L o These represent the losses for the shape parameters, expression parameters, and other parameters extracted from the network output parameters, respectively. a2, a3, and a1 represent the weights of the corresponding parameters.
[0095] Step 3: Continuously update the parameter weights using an adaptive method to increase the effectiveness of the attack. This is achieved through boundary loss E. bd and extreme value loss E wb Adaptive update of parameter weights, where E bd and E wb The calculation formulas are as follows:
[0096] E bd = f(x0+∈) - f(x0-∈)
[0097]
[0098] ∈ represents the maximum perturbation range. and These represent the worst and best adversarial examples, respectively. The adaptive update formula for the parameters is:
[0099]
[0100] Where k is the index of the parameter and i is the number of iterations. E bd The upper and lower bounds of the adversarial examples and the number of iterations determine the basic influence of each parameter, which decreases as the number of iterations increases. E wb The optimization process depends on the best and worst adversarial examples and is handled by parameter-based operations. and As the gap between them gradually widens, the adaptive weights are more likely to be determined by E. wb leading.
[0101] Step 4: Update the adversarial examples using gradient descent to deceive the 3D face reconstruction network. Examples of the effects of noise perturbation with different perturbation magnitudes are shown in the figure below. Figure 3 The formula is expressed as:
[0102]
[0103] Where sign represents the sign-reset operation, and T represents the maximum number of iterations.
[0104] Step 5: Project the adversarial examples onto a small-range infinite norm space of the natural image to constrain the numerical range of the generated adversarial examples, as expressed by the formula:
[0105] x = Projection ∞ (x, x0, ∈)
[0106] Where Projection is the projection function, x0 is the natural image corresponding to the perturbed face parameters output after the attack, and ∈ is a small fixed value used to constrain the numerical range of the perturbed image. Example images of the optimized adversarial sample and the reconstructed face from the adversarial sample are shown below. Figure 4 As shown.
[0107] Step 6: Iteratively execute steps 3 to 5 based on the deep learning optimizer to find the optimal gradient descent direction of the loss function and update the adversarial examples until the stopping condition is met, and then obtain the final result x.
[0108] Step 7: Extend the specific image attack to a general attack. Calculate a general perturbation using images from the entire dataset, and then superimpose the perturbation onto clean images. This approach succeeds on most images. Figure 5 This is an example image illustrating the effects of a general attack.
[0109] In summary, this invention proposes an adaptive parameter attack algorithm. It derives a parameter loss function from the output parameters and weights of a 3D face reconstruction model; then, it attacks the 3D face reconstruction model while adaptively optimizing the parameter weights and adversarial examples; finally, it incorporates semantic constraints from natural images to enhance the visual concealment of the adversarial examples. This invention, by leveraging the characteristics of the 3D face reconstruction network output, exhibits stronger attack capabilities than directly applying iterative gradient descent under 2D tasks to the 3D face reconstruction model. Furthermore, during the adaptive optimization process, the parameter weights are controlled by a result-driven strategy and normalized after each update, resulting in better generalization ability than manually setting the weight parameters.
[0110] In some alternative embodiments, the functions / operations mentioned in the block diagrams may not occur in the order shown in the operation diagrams. For example, depending on the functions / operations involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order. Furthermore, the embodiments presented and described in the flowcharts of this invention are provided by way of example to provide a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logic flows presented herein. Alternative embodiments are contemplated in which the order of various operations is altered and sub-operations described as part of a larger operation are executed independently.
[0111] Furthermore, although the invention has been described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the described functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the invention. Rather, given the properties, functions, and internal relationships of the various functional modules in the apparatus disclosed herein, the actual implementation of the module will be understood within the scope of conventional skill of an engineer. Therefore, those skilled in the art can implement the invention as set forth in the claims using ordinary techniques without excessive experimentation. It is also understood that the specific concepts disclosed are merely illustrative and not intended to limit the scope of the invention, which is determined by the full scope of the appended claims and their equivalents.
[0112] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0113] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0114] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0115] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0116] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0117] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
[0118] The above is a detailed description of the preferred embodiments of the present invention, but the present invention is not limited to the embodiments described. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of the present invention, and these equivalent modifications or substitutions are all included within the scope defined by the claims of this application.
Claims
1. An adaptive parameter adversarial attack method for 3D face reconstruction systems, characterized in that, include: The parameter weights are initialized according to the types of output parameters of the 3D face reconstruction network; wherein, the types of output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters, and camera parameters; Based on the parameter weights, the input adversarial sample attacks the 3D face reconstruction model. The parameter weights are continuously updated using an adaptive method; The adversarial sample is continuously updated using gradient descent and optimized using semantic constraints until a preset condition is met, thus completing the attack on the target image. The optimization of the adversarial example through semantic constraints includes: The adversarial examples are projected into a small-range infinite norm space of the natural image to constrain the numerical range of the generated adversarial examples. The expression for the constraint is: Wherein, Projection is the projection function; Represents a clean image; This represents the maximum disturbance range. These are constrained adversarial examples.
2. The adaptive parameter adversarial attack method for a 3D face reconstruction system according to claim 1, characterized in that, The step of attacking the 3D face reconstruction model by inputting adversarial examples based on the parameter weights includes: A random noise matrix is generated based on a uniform random distribution, and the adversarial sample is initialized accordingly. Based on the output parameters of the adversarial examples and the output parameters of the clean image, the parameter loss is calculated based on the parameter weights to optimize the adversarial examples, thereby misleading the output results of the 3D face reconstruction network.
3. The adaptive parameter adversarial attack method for a 3D face reconstruction system according to claim 1, characterized in that, The method of continuously updating the parameter weights using an adaptive approach includes: Based on parameter loss-driven adaptive optimization iteration, the optimal parameter weights are found each time, so that the distance between the adversarial example and the clean image increases, thereby reducing the similarity between the output parameters of the adversarial example and the output parameters of the clean image.
4. The adaptive parameter adversarial attack method for a 3D face reconstruction system according to claim 1, characterized in that, The method of continuously updating the parameter weights using an adaptive approach includes: The parameter weights are adaptively updated using boundary loss and extreme value loss. The expression for the boundary loss is as follows: The expression for the extreme value loss is: in, Represents boundary loss; This represents the output of a 3D face reconstruction system. Represents a clean image; Represents the maximum disturbance range; Represents extreme value loss; Representative adversarial examples; The output represents the worst adversarial example currently available; The output represents the current best adversarial example.
5. The adaptive parameter adversarial attack method for a 3D face reconstruction system according to claim 1, characterized in that, In the step of continuously updating the adversarial examples using gradient descent, the update formula for the adversarial examples is: in, Representative adversarial examples; Represents the maximum disturbance range; Represents the maximum number of iterations; Represents the sign-removing operation; Representative of adversarial examples Find the gradient; This represents the loss function.
6. An apparatus for implementing an adaptive parameter adversarial attack method for a 3D face reconstruction system as described in any one of claims 1-5, characterized in that, include: The first module is used to initialize the parameter weights according to the types of output parameters of the 3D face reconstruction network; wherein, the types of output parameters include shape parameters, expression parameters, position parameters, material parameters, lighting parameters and camera parameters; The second module is used to attack the 3D face reconstruction model by inputting adversarial samples according to the parameter weights. The third module is used to continuously update the parameter weights using an adaptive method; The fourth module is used to continuously update the adversarial samples using gradient descent and optimize them through semantic constraints until preset conditions are met, thus completing the attack task on the target image.
7. An electronic device, characterized in that, Including the processor and memory; The memory is used to store programs; The processor executes the program to implement the method as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The storage medium stores a program that is executed by a processor to implement the method as described in any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Face image reconstruction method based on identity information
CN110910310A
Three-dimensional face reconstruction method and device, electronic equipment and storage medium
CN114187407A