Method and apparatus for detecting security of image recognition model
Patent Information
- Application Number
- CN202310459621.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-24
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2043-04-24
AI Technical Summary
[0025]The security detection method for image recognition models provided in this specification includes: acquiring an initial detection image; processing the initial detection image based on preset adjustment rules to generate at least one target detection image; inputting each target detection image and the initial detection image into the image recognition model respectively to obtain the image recognition result corresponding to each target detection image; and determining that the image recognition model has a security problem if there is a successful recognition result in the image recognition result. The method provided in this specification can process the initial detection image according to multiple adjustment rules, generating multiple numbers of target detection images from multiple dimensions. Multiple-dimensional target detection images can verify the security breadth of the image recognition model, and multiple numbers of target detection images can verify the security depth of the image recognition model, enriching the ways to verify the security of image recognition models.
Smart Images

Figure CN116434312B_ABST
Abstract
Description
Technical Field
[0001] The embodiments in this specification relate to the field of image recognition technology, and in particular to a method for security detection of image recognition models. Background Technology
[0002] With the continuous development of computer technology, technologies such as artificial intelligence and computer vision have also developed rapidly. Among them, image recognition is an important topic. In image recognition scenarios, the problem of comparing whether two images are the same is often encountered. For example, in the face recognition scenario, the currently captured face is compared with the pre-saved face to determine whether the current user is the real user.
[0003] Currently, attackers often use various methods to attack image comparison applications in order to bypass their verification. For example, in the case of facial recognition, they attack the facial recognition model in various ways to achieve a realistic effect. How to simulate the attacker's behavior and verify the robustness of the image comparison application has become an urgent problem for technology developers to solve. Summary of the Invention
[0004] In view of this, embodiments of this specification provide a security detection method for image recognition models. One or more embodiments of this specification also relate to a security detection device for image recognition models, a computing device, a computer-readable storage medium, and a computer program, to address the technical deficiencies existing in the prior art.
[0005] According to a first aspect of the embodiments of this specification, a security detection method for an image recognition model is provided, comprising:
[0006] Acquire the initial detection image;
[0007] The initial detection image is processed based on preset adjustment rules to generate at least one target detection image;
[0008] Each target detection image and the initial detection image are input into the image recognition model to obtain the image recognition result corresponding to each target detection image;
[0009] If the image recognition results show a successful recognition, it is determined that the image recognition model has a security issue.
[0010] According to a second aspect of the embodiments of this specification, a security detection method for a face recognition model is provided, comprising:
[0011] Obtain the initial face image;
[0012] The initial face image is processed based on preset adjustment rules to generate at least one target face image;
[0013] Each target face image and the initial face image are input into the face recognition model to obtain the face recognition result corresponding to each target face image;
[0014] If a face recognition result shows a successful recognition, it is determined that the face recognition model has a security issue.
[0015] According to a third aspect of the embodiments of this specification, a security detection device for an image recognition model is provided, comprising:
[0016] The acquisition module is configured to acquire the initial detection image;
[0017] The generation module is configured to process the initial detection image based on a preset adjustment rule to generate at least one target detection image;
[0018] The recognition module is configured to input each target detection image and the initial detection image into the image recognition model to obtain the image recognition result corresponding to each target detection image;
[0019] The determination module is configured to determine that the image recognition model has a security problem if the image recognition result shows a successful recognition.
[0020] According to a fourth aspect of the embodiments of this specification, a computing device is provided, comprising:
[0021] Memory and processor;
[0022] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, they implement the steps of the security detection method of the above-described image recognition model.
[0023] According to a fifth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions, which, when executed by a processor, implement the steps of the security detection method of the image recognition model described above.
[0024] According to a sixth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the security detection method of the image recognition model described above.
[0025] The security detection method for image recognition models provided in this specification includes: acquiring an initial detection image; processing the initial detection image based on preset adjustment rules to generate at least one target detection image; inputting each target detection image and the initial detection image into the image recognition model respectively to obtain the image recognition result corresponding to each target detection image; and determining that the image recognition model has a security problem if there is a successful recognition result in the image recognition result. The method provided in this specification can process the initial detection image according to multiple adjustment rules, generating multiple numbers of target detection images from multiple dimensions. Multiple-dimensional target detection images can verify the security breadth of the image recognition model, and multiple numbers of target detection images can verify the security depth of the image recognition model, enriching the ways to verify the security of image recognition models. Attached Figure Description
[0026] Figure 1 This is a flowchart illustrating a security detection method for an image recognition model provided in one embodiment of this specification;
[0027] Figure 2 This is a schematic diagram of image processing for a face authentication scenario provided in one embodiment of this specification;
[0028] Figure 3 This is a flowchart illustrating the processing procedure of a security detection method for an image recognition model in a face authentication scenario, provided in one embodiment of this specification.
[0029] Figure 4 This is a flowchart of a security detection method for a face recognition model provided in one embodiment of this specification;
[0030] Figure 5 This is a schematic diagram of the structure of a security detection device for an image recognition model provided in one embodiment of this specification;
[0031] Figure 6 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation
[0032] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0033] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0034] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0035] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this manual are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0036] First, the terms and concepts used in one or more embodiments of this specification will be explained.
[0037] Robustness: The ability of software to handle inputs that are not in accordance with specifications.
[0038] Moiré patterns are high-frequency interference stripes that appear on the photosensitive components of devices such as digital cameras or scanners. They are irregular, high-frequency stripes that cause images to appear colorful.
[0039] Face retouching: The process of using image editing tools to process original images containing human faces.
[0040] With the continuous development of computer technology, technologies such as artificial intelligence and computer vision have also developed rapidly. Among them, image recognition is an important topic. In image recognition scenarios, the problem of comparing whether two images are the same is often encountered. For example, in the face recognition scenario, the currently captured face is compared with the pre-saved face to determine whether the current user is the real user.
[0041] Currently, attackers often use various methods to attack image comparison applications, thereby bypassing their verification. For example, in facial recognition scenarios, attackers use various methods to attack facial recognition models, achieving a realistic effect. Attackers currently use methods such as screen capture, facial retouching, and AI (Artificial Intelligence) face swapping to attack existing facial recognition models. There is currently no system or tool that can evaluate the robustness and security of facial recognition models (facial recognition application programming interfaces).
[0042] Based on this, this specification provides a security detection method for image recognition models. This specification also relates to a security detection device for image recognition models, a computing device, and a computer-readable storage medium, which will be described in detail in the following embodiments.
[0043] See Figure 1 , Figure 1 A flowchart of a security detection method for an image recognition model according to an embodiment of this specification is shown, which specifically includes the following steps.
[0044] Step 102: Obtain the initial detection image.
[0045] The methods provided in this manual are applicable to terminal devices, which may be desktop computers, laptops, smart terminals, servers, cloud servers, distributed servers, etc. This manual does not limit the specific form of the terminal device; the actual application shall prevail.
[0046] The initial detection image specifically refers to the original image that needs to be detected. For example, in a face recognition scenario, the initial detection image is the original image of the user captured by the image acquisition device; in a target tracking scenario, the initial detection image is the original image that includes the target being tracked; and in an image comparison scenario, the initial detection image is the original image that is being compared.
[0047] The security detection method for the image recognition model provided in this manual requires generating multiple similar images based on an initial detection image. The image recognition model then identifies whether each similar image is identical to the initial detection image. If the model determines that the similar image is the same as the initial detection image, it indicates a security vulnerability in the image recognition model, making it susceptible to attacks using image manipulation techniques. Taking facial recognition as an example, the system pre-saves the user's real image (i.e., the initial detection image). Malicious attackers attempting to compromise the facial recognition system might use methods such as screen capture or image editing to simulate a real user. The facial recognition system needs to identify these altered images to protect the user's information security. Obtaining the initial detection image provides the data foundation for subsequent image processing and recognition.
[0048] Step 104: Process the initial detection image based on preset adjustment rules to generate at least one target detection image.
[0049] Among them, the preset adjustment rules are specific rules for adjusting the initial detection image. In practical applications, attackers may use various attack methods, such as screen capture, image retouching, modeling and screenshotting. In the method provided in this specification, preset adjustment rules are created based on various attack methods, and the initial detection image is processed based on the preset adjustment rules to generate the target detection image corresponding to the initial detection image.
[0050] The target detection image specifically refers to the image obtained after processing the initial detection image. In the embodiments provided in this specification, the target detection image is used to simulate an image created by an attacker. It should be noted that in practical applications, attackers can employ various attack methods. To better test the robustness of the image recognition model, multiple target detection images are generated during the generation process, and the security of the image recognition model is verified through a large amount of target detection data.
[0051] In practical applications, there are various preset adjustment rules. Based on these rules, the initial detection image is processed to generate at least one target detection image, including:
[0052] S1040. Extract the image editing rules, model rules, and artificial intelligence rules from the preset adjustment rules.
[0053] Among them, the image retouching rules specifically refer to the rules for adjusting the initial detection image, the model rules specifically refer to the rules for generating a corresponding 3D model based on the initial detection image and generating an image based on the 3D model, and the artificial intelligence rules specifically refer to the rules for generating an adjusted image corresponding to the initial detection image based on AI (Artificial Intelligence) technology.
[0054] In practical applications, the preset adjustment rules will include at least one of the three rules mentioned above. To ensure the accuracy of security detection by the image recognition model, it is preferable to include all three rules. After determining the adjustment rules, the initial detection image should be adjusted accordingly based on these rules.
[0055] S1042. Process the initial detection image based on the image retouching rules to generate an image retouching detection image.
[0056] Image retouching rules can be understood as image retouching operations performed on the initial detection image, such as adjusting the initial detection image using image retouching software.
[0057] In practical applications, there are many dimensions to adjust for an initial detection image. Therefore, the initial detection image is processed according to the aforementioned retouching rules to generate a retouched detection image, including:
[0058] Add image interference patterns to the initial detection image to obtain the first retouched detection image;
[0059] Add mirror interference information to the initial detection image to obtain a second retouched detection image;
[0060] Add an image interference box to the initial detection image to obtain a third retouched detection image;
[0061] The target object in the initial detection image is retouched to obtain a fourth retouched detection image;
[0062] Add distortion interference information to the target object in the initial detection image to obtain the fifth retouched detection image;
[0063] The initial detection image is color-adjusted to obtain the sixth retouched detection image;
[0064] An image retouching detection image is generated based on at least one of the first image retouching detection image, the second image retouching detection image, the third image retouching detection image, the fourth image retouching detection image, the fifth image retouching detection image, and the sixth image retouching detection image.
[0065] Specifically, image interference patterns can be understood as moiré patterns, which are high-frequency interference stripes appearing on the photosensitive components of devices such as digital cameras or scanners. In practical applications, attackers sometimes simulate real users by photographing images of screens. When photographing a screen, the captured image will have moiré patterns. This situation can be simulated by adding image interference patterns to the initial detection image. Furthermore, moiré patterns are irregular stripes. In the method provided in this specification, moiré pattern layers with different transparency and shapes can also be added to the original detection image to generate at least one first retouched detection image. The first retouched detection image refers to the image with added image interference patterns.
[0066] Mirror interference information specifically refers to adding a specular reflection effect to the initial detection image. In practical applications, when an attacker flips a screen, there may be reflected light. By adding mirror interference information, the situation of an attacker flipping the screen can be simulated, increasing the stability of the image recognition model's security verification. By adding mirror interference information to the initial detection image, a corresponding second-edited detection image can be obtained. Other image layers with different transparency can be added to the initial detection image to simulate specular reflection, generating at least one second-edited detection image. The second-edited detection image is the image with the added mirror interference information.
[0067] Image interference boxes are also used to simulate the situation of an attacker taking pictures of the screen. When an attacker takes pictures of the initial detection image, they are likely to capture the screen's border. By adding right-angled or flat-angled borders such as black, silver, white, and gray to the initial detection image, the screen's border is simulated, thereby simulating the situation of taking pictures of the screen and generating at least one third-edited detection image. The third-edited detection image refers to the image with added image interference information.
[0068] In practical applications, attackers not only photograph the screen but also generate new images through image retouching. Specifically, they retouch the target object in the initial detection image. The target object refers to the object to be identified during image recognition; for example, in a face recognition model, the target object is the face; in an object tracking model, the target object is the object being tracked. Retouching the initial detection image specifically involves adjusting some pixels of the target object to simulate the retouching effects of image editing software. Through this retouching of the target object, at least one fourth retouched detection image is generated.
[0069] Furthermore, distortion interference information can be added to the target object, such as stretching or compressing it to create distortion, simulating the effect of software that makes static images appear animated. Currently, some software can give static images dynamic effects; for example, a static face image can simulate actions like opening the mouth, tilting the head back, and blinking. This type of software processing will cause varying degrees of distortion in the image, resulting in a noticeable distorted shape of the displayed target object. By adding distortion interference information to the target object, at least one fifth-level retouching detection image can be generated.
[0070] The method provided in this specification also includes a color adjustment process, which adjusts the color of the initial detection image, for example, by converting a color image to a black and white image. In practical applications, black and white images can hide more information and are a common attack method used by attackers. By adjusting the color of the initial detection image, at least one sixth retouched detection image is generated.
[0071] After the above processing, multiple first retouched detection images, second retouched detection images, third retouched detection images, fourth retouched detection images, fifth retouched detection images, and sixth retouched detection images can be obtained. At least one of them can be selected as the final retouched detection image. In order to further improve the accuracy of the image recognition model verification, preferably, all generated images are used as retouched detection images.
[0072] S1044. Process the initial detection image based on the model rules to generate a model detection image.
[0073] The model rule specifically refers to the process of generating a corresponding 3D model based on the initial detection image, and then generating a model detection image through the 3D model.
[0074] Specifically, the initial detection image is processed based on the model rules to generate a model detection image, including:
[0075] Identify the target object in the initial detection image;
[0076] The target object is modeled based on a 3D modeling model to obtain the target 3D object;
[0077] Determine at least one three-dimensional viewpoint and capture the model detection image corresponding to the target three-dimensional object under each three-dimensional viewpoint.
[0078] The method provided in this specification verifies the security of the image recognition model. Furthermore, the image recognition model identifies whether the objects in two images are the same. For example, in a face recognition scenario, it identifies whether the faces in two images are the same person; in a target tracking scenario, it identifies whether the targets in two images are the same target.
[0079] Based on this, the model processing rules first need to identify the target object in the initial detection image. As described in the steps above, the target object specifically refers to the object that needs to be compared during the image recognition process, such as a face in a face recognition scenario, a target in a target tracking scenario, and so on.
[0080] After identifying the target object, which is currently two-dimensional, a three-dimensional model can be created based on this model to obtain the corresponding three-dimensional object. For example, in a face recognition scenario, if the target object in the initial detection image is identified as a face, a three-dimensional model can be created based on the three-dimensional model to obtain the head model corresponding to that face.
[0081] After obtaining the target 3D object, it can be observed from different 3D perspectives, and model detection images corresponding to the target 3D object can be captured from each perspective. In practical applications, the number of model detection images is related to the number of 3D perspectives.
[0082] S1046. Process the initial detection image based on the artificial intelligence rules to generate an artificial intelligence detection image.
[0083] Artificial intelligence processing rules specifically refer to the rules for generating adjusted images corresponding to the initial detection images based on AI (Artificial Intelligence) technology. With the development of AI technology, AI face-swapping applications are becoming increasingly common. For example, given an original face 'a', any face in a video containing other faces can be converted into face 'a', thus achieving the effect of AI face-swapping.
[0084] Specifically, the initial detection image is processed based on the aforementioned artificial intelligence rules to generate an artificial intelligence detection image, including:
[0085] Identify the target object in the initial detection image;
[0086] Obtain at least one reference object;
[0087] An artificial intelligence detection image is generated by replacing the target object in the initial detection image with each reference object.
[0088] The process of identifying the target object in the initial detection image follows the same steps as described above, and can be achieved through image recognition, image matting, or other methods. The reference object specifically refers to the object that needs to be replaced. For example, in AI face swapping, a video is acquired, faces in the video are identified, and these faces are used as the replacement faces. The target object's face is then used to replace the face in the video, thus obtaining the AI-detected image. For instance, if the target object is face 'a', and the reference object in the video is face 'b', face 'a' is used to replace face 'b' in the video, achieving the effect of face 'a' in the video. Then, by taking a screenshot, an image containing face 'a' can be obtained from the modified video.
[0089] S1048. The image being edited, the image being detected by the model, and the image being detected by the artificial intelligence are determined as the target image being detected.
[0090] After the above steps, the obtained image detection images, model detection images, and artificial intelligence detection images can be used to generate target detection images. In practical applications, target detection images can be generated based on one, two, or more of these images. To better verify the verification effect of the image recognition model, it is preferable to use images generated by various types of rules as target detection images. By using multiple types of rules, the dimensions of the image recognition model's resistance to attacks can be verified, and by using multiple target detection images, the stability of the image recognition model's resistance to attacks can be verified.
[0091] Step 106: Input each target detection image and the initial detection image into the image recognition model to obtain the image recognition result corresponding to each target detection image.
[0092] After obtaining at least one target detection image, the security of the target recognition model can be tested using the target detection image and the initial detection image. This involves simulating an attack on the image recognition model using the target detection image. Specifically, each target detection image and the initial detection image are input into the image recognition model, which then processes both to obtain the image recognition result for each target detection image.
[0093] Specifically, each target detection image and the initial detection image are input into the image recognition model to obtain the image recognition result corresponding to each target detection image, including:
[0094] Identify the target detection image to be processed from each target detection image;
[0095] The target detection image to be processed and the initial detection image are input into the image recognition model;
[0096] Obtain the image recognition result returned by the image recognition model, wherein the image recognition result includes recognition success or recognition failure.
[0097] In the embodiments provided in this specification, a single target detection image is used as an example for explanation. The same processing is performed on each target detection image. Specifically, one target detection image to be processed is first selected from each target detection image. The target detection image to be processed and the initial detection image are simultaneously input into the image recognition model. The image recognition model extracts the first image features of the target detection image to be processed and the second image features of the initial detection image. The first image features are then encoded to obtain the first image encoded features, and the second image features are encoded to obtain the second image encoded features. The first image encoded features and the second image encoded features are then compared to calculate their similarity. Finally, the image recognition result is output through a binary classification model.
[0098] Obtain the image recognition results output by the image recognition model. Specifically, the image recognition results for each target detection image include recognition success or recognition failure. Recognition success means that the image recognition model considers the target detection image to be a successful match with the initial detection image after recognition, while recognition failure means that the image recognition model considers the target detection image to be a failed match with the initial detection image after recognition.
[0099] Step 108: If the image recognition results show successful recognition, it is determined that the image recognition model has a security problem.
[0100] After performing the above image recognition processing on each target detection image, the image recognition result for each target detection image is obtained. The method provided in this specification aims to address the security issue of the detection image recognition model. The target detection image simulates the attack behavior of an attacker. Therefore, when there is a successful recognition in the image recognition result, it indicates that the simulated attacker behavior has successfully attacked the image recognition model, meaning that the image recognition model still has security vulnerabilities. For example, the image recognition model may incorrectly recognize disguised images. Therefore, if there is a successful recognition in the image recognition result, it can be determined that the image recognition model has a security problem.
[0101] In one specific embodiment provided in the embodiments of this specification, the method further includes:
[0102] A detection report corresponding to the security issue is generated based on the image recognition results.
[0103] Furthermore, if a security issue is identified in the image recognition model, a detection report needs to be generated based on the image recognition results to pinpoint where the model needs improvement. After generating the report, it should be provided to the image recognition model's developers so they can make targeted improvements.
[0104] Specifically, a detection report corresponding to the security issue is generated based on the image recognition results, including:
[0105] The image recognition result is determined to be a successfully recognized target detection image;
[0106] Determine the target adjustment rules corresponding to the target detection image to be processed;
[0107] Based on the target adjustment rules, a detection report corresponding to the security issue is generated.
[0108] During the generation of the detection report, it is necessary to specifically explain the rules that caused the problem. Therefore, it is first necessary to determine that the image recognition result is a successfully recognized target detection image, and then determine the target adjustment rule corresponding to the target detection image. This target adjustment rule can be a pre-set adjustment rule such as image retouching rules, model rules, or artificial intelligence rules, or it can be a more specific image adjustment rule, such as image interference patterns, image interference boxes, etc. After determining the target adjustment rule, a detection report corresponding to the security issue is generated based on the target adjustment rule. If the image recognition result of the target detection image with image interference boxes is successful, it can be determined that the image with added image interference boxes is easy to pass the security authentication of the image recognition model, and a detection report of "the image corresponding to the image interference box has a security risk" is issued. After seeing the detection report, technicians can add corresponding security authentication mechanisms to the image corresponding to the image interference boxes.
[0109] The security detection method for image recognition models provided in this specification includes: acquiring an initial detection image; processing the initial detection image based on preset adjustment rules to generate at least one target detection image; inputting each target detection image and the initial detection image into the image recognition model respectively to obtain the image recognition result corresponding to each target detection image; and determining that the image recognition model has a security problem if there is a successful recognition result in the image recognition result. The method provided in this specification can process the initial detection image according to multiple adjustment rules, generating multiple numbers of target detection images from multiple dimensions. Multiple-dimensional target detection images can verify the security breadth of the image recognition model, and multiple numbers of target detection images can verify the security depth of the image recognition model, enriching the ways to verify the security of image recognition models.
[0110] The following is in conjunction with the appendix Figure 2 and Figure 3 Taking the application of the image recognition model security detection method provided in this specification in a face authentication scenario as an example, the security detection method of the image recognition model will be further explained. Among them, Figure 2 This document illustrates an image processing diagram of a face authentication scenario provided in one embodiment of this specification. In this embodiment, the robustness of a face comparison API is tested. The API (Application Programming Interface) specifically refers to a face comparison application programming interface. Users upload images to the server through this face comparison API. The server's face comparison model, based on this face comparison API, can identify whether the image contains the same person and return the comparison result. Taking user A as an example, the initial face image is user A's face photo 'a'. Face photo 'a' is processed through image interference patterns, mirror interference information, image interference boxes, retouching, distortion interference information, color adjustment, 3D modeling tools, and AI face-swapping tools to obtain multiple target face images. Each target face image is then input into a face comparison API for face comparison. The face comparison API returns the face comparison results. If there are any "successful comparison" results, it indicates that the face comparison API has a security problem. If all comparison results are "failed comparison", it means that the face comparison API has passed the security test.
[0111] Figure 3 The flowchart illustrates the processing steps of the security detection method for the image recognition model in a face authentication scenario provided in the embodiments of this specification.
[0112] Step 302: Obtain the initial face image.
[0113] Step 304: Obtain image editing rules, model rules, and artificial intelligence rules.
[0114] Step 306: Process the initial face image based on the image retouching rules to obtain the retouched face image.
[0115] Step 308: Obtain the initial face image based on model rules to obtain multiple model face images generated by the 3D modeling tool.
[0116] Step 310: Obtain the initial face image based on artificial intelligence rules, and obtain multiple AI face images generated by the AI face-swapping tool.
[0117] Step 312: Input the edited face image, model face image, AI face image and the initial face image into the face comparison API.
[0118] Step 314: Obtain each recognition result returned by the face comparison API.
[0119] Step 316: Determine if there is a successful alignment result. If yes, proceed to step 318; otherwise, proceed to step 320.
[0120] Step 318: Determine if the face comparison API has a security issue and generate a detection report.
[0121] Step 320: Determine that the face comparison AIP passes the security check.
[0122] The security detection method for the image recognition model provided in this manual is applied to test the security of face comparison APIs. Using the method provided in this manual, the initial face image can be processed according to multiple adjustment rules to generate multiple target face images from multiple dimensions. The multiple target face images can verify the security breadth of the face comparison API, and the multiple target face images can verify the security depth of the face comparison API, thus enriching the ways to verify the security of face comparison APIs.
[0123] This specification provides a specific implementation method and also offers a security detection method for a face recognition model. Figure 4 This specification illustrates a flowchart of a security detection method for a face recognition model provided in one embodiment, which specifically includes:
[0124] Step 402: Obtain the initial face image.
[0125] Step 404: Process the initial face image based on preset adjustment rules to generate at least one target face image.
[0126] Step 406: Input each target face image and the initial face image into the face recognition model to obtain the face recognition result corresponding to each target face image.
[0127] Step 408: If the face recognition result shows a successful recognition, it is determined that the face recognition model has a security problem.
[0128] Optionally, the method further includes:
[0129] A detection report corresponding to the security issue is generated based on the facial recognition results.
[0130] Optionally, a detection report corresponding to the security issue is generated based on the facial recognition results, including:
[0131] The face recognition result is determined to be a successfully recognized target face image;
[0132] Determine the target adjustment rules corresponding to the target face image to be processed;
[0133] Based on the target adjustment rules, a detection report corresponding to the security issue is generated.
[0134] Optionally, the initial face image is processed based on preset adjustment rules to generate at least one target face image, including:
[0135] Extract the image editing rules, model rules, and artificial intelligence rules from the preset adjustment rules;
[0136] The initial face image is processed based on the aforementioned retouching rules to generate a retouched face image;
[0137] The initial face image is processed based on the model rules to generate a model face image;
[0138] The initial face image is processed based on the aforementioned artificial intelligence rules to generate an artificial intelligence face image;
[0139] The edited face image, the model face image, and the artificial intelligence face image are identified as the target face image.
[0140] Optionally, the initial face image is processed based on the retouching rules to generate a retouched face image, including:
[0141] Add image interference patterns to the initial face image to obtain the first retouched face image;
[0142] Add mirror interference information to the initial face image to obtain a second retouched face image;
[0143] Add an image interference box to the initial face image to obtain a third retouched face image;
[0144] The target face in the initial face image is retouched to obtain a fourth retouched face image;
[0145] Add distortion interference information to the target face in the initial face image to obtain the fifth retouched face image;
[0146] The initial face image is color-adjusted to obtain the sixth retouched face image;
[0147] An edited face image is generated based on at least one of the first edited face image, the second edited face image, the third edited face image, the fourth edited face image, the fifth edited face image, and the sixth edited face image.
[0148] Optionally, the initial face image is processed based on the model rules to generate a model face image, including:
[0149] Identify the target face in the initial detection image;
[0150] The target human face is modeled based on the 3D modeling model to obtain the target 3D human head;
[0151] Determine at least one three-dimensional viewpoint and capture the model face image corresponding to the target three-dimensional human head from each three-dimensional viewpoint.
[0152] Optionally, the initial face image is processed based on the artificial intelligence rules to generate an artificial intelligence face image, including:
[0153] Identify the target face in the initial face image;
[0154] Obtain at least one reference face;
[0155] An AI-generated face image is generated by replacing the target face in the initial face image with each reference face.
[0156] The security testing method for face recognition models provided in this specification is used to test the security of face recognition models. Using the method provided in this specification, the initial face image can be processed according to multiple adjustment rules to generate multiple target face images from multiple dimensions. The multiple target face images can verify the security breadth of the face recognition model, and the multiple target face images can verify the security depth of the face recognition model, thus enriching the ways to verify the security of face recognition models.
[0157] Corresponding to the above method embodiments, this specification also provides embodiments of a security detection device for image recognition models. Figure 5 This specification shows a schematic diagram of the structure of a security detection device for an image recognition model provided in one embodiment.
[0158] like Figure 5 As shown, the device includes:
[0159] The acquisition module 502 is configured to acquire the initial detection image;
[0160] The generation module 504 is configured to process the initial detection image based on a preset adjustment rule to generate at least one target detection image;
[0161] The recognition module 506 is configured to input each target detection image and the initial detection image into the image recognition model to obtain the image recognition result corresponding to each target detection image;
[0162] The determination module 508 is configured to determine that the image recognition model has a security problem if the image recognition result shows a successful recognition.
[0163] Optionally, the device further includes:
[0164] The reporting module is configured to generate a detection report corresponding to the security issue based on the image recognition results.
[0165] Optionally, the reporting module is further configured to:
[0166] The image recognition result is determined to be a successfully recognized target detection image;
[0167] Determine the target adjustment rules corresponding to the target detection image to be processed;
[0168] Based on the target adjustment rules, a detection report corresponding to the security issue is generated.
[0169] Optionally, the generation module 504 is further configured to:
[0170] Extract the image editing rules, model rules, and artificial intelligence rules from the preset adjustment rules;
[0171] The initial detection image is processed based on the image retouching rules to generate a retouched detection image;
[0172] The initial detection image is processed based on the model rules to generate a model detection image;
[0173] The initial detection image is processed based on the aforementioned artificial intelligence rules to generate an artificial intelligence detection image;
[0174] The image being processed, the image being detected by the model, and the image being detected by the artificial intelligence are identified as the target image.
[0175] Optionally, the generation module 504 is further configured to:
[0176] Add image interference patterns to the initial detection image to obtain the first retouched detection image;
[0177] Add mirror interference information to the initial detection image to obtain a second retouched detection image;
[0178] Add an image interference box to the initial detection image to obtain a third retouched detection image;
[0179] The target object in the initial detection image is retouched to obtain a fourth retouched detection image;
[0180] Add distortion interference information to the target object in the initial detection image to obtain the fifth retouched detection image;
[0181] The initial detection image is color-adjusted to obtain the sixth retouched detection image;
[0182] An image retouching detection image is generated based on at least one of the first image retouching detection image, the second image retouching detection image, the third image retouching detection image, the fourth image retouching detection image, the fifth image retouching detection image, and the sixth image retouching detection image.
[0183] Optionally, the generation module 504 is further configured to:
[0184] Identify the target object in the initial detection image;
[0185] The target object is modeled based on a 3D modeling model to obtain the target 3D object;
[0186] Determine at least one three-dimensional viewpoint and capture the model detection image corresponding to the target three-dimensional object under each three-dimensional viewpoint.
[0187] Optionally, the generation module 504 is further configured to:
[0188] Identify the target object in the initial detection image;
[0189] Obtain at least one reference object;
[0190] An artificial intelligence detection image is generated by replacing the target object in the initial detection image with each reference object.
[0191] Optionally, the identification module 506 is further configured to:
[0192] Identify the target detection image to be processed from each target detection image;
[0193] The target detection image to be processed and the initial detection image are input into the image recognition model;
[0194] Obtain the image recognition result returned by the image recognition model, wherein the image recognition result includes recognition success or recognition failure.
[0195] The security detection device for the image recognition model provided in this specification includes: acquiring an initial detection image; processing the initial detection image based on preset adjustment rules to generate at least one target detection image; inputting each target detection image and the initial detection image into the image recognition model respectively to obtain the image recognition result corresponding to each target detection image; and determining that the image recognition model has a security problem if there is a successful recognition result in the image recognition result. Using the device provided in this specification, the initial detection image can be processed according to multiple adjustment rules to generate multiple numbers of target detection images from multiple dimensions. Multiple-dimensional target detection images can verify the security breadth of the image recognition model, and multiple numbers of target detection images can verify the security depth of the image recognition model, enriching the methods for verifying the security of the image recognition model.
[0196] The above is a schematic scheme of a security detection device for an image recognition model according to this embodiment. It should be noted that the technical solution of this security detection device for an image recognition model and the technical solution of the security detection method for an image recognition model described above belong to the same concept. For details not described in detail in the technical solution of the security detection device for an image recognition model, please refer to the description of the technical solution of the security detection method for an image recognition model described above.
[0197] Figure 6 A structural block diagram of a computing device 600 according to one embodiment of this specification is shown. The components of the computing device 600 include, but are not limited to, a memory 610 and a processor 620. The processor 620 is connected to the memory 610 via a bus 630, and a database 650 is used to store data.
[0198] The computing device 600 also includes an access device 640, which enables the computing device 600 to communicate via one or more networks 660. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 640 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC) interface.
[0199] In one embodiment of this specification, the above-described components of the computing device 600 and Figure 6 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 6 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.
[0200] The computing device 600 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 600 can also be a mobile or stationary server.
[0201] The processor 620 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-described data processing method. The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above-described security detection method for image recognition models belong to the same concept. Details not described in detail in the technical solution of the computing device can be found in the description of the technical solution of the above-described security detection method for image recognition models.
[0202] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the security detection method of the image recognition model described above.
[0203] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium belongs to the same concept as the technical solution of the security detection method for the image recognition model described above. Details not described in detail in the technical solution of the storage medium can be found in the description of the technical solution of the security detection method for the image recognition model described above.
[0204] An embodiment of this specification also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the security detection method of the image recognition model described above.
[0205] The above is an illustrative example of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the security detection method for the image recognition model described above belong to the same concept. Details not described in detail in the technical solution of the computer program can be found in the description of the technical solution of the security detection method for the image recognition model described above.
[0206] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0207] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.
[0208] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.
[0209] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0210] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A security detection method for an image recognition model, comprising: Acquire the initial detection image; Extract the image editing rules, model rules, and artificial intelligence rules from the preset adjustment rules, wherein the preset adjustment rules are determined according to the attack form; The initial detection image is processed based on the image retouching rules to generate a retouched detection image; The initial detection image is processed based on the model rules to generate a model detection image. The process of processing the initial detection image based on the model rules to generate a model detection image includes: identifying a target object in the initial detection image; modeling the target object based on a 3D modeling model to obtain a target 3D object; determining at least one 3D viewpoint; and capturing the model detection image corresponding to the target 3D object under each 3D viewpoint. The number of model detection images is related to the number of 3D viewpoints. The initial detection image is processed based on the aforementioned artificial intelligence rules to generate an artificial intelligence detection image; The image being retouched, the image being detected by the model, and the image being detected by artificial intelligence are identified as the target detection image. Each target detection image and the initial detection image are input into the image recognition model to obtain the image recognition result corresponding to each target detection image; If the image recognition results show a successful recognition, it is determined that the image recognition model has a security issue.
2. The method of claim 1, further comprising: A detection report corresponding to the security issue is generated based on the image recognition results.
3. The method as described in claim 2, comprising generating a detection report corresponding to the security issue based on the image recognition results, including: The image recognition result is determined to be a successfully recognized target detection image; Determine the target adjustment rules corresponding to the target detection image to be processed; Based on the target adjustment rules, a detection report corresponding to the security issue is generated.
4. The method as described in claim 1, wherein the initial detection image is processed based on the retouching rules to generate a retouched detection image, comprising: Add image interference patterns to the initial detection image to obtain the first retouched detection image; Add mirror interference information to the initial detection image to obtain a second retouched detection image; Add an image interference box to the initial detection image to obtain a third retouched detection image; The target object in the initial detection image is retouched to obtain a fourth retouched detection image; Add distortion interference information to the target object in the initial detection image to obtain the fifth retouched detection image; The initial detection image is color-adjusted to obtain the sixth retouched detection image; An image retouching detection image is generated based on at least one of the first image retouching detection image, the second image retouching detection image, the third image retouching detection image, the fourth image retouching detection image, the fifth image retouching detection image, and the sixth image retouching detection image.
5. The method as described in claim 1, wherein the initial detection image is processed based on the artificial intelligence rules to generate an artificial intelligence detection image, comprising: Identify the target object in the initial detection image; Obtain at least one reference object; An artificial intelligence detection image is generated by replacing the target object in the initial detection image with each reference object.
6. The method as described in claim 1, wherein the image recognition model is a face recognition model.
7. The method as described in claim 1, wherein each target detection image and the initial detection image are respectively input into an image recognition model to obtain an image recognition result corresponding to each target detection image, comprising: Identify the target detection image to be processed from each target detection image; The target detection image to be processed and the initial detection image are input into the image recognition model; Obtain the image recognition result returned by the image recognition model, wherein the image recognition result includes recognition success or recognition failure.
8. A security detection method for a face recognition model, comprising: Obtain the initial face image; Extract the image editing rules, model rules, and artificial intelligence rules from the preset adjustment rules, wherein the preset adjustment rules are determined according to the attack form; The initial face image is processed based on the image retouching rules to generate an image retouching detection image; The initial face image is processed based on the model rules to generate model detection images. The process of processing the initial face image based on the model rules to generate model detection images includes: identifying target objects in the initial face image; modeling the target objects based on a 3D modeling model to obtain the target 3D objects; determining at least one 3D viewpoint; and capturing model detection images corresponding to the target 3D objects under each 3D viewpoint. The number of model detection images is related to the number of 3D viewpoints. The initial face image is processed based on the aforementioned artificial intelligence rules to generate an artificial intelligence detection image; The image being retouched, the image being detected by the model, and the image being detected by artificial intelligence are identified as the target detection image. Each target face image and the initial face image are input into the face recognition model to obtain the face recognition result corresponding to each target face image; If a face recognition result shows a successful recognition, it is determined that the face recognition model has a security issue.
9. A security detection device for an image recognition model, comprising: The acquisition module is configured to acquire the initial detection image; The generation module is configured to extract image retouching rules, model rules, and artificial intelligence rules from preset adjustment rules. The preset adjustment rules are determined based on the attack form. The module processes the initial detection image based on the image retouching rules to generate an image retouching detection image. It also processes the initial detection image based on the model rules to generate a model detection image. The process of generating the model detection image based on the model rules includes: identifying a target object in the initial detection image; modeling the target object based on a 3D modeling model to obtain the target 3D object; determining at least one 3D viewpoint and capturing model detection images corresponding to the target 3D object from each 3D viewpoint (the number of model detection images is related to the number of 3D viewpoints); processing the initial detection image based on the artificial intelligence rules to generate an artificial intelligence detection image; and determining the image retouching detection image, the model detection image, and the artificial intelligence detection image as the target detection image. The recognition module is configured to input each target detection image and the initial detection image into the image recognition model to obtain the image recognition result corresponding to each target detection image; The determination module is configured to determine that the image recognition model has a security problem if the image recognition result shows a successful recognition.
10. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 8.
11. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Image model detection method and device, electronic equipment and storage medium
CN110851835A
Safety verification method of face identification system, electronic device and storage medium
CN113554005A