Vehicle target anti-recognition method, system and storage medium based on physical implementable constraints

By generating and optimizing the position and color composition of adversarial blocks during the training and application phases, the problem of poor implementation and operability of existing methods in the physical world is solved, and the applicability and effectiveness of vehicle target anti-recognition are realized.

CN116524367BActive Publication Date: 2025-11-21HUAZHONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310385765.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-12
Publication Date
2025-11-21
Estimated Expiration
2043-04-12

AI Technical Summary

Technical Problem

Existing adversarial attack methods are poorly implemented and operable in the physical world, and are prone to disrupting the typical characteristics of the target, thus lacking strong applicability.

Method used

Through the training and application phases of adversarial blocks, the position and color composition of adversarial blocks are generated and optimized. The position and color of the color blocks are adjusted using the backpropagation algorithm to generate physically realizable adversarial sample images. These images are then printed as adversarial posters and posted at specific locations on vehicles for vehicle target anti-recognition.

Benefits of technology

The generated adversarial blocks are easy to implement in the physical world, have strong applicability, can effectively reduce the vehicle detection confidence of deep neural networks without destroying vehicle features, and have good transferability and robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116524367B_ABST
    Figure CN116524367B_ABST
Patent Text Reader

Abstract

The application discloses a physically realizable constrained vehicle target anti-recognition method and system and a storage medium, and belongs to the field of adversarial attacks of deep learning methods, and the method comprises the following steps: in the training stage, a remote sensing image of an adversarial target vehicle in a physical world is acquired; the generation position and size of an adversarial block in the remote sensing image are determined; a corresponding random initial adversarial block is generated according to the generation position and size of the adversarial block, so that an adversarial sample image is obtained; the adversarial sample image is input into a vehicle detection network, the color composition of the adversarial block is trained, and the training is stopped until the loss converges or the set number of training times is reached, and a trained adversarial block is output; in the prediction stage, the trained adversarial block is used for physically realizable constrained vehicle target anti-recognition. The method has physical realizability and high applicability, can be applied to appearance protection processing of special vehicles against deep neural network vehicle detectors, and enhances the concealment of the special vehicles when facing the deep neural network vehicle detectors.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of adversarial attacks of deep learning methods, and more particularly relates to a physically realizable constraint vehicle target anti-recognition method, system and storage medium. BACKGROUND

[0002] With the development of informationization, automation and intelligentization of modern society, artificial intelligence technology has been widely popularized and applied in various fields. The vigorous development of artificial intelligence technology is inseparable from the rapid development of computer vision image recognition technology. Deep learning models play an important role in the field of computer vision, but the security risks of deep learning technology such as being deceived by adversarial samples and privacy leakage due to the security risks of model algorithms. Among them, the sample added with adversarial perturbation is called adversarial sample.

[0003] Most of the existing adversarial attack methods focus on reducing the difference between adversarial samples and original samples to achieve the purpose of being imperceptible, but ignore the feasibility and operability in the physical world. Most of the existing physical implementation of adversarial attack methods directly destroy the typical features possessed by the attack target itself, such as changing the line features of the attack target vehicle, shielding part of the numbers or letters in the license plate, changing the indication signs on the traffic signs, etc. These methods have poor applicability. SUMMARY

[0004] In view of the defects of the prior art and the improvement demand, the present application provides a physically realizable constraint vehicle target anti-recognition method, system and storage medium, which aims to provide a physically realizable vehicle target anti-recognition method and improve the applicability of the method.

[0005] To achieve the above-mentioned purpose, according to one aspect of the present application, a physically realizable constraint vehicle target anti-recognition method is provided, which includes an adversarial block training phase and an application phase. The adversarial block training phase includes S1-S4, and the application phase includes S5:

[0006] S1, obtaining a remote sensing image of a physical world adversarial target vehicle;

[0007] S2, determining the generation position and size of the adversarial block in the remote sensing image;

[0008] S3, generating a corresponding random initial adversarial block according to the generation position and size of the adversarial block determined in S2 according to the adversarial block generation principle, to obtain an adversarial sample image; wherein the adversarial block generation principle includes increasing the minimum unit of color change of each adversarial block;

[0009] S4, input the adversarial sample image into the neural network, train the loss, adjust the position and color composition of each adversarial block inside by using the back propagation algorithm, until the loss converges or reaches the set number of training times, and output the trained adversarial block;

[0010] S5, using the trained adversarial block to perform physical realizable constrained vehicle target anti-recognition.

[0011] Further, the adversarial block generation principle further includes: increasing the color difference of different colors inside the adversarial block.

[0012] Further, in S4, the process of training loss includes:

[0013] S41, adjust the position and color composition of each adversarial block inside by using the back propagation algorithm, and replace the adversarial block in the last training with the adjusted adversarial block to form a new adversarial sample image;

[0014] S42, input the new adversarial sample image into the trained deep neural network vehicle detector, and output the confidence of the adversarial target vehicle;

[0015] S43, determine whether the confidence is less than the set threshold or reaches the set number of training times, if yes, output the trained adversarial block, otherwise, repeat S41-S42.

[0016] Further, the loss function in the training process is:

[0017]

[0018] wherein, represents the position and color composition of the adversarial block inside corresponding to the minimum confidence of the vehicle detector on the target vehicle category; A(x, s, l, P) represents that after the adversarial block P is transformed by the position and color composition of the inside color block, it is generated in the set position l in the remote sensing image x. x,s,l represents the confidence of the adversarial block on the adversarial target vehicle category.

[0019] Further, in S5, it includes:

[0020] S51, according to the size information of the adversarial target vehicle, determine the size of the adversarial poster to be generated in the physical world;

[0021] S52, according to the scale ratio between the size of the adversarial poster and the trained adversarial block, print the trained adversarial block into an adversarial poster, and paste it in the corresponding position of the adversarial target vehicle, for physical realizable constrained vehicle target anti-recognition.

[0022] ​Further, a physical world verification stage is further included:

[0023] S6, an adversarial image after the adversarial target vehicle pastes the adversarial poster is acquired;

[0024] S7, the adversarial image is input into the vehicle detector to view the confidence of the adversarial target vehicle.

[0025] Further, in S2, the generation position of the adversarial block in the remote sensing image includes one or more of the roof cover, the front engine cover, the rear trunk cover and the door area of the adversarial target vehicle.

[0026] According to another aspect of the present application, a physically realizable constrained vehicle target anti-recognition system is provided for performing a physically realizable constrained vehicle target anti-recognition method according to any one of the first aspect, comprising:

[0027] An adversarial target vehicle image acquisition module is configured to acquire a remote sensing image of a physical world adversarial target vehicle;

[0028] An adversarial block generation position and size determination module is configured to determine a generation position and size of an adversarial block in the remote sensing image;

[0029] An adversarial block generation module is configured to generate a corresponding random initial adversarial block according to the generation position and size of the adversarial block determined by the adversarial block generation position and size determination module, according to an adversarial block generation principle, to obtain an adversarial sample image; wherein the adversarial block generation principle includes increasing the minimum unit of color change of each adversarial block;

[0030] An adversarial block training module is configured to input the adversarial sample image into a neural network, train a loss, and adjust the position and color composition of each adversarial block using a backpropagation algorithm until the loss converges or a set number of training times is reached, and output a trained adversarial block;

[0031] A vehicle target anti-recognition module is configured to perform physically realizable constrained vehicle target anti-recognition using the trained adversarial block.

[0032] Further, in the adversarial block generation module, the adversarial block generation principle further includes increasing the color difference of different colors of the internal color blocks of the adversarial block.

[0033] According to another aspect of the present application, a computer readable storage medium is provided, having a computer program stored thereon, the program being executed by a processor to implement the method according to any one of the first aspect.

[0034] Overall, the above technical solutions conceived by the present application can achieve the following beneficial effects:

[0035] (1) the method of the present application makes the generated adversarial blocks easy to implement in the physical world by limiting the generation position and size of the adversarial blocks and increasing the minimum unit of color change of each adversarial block, optimizes the position and color composition of each internal color block of the adversarial block, and uses the trained adversarial block for vehicle target anti-recognition, which is independent of the characteristics of the target vehicle itself, and in practical application, the background of the moving target vehicle is also changing, by limiting the generation position and size of the adversarial block, the position of the generated adversarial block can be ensured not to be in the background of the adversarial target vehicle, and the operation of the target vehicle will not be affected, and the universality and applicability are stronger.

[0036] (2) as preferred, by increasing the color difference of different colors of the internal color blocks of the adversarial block, the problem of adversarial block attribute change caused by printing error, imaging error and the like in later application can be solved, and the operability of the adversarial block in the physical world is further improved.

[0037] (3) the present application also provides a specific method for training loss and a corresponding loss function, based on the characteristics of the present application, the position of the generated adversarial block is fixed, the loss function designed by the present application only trains the position and color composition transformation of the internal color blocks of the adversarial block, the loss function is simpler, and faster and more effective training can be realized.

[0038] (4) in the process of using the trained adversarial block for vehicle target anti-recognition, only the adversarial block needs to be converted into an adversarial disturbance poster of corresponding size in the physical world and pasted at the corresponding position of the adversarial target vehicle, without damaging the typical characteristics possessed by the adversarial target vehicle itself, and the applicability is stronger. At the same time, the experimental results of the physical verification stage show that the method of the present application also has good migration, robustness and effectiveness.

[0039] (5) as preferred, the generation area of the adversarial block can be one or more of the roof cover, front engine cover, rear box cover and door area of the vehicle, which does not affect the typical characteristics possessed by the vehicle itself, so that the method of the present application is more universal.

[0040] In summary, the method of the present application has physical realizability and high applicability, and can be applied to vehicle appearance protection processing for deep neural network vehicle detector, especially special vehicles, to enhance the concealment of special vehicles when facing deep neural network vehicle detector. BRIEF DESCRIPTION OF DRAWINGS

[0041] Figure 1 The physical realizable constraint vehicle target anti-recognition method provided by the present application is shown in the schematic diagram.

[0042] Figure 2 The flow chart of the physical realizable constraint vehicle target anti-recognition method provided by the present application is shown in the schematic diagram.

[0043] Figure 3 Physical implementable adversarial block generation position schematic diagram provided by the embodiment of the present application.

[0044] Figures 4(a)-4(c) The schematic diagrams of the physical implementable adversarial block poster pasted on the front engine hood, the rear trunk cover and the roof cover of the adversarial target vehicle respectively provided by the embodiment of the present application.

[0045] Figures 5(a)-5(c) The simulation result comparison diagrams respectively of the embodiment of the present application without adding the adversarial block, adding the trained adversarial block and adding the random initial adversarial block.

[0046] Figures 6(a)-6(b) The simulation result diagrams respectively of the embodiment of the present application for adversarial identification at different positions of different target vehicles.

[0047] Figures 7(a)-7(b) The simulation result diagrams respectively of the embodiment of the present application for adversarial identification of the same target vehicle using different original images.

[0048] Figures 8(a)-8(d) The physical simulation result diagrams respectively of the embodiment of the present application in the physical world verification stage for adversarial identification of the same target vehicle after pasting the adversarial poster at different heights.

[0049] Figures 9(a)-9(b) The physical simulation result diagrams respectively of the embodiment of the present application in the physical world verification stage for adversarial identification of the same target vehicle after pasting the adversarial poster at the same height and different angles. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical scheme and advantages of the present application clearer and more apparent, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.

[0051] As shown in Figure 1 , Figure 2 The physical implementable constraint vehicle target anti-recognition method provided by the present application mainly includes an adversarial block training stage and an application stage, the adversarial block training stage includes S1-S4, and the application stage includes S5:

[0052] S1, obtaining a remote sensing image of an adversarial target vehicle in a physical world;

[0053] In S1, the embodiment of the present application uses a UAV to obtain a remote sensing image of a physical world confrontation target vehicle under the condition of a relative height of 20 meters and a pitch angle of 90 degrees, and the resolution of the obtained image is 1280*720 pixels.

[0054] In S2, the generation position and size of the confrontation block in the remote sensing image in S1 are determined.

[0055] In S2, as shown in the figure, Figure 3 For the vehicle anti-recognition of the UAV visual angle of 90 degrees in this embodiment, the generation area of the confrontation block is limited to the roof cover, the front engine cover and the rear trunk cover of the vehicle, and none of the three areas affects the typical features possessed by the vehicle itself. In other embodiments, the generation area of the confrontation block can be one or more of the roof cover, the front engine cover, the rear trunk cover and the door area of the vehicle, for example: for the visual angle of the side of the vehicle, the generation area of the confrontation block can be the door area.

[0056] In S3, a corresponding random initial confrontation block is generated according to the generation position and size of the confrontation block determined in S2 according to the confrontation block generation principle designed by the present application, and a confrontation sample image is obtained; wherein the confrontation block generation principle designed by the present application includes: increasing the minimum unit of color change of each confrontation block, so that the color blocks inside the confrontation block can be perceived by the camera in the physical world.

[0057] The confrontation block generation principle designed by the present application also includes: increasing the color difference of different colors of the color blocks inside the confrontation block to avoid the problem of attribute change of the confrontation block caused by printing error, imaging error and the like in the later application.

[0058] In S3, a computer is used for digital simulation to generate a random confrontation block of a specified size at the position determined in S2, and a preliminary confrontation sample image is obtained. In the embodiment of the present application, the minimum unit of color change inside the confrontation block is increased from a single pixel to 5*5 pixels; and the color selection of the color blocks inside the confrontation block is limited, and the selectable colors of the confrontation block are limited to specific colors, for example, six specific colors of black, white, red, blue, yellow and green. By limiting the colors with large differentiation, the color difference of different colors of the color blocks inside the confrontation block is increased.

[0059] In S4, the confrontation sample image is input into a neural network, a loss is trained, and the position and color composition of each color block inside the confrontation block are iteratively adjusted by using a back propagation algorithm until the loss converges or a set number of training times is reached, and a trained confrontation block is output.

[0060] In S4, the training process includes:

[0061] S41, the position and color composition of each color block inside the adversarial block are iteratively adjusted by using a back propagation algorithm, so that the position and color composition of the color block inside the adversarial block change in a direction of reducing the confidence of the adversarial target, and the adversarial block after adjustment is used to replace the adversarial block in the last training to form a new adversarial sample image;

[0062] S42, the new adversarial sample image is input into the trained deep neural network vehicle detector, and the confidence of the adversarial anti-recognition target vehicle is output;

[0063] S43, whether the confidence is less than a set threshold M (0 < M < 1) or reaches a set training number N is judged, if yes, the trained adversarial block is output, otherwise, S41-S42 are repeated.

[0064] Finally, the anti-recognition attack adversarial block of the target vehicle at different positions and the position and color composition of the color block inside the adversarial block are obtained.

[0065] In the training process of the adversarial block, the position and color composition of the color block inside the obtained adversarial block are used to minimize the confidence of the deep neural network vehicle detector outputting the adversarial anti-recognition target vehicle as the target, and the loss function designed by the application is:

[0066]

[0067] Wherein, represents the position and color composition of the color block inside the adversarial block corresponding to the minimum confidence of the vehicle detector to the correct category (target vehicle), A (x, s, l, P) represents that the adversarial block P is transformed by the position and color composition of the color block to generate in the set position l on the remote sensing image x of the adversarial target vehicle; C x,s,l represents the confidence of the adversarial block generated in the set position l on the remote sensing image x of the adversarial target vehicle after the transformation s of the position and color composition of the color block to the category .

[0068] In the method of the application, the position l generated by the adversarial block is fixed, therefore, the target of the training is the transformation s of the position and color composition of the color block inside the adversarial block P, so that the loss function designed by the application is simpler, and faster and more effective training can be realized.

[0069] In the embodiment of the present application, M=0.1 and N=100. A YOLOv3 deep neural network vehicle detector that has been trained is used, and in other embodiments, YOLOv5 / YOLOv7 or Faster RCNN can also be used as a deep neural network vehicle detector. In the embodiment of the present application, the "VisDrone2019" dataset is used as a training set to train the unmanned aerial vehicle perspective YOLOv3 deep neural network vehicle detector used in the present application. The "VisDrone2019" dataset is used for object detection and tracking in the unmanned aerial vehicle perspective from visual data obtained by a unmanned aerial vehicle. The annotation categories of this dataset have a total of 12 categories, including car, van, bus, truck and other vehicle-related categories. After 350 epochs of training, the trained model file is used as the vehicle detection effect after the model of YOLOv3 in the yolo.py file. Most vehicles can be identified and have a confidence of more than 0.95, and most have a confidence of 0.99, 1.00.

[0070] S5, using the trained adversarial block to perform physically realizable constrained vehicle target counter-detection.

[0071] Specifically, in S5, the following steps are included:

[0072] S51, determining the size of the adversarial block poster to be generated in the physical world according to the size information of the counter-detection target vehicle;

[0073] S52, printing the trained adversarial block into a poster according to the scale ratio between the size of the adversarial block poster to be generated in the physical world and the size of the trained adversarial block obtained from the digital world, and pasting it at the corresponding position of the counter-detection target vehicle for physically realizable constrained vehicle target counter-detection.

[0074] In the embodiment of the present application, the adversarial target vehicle model used is Dongfeng Peugeot 408, and the actual measured size data related to the adversarial block generation area is shown in Table 1.

[0075] Table 1 Physical world adversarial target vehicle size data

[0076] Roof Front bonnet Rear boot Lateral 114 cm 127 cm 125 cm Longitudinal 150 cm 68 cm 29 cm

[0077] After measuring the size data of the physical world adversarial target vehicle, the pixel size of the adversarial block generated in the digital world simulation is compared to determine the correspondence between the pixel and the distance size.

[0078] The size data of the trained adversarial block generated in the digital world simulation is shown in Table 2.

[0079] Table 2 Virtual world adversarial block size data

[0080] Roof Front bonnet Rear boot Lateral 60 pixels 55 pixels 65 pixels Longitudinal 75 pixels 35 pixels 10 pixels

[0081] Through the analysis and comparison of Table 1 and Table 2, in the embodiment of the application, the scale ratio of 1 pixel in the digital world corresponding to 1.9 centimeters in the physical world is used to make the physical world confrontation disturbance poster. The size of the final obtained physical world confrontation disturbance poster is as shown in Table 3:

[0082] Table 3 Size data of the physical world confrontation disturbance poster

[0083] Roof Front bonnet Rear boot Lateral 114 cm 104.5 cm 123.5 cm Longitudinal 142.5 cm 66.5 cm 19 cm

[0084] The corresponding confrontation disturbance poster is pasted at the corresponding position of the confrontation target vehicle, as shown in Figures 4(a)-4(c) .

[0085] Based on the above method, the method of the application further includes a physical world verification phase, specifically including:

[0086] S6, obtaining the confrontation image of the confrontation target vehicle after pasting the confrontation poster; in the embodiment of the application, the quadcopter unmanned aerial vehicle is operated on a day with good weather conditions, sufficient light and small wind to take unmanned aerial vehicle perspective images of the target vehicle pasted with the physical world confrontation disturbance poster at different heights and different perspectives.

[0087] S7, inputting the confrontation image into the trained deep neural network vehicle detector to view the vehicle anti-recognition confrontation attack effect of the confrontation block in the physical world; in the embodiment of the application, the unmanned aerial vehicle perspective image of the target vehicle pasted with the physical world confrontation disturbance poster is input as the confrontation sample image into the YOLOv3 detector to view the confidence change of the confrontation target vehicle and analyze the confrontation attack effect of the confrontation block. The confrontation attack effect analysis is respectively carried out under the conditions of 20-30 meters relative height and different shooting angles.

[0088] As shown in Figures 5(a)-5(c) , it can be found that the confidence of the target vehicle without adding the confrontation block is 0.99, the confidence of the target vehicle adding the trained confrontation block is 0.56, and the confidence of the target vehicle adding only the random initial confrontation block is 0.97. It is proved that the confrontation block trained by the method designed by the application has effect, and the confrontation effect is not derived from the large-area confrontation coverage, but from the position and composition of the color blocks inside the confrontation block.

[0089] As shown in Figures 6(a)-6(b) , it can be found that for different target vehicles at different positions, the same set of trained confrontation blocks is used, and the confidence is reduced from 0.99 to 0.3 and from 0.98 to 0.62, respectively. That is, the method of the application has good migration.

[0090] As Figures 7(a)-7(b) shown, it can be found that the confidence is reduced from 0.98 to 0.7 and 0.62 respectively by using the same set of trained adversarial blocks for the same target vehicle using different original images, that is, the method of the present application has good robustness.

[0091] As Figures 8(a)-8(d) shown, wherein Fig. 8(a) is a simulation result diagram of the target vehicle without pasting the adversarial disturbance poster for anti-identification adversarial attack at 20 meters high, Figures 8(b)-8(d) Fig. 8(b) is a physical simulation result diagram of the target vehicle pasting the adversarial disturbance poster for anti-identification adversarial attack at 20 meters high, Fig. 8(c) is a physical simulation result diagram of the target vehicle pasting the adversarial disturbance poster for anti-identification adversarial attack at 25 meters high, and Fig. 8(d) is a physical simulation result diagram of the target vehicle pasting the adversarial disturbance poster for anti-identification adversarial attack at 30 meters high.

[0092] It can be found that in the physical world verification stage, for the same target vehicle, the confidence is 1.00 without pasting the adversarial poster and 0.84 after pasting the adversarial poster at the same spatial height; and for the same target vehicle, the confidence is reduced to 0.84, 0.66, 0.39 at different spatial heights, that is, the method of the present application has good adversarial effect at different high distance.

[0093] As Figures 9(a)-9(b) shown, wherein Fig. 9(a) is an adversarial image obtained at a 30-meter-high longitudinal shooting angle, and Fig. 9(b) is an adversarial image obtained at a 30-meter-high transverse shooting angle. It can be found that in the physical world verification stage, for the same target vehicle, the confidence is reduced to 0.39 and 0.53 at the same spatial height for different shooting angles, that is, the method of the present application also has strong robustness for angle transformation.

[0094] At the same time, it can also be found through the above simulation experiments that the method of the present application has good effect for the same type of vehicle using the same set of adversarial blocks for adversarial identification, and the adversarial effect of the generated adversarial blocks of the present application mainly depends on the position and color composition of the adversarial blocks inside, and is irrelevant to the characteristics of the vehicle itself, and has stronger universality and applicability.

[0095] It is also found that pasting the adversarial poster at multiple positions has better adversarial effect than pasting the adversarial poster at only one position (such as only on the roof cover); at the same time, as a preferred, the specified size of the adversarial block is grown as much as possible at the set adversarial block generation position, and the adversarial effect of generating the specified size of the adversarial block at the determined position is good.

[0096] The method of the present application makes the generated adversarial blocks easy to implement in the physical world by limiting the generation position and size of the adversarial blocks, increasing the minimum unit of color change of each adversarial block, and increasing the color difference of different colors inside the adversarial blocks, and by optimizing the position and color composition of each color block inside the adversarial blocks, the trained adversarial blocks are used for vehicle target anti-recognition, which is independent of the characteristics of the target vehicle itself, and has stronger universality and applicability. Moreover, in practical application, the background of the moving target vehicle is also changing, by limiting the generation position and size of the adversarial blocks, it can be ensured that the generated position of the adversarial blocks will not be in the background of the adversarial target vehicle, and will not affect the operation of the target vehicle, and the generation position and size also affect the effect of the adversarial attack.

[0097] In the process of vehicle target anti-recognition using the trained adversarial blocks, only the adversarial blocks need to be converted into adversarial disturbance posters of corresponding size in the physical world, and pasted at the corresponding position of the adversarial target vehicle, without damaging the typical features of the target vehicle, and the applicability is stronger. Experimental results show that the method of the present application also has good migration, robustness and effectiveness.

[0098] The method of the present application can be applied to appearance protection processing of vehicles against deep neural network vehicle detectors, especially special vehicles, to enhance the concealment of special vehicles when facing deep neural network vehicle detectors.

[0099] According to another aspect of the present application, a physically implementable constrained vehicle target anti-recognition system is also provided, comprising:

[0100] An adversarial target vehicle image acquisition module is configured to acquire a remote sensing image of an adversarial target vehicle in a physical world;

[0101] An adversarial block generation position and size determination module is configured to determine a generation position and size of an adversarial block in the remote sensing image;

[0102] An adversarial block generation module is configured to generate a corresponding random initial adversarial block according to the generation position and size of the adversarial block determined by the adversarial block generation position and size determination module, according to an adversarial block generation principle, to obtain an adversarial sample image; wherein the adversarial block generation principle includes increasing the minimum unit of color change of each adversarial block;

[0103] An adversarial block training module is configured to input the adversarial sample image into a neural network, train a loss, adjust the position and color composition of each color block inside the adversarial block using a back propagation algorithm, until the loss converges or a set number of training times is reached, and output a trained adversarial block;

[0104] A vehicle target anti-recognition module is configured to use the trained adversarial block for physically implementable constrained vehicle target anti-recognition.

[0105] Further, in the adversarial block generation module, the adversarial block generation principle further includes increasing the color difference of different colors of the color blocks inside the adversarial block.

[0106] Each of the modules is configured to perform each of the specific steps of the physically realizable vehicle target anti-recognition method.

[0107] According to another aspect of the present application, a computer readable storage medium is provided, which stores a computer program, and the program is executed by a processor to implement each of the specific steps of the physically realizable vehicle target anti-recognition method.

[0108] Those skilled in the art will easily understand that the above description is only the preferred embodiment of the present application, and is not intended to limit the present application, and any modification, equivalent replacement and improvement made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A physically realizable constrained vehicle target anti-identification method, characterized in that, The method comprises an adversarial block training phase and an application phase, the adversarial block training phase comprises S1-S4, and the application phase comprises S5: S1, acquiring a remote sensing image of an adversarial target vehicle in a physical world; S2, determining a generation position and size of an adversarial block in the remote sensing image; S3, generating a corresponding random initial adversarial block according to the generation position and size of the adversarial block determined in S2 according to an adversarial block generation principle, to obtain an adversarial sample image; wherein the adversarial block generation principle comprises increasing a minimum unit of color change of each adversarial block; S4, inputting the adversarial sample image into a neural network, training a loss, adjusting a position and color composition of an internal color block of each adversarial block by using a back propagation algorithm, until the loss converges or a set training number is reached, and outputting a trained adversarial block; S5, using the trained adversarial block to perform physical realizable constraint vehicle target anti-recognition; A loss function in the training process is: wherein, represents the position and color composition of the adversarial patch corresponding to the time when the vehicle detector has the lowest confidence in the target vehicle class; represents the adversarial patch after the position and color composition of the internal color patch are transformed , a remote sensing image is generated at the position set in the remote sensing image ; represents the confidence of the adversarial patch for the adversarial target vehicle class.

2. The method of claim 1, wherein, The adversarial block generation principle further comprises: increasing a color difference of different colors of the internal color block of the adversarial block.

3. The method according to claim 1 or 2, characterized in that, In S4, the process of training the loss comprises: S41, adjusting the position and color composition of the internal color block of each adversarial block by using the back propagation algorithm, and replacing the adversarial block in the last training with the adjusted adversarial block to form a new adversarial sample image; S42, inputting the new adversarial sample image into a trained deep neural network vehicle detector to output a confidence of the adversarial target vehicle; S43, determining whether the confidence is less than a set threshold or a set training number is reached, if yes, outputting the trained adversarial block, otherwise, repeating S41-S42.

4. The method according to claim 1 or 2, characterized in that, In S5, the method comprises: S51, determining a size of an adversarial poster to be generated in the physical world according to size information of the adversarial target vehicle; S52, printing the trained adversarial block into an adversarial poster according to a scale ratio between the size of the adversarial poster and the trained adversarial block, and pasting the adversarial poster at a corresponding position of the adversarial target vehicle, to perform the physical realizable constraint vehicle target anti-recognition.

5. The method of claim 4, wherein, The method further comprises a physical world verification phase: S6, acquiring an adversarial image after the adversarial target vehicle pastes the adversarial poster; S7, inputting the adversarial image into the vehicle detector to view the confidence of the adversarial target vehicle.

6. The method of claim 1 or 2, wherein, In S2, the generation position of the adversarial block in the remote sensing image comprises one or more of a roof cover, a front engine cover, a rear trunk cover and a door area of the adversarial target vehicle.

7. A physically realizable constrained vehicle target anti-identification system, characterized by, A device for performing a physical realizable constraint vehicle target anti-recognition method according to any one of claims 1-6, comprising: an adversarial target vehicle image acquisition module, configured to acquire a remote sensing image of an adversarial target vehicle in a physical world; an adversarial block generation position and size determination module, configured to determine a generation position and size of an adversarial block in the remote sensing image; an adversarial block generation module, configured to generate a corresponding random initial adversarial block according to the generation position and size of the adversarial block determined by the adversarial block generation position and size determination module according to an adversarial block generation principle, to obtain an adversarial sample image; wherein the adversarial block generation principle comprises increasing a minimum unit of color change of each adversarial block; The adversarial block training module is configured to input the adversarial sample image into a neural network, train a loss, adjust a position and a color composition of each color block in the adversarial block by using a back propagation algorithm, output a trained adversarial block until the loss converges or a set training number is reached. The vehicle target anti-recognition module is configured to perform physical realizable constraint vehicle target anti-recognition by using the trained adversarial block.

8. The system of claim 7, wherein, The adversarial block generation principle further includes increasing a color difference between different colors of the color blocks in the adversarial block.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Physical world confrontation sample generation method and device, electronic equipment and storage medium

    CN114005168A

  • Adversarial patches including pixel blocks for machine learning

    US20210064938A1