A target detection method, system, device and medium with robustness guarantee
By constructing a smooth detection model based on Gaussian distributed noise and safe area division, the robustness guarantee range is calculated, and the detection error problem of existing object detection algorithms under external interference is solved, and robustness guarantee and quantitative description are achieved.
Patent Information
- Application Number
- CN202310539710.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2043-05-12
AI Technical Summary
Existing object detection algorithms are prone to detection errors when facing external interference, and the existing robustness improvement methods are empirically empirically and difficult to ensure the robust performance of the model for fixed-range perturbations, and are easily defeated by new attack algorithms.
By constructing a smooth detection model based on Gaussian distributed noise, and using the distance measurement function to divide the safe area around the target detection result, the robustness guarantee range of the input space is calculated, and the target detection result and robustness guarantee range are output.
It is realized that when the adversarial sample is within the guaranteed range of robustness, the target detection results are always in the safe area, ensuring that the detection error is within a fixed small range, providing a quantitative description of robustness.
Smart Images

Figure CN116630742B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer vision technology, and particularly to an object detection method, system, device and medium with robustness guarantee. Background Art
[0002] Most of the current object detection algorithms are based on deep learning technology and are generally composed of a basic network and a detection head; usually, the basic network extracts features to obtain representations of different abstraction levels of an image; the detection head then learns position prediction based on the abstract representation and supervision information. However, object detection algorithms also have the vulnerability of the model and are extremely vulnerable to external interference, resulting in detection errors.
[0003] The existing defense means against adversarial attacks on object detection models mainly include robust optimization and adversarial training. Robust optimization is to design a new target model to enhance the anti-disturbance ability of the model itself. Adversarial training is to add adversarial samples to the training set and conduct targeted training to increase the resistance of the prediction model to perturbations.
[0004] The existing object detection algorithms have the following defects: on the one hand, the existing methods for improving the robustness of object detection algorithms are empirical and cannot fully guarantee the robust performance of the model against perturbations within a fixed range, and are easily broken by the latest research attack algorithms, resulting in very poor detection results. On the other hand, the output of the current detection algorithm only contains the detection result and does not contain a quantitative description of the robust performance of the model. Such an output form has a limited application range in reality due to the lack of reliability. Summary of the Invention
[0005] The embodiments of the present application provide an object detection method, system, device and medium with robustness guarantee, and by involving a smooth object detection model, quantitatively describe the robustness while outputting the object detection result.
[0006] To solve the above technical problems, in a first aspect, the embodiments of the present application provide an object detection method with robustness guarantee, including the following steps: First, based on Gaussian distribution noise and an object detection model, construct a smooth detection model; input the data to be detected into the smooth detection model to obtain an object detection result; based on a distance metric function, regard the output space as a semi-metric space and divide out a safe area around the object detection result; input the data to be detected, the object detection result and the radius of the safe area into a robustness calculation model to obtain the robustness guarantee range of the input space; output the object detection result and the robustness guarantee range; when the adversarial sample is within the robustness guarantee range, the object detection result is always within the safe area.
[0007] In some exemplary embodiments, a smoothed detection model is constructed based on Gaussian distribution noise and an object detection model; the data to be detected is input into the smoothed detection model to obtain an object detection result, including: using Monte Carlo sampling for the Gaussian distribution noise to obtain a plurality of sampled noises; adding the sampled noises to the data to be detected to obtain a data set to be detected; inputting the data set to be detected into the object detection model to obtain an initial detection result set; the object detection model is a traditional detection model; the initial detection result set includes a plurality of detection results; the number of detection results is consistent with the number of sampled noises; removing outliers from the detection results in the initial detection result set and taking the average of the detection results after removing outliers to obtain a smoothed detection result; and obtaining the smoothed detection model based on the smoothed detection result.
[0008] In some exemplary embodiments, based on a distance metric function, the output space is regarded as a semi-metric space, and a safety region around the object detection result is divided, including: using the distance metric method of Jaccard distance to calculate the Jaccard distance between each element in the detection result set and the object detection result to obtain a distance set; the detection result set is obtained by inputting the data to be detected into the smoothed detection model to obtain a set of object detection results; denoting the median of the distance set as the radius of the safety region; and obtaining the safety region around the object detection result based on the radius of the safety region.
[0009] In some exemplary embodiments, the definition of the distance metric method using Jaccard distance is shown in formula (1):
[0010]
[0011] where IOU represents the overlap between two detection results in the detection result set, and the overlap is the ratio of the intersection of the two detection results to the union of the two detection results.
[0012] In some exemplary embodiments, the data to be detected, the target detection result, and the radius of the safe region are input into a robustness calculation model to obtain the robustness guarantee range of the input space, including: using Monte Carlo sampling for Gaussian distribution noise to obtain a plurality of sampled noises; adding the sampled noises to the data to be detected to obtain a data set to be detected; inputting the data set to be detected into a smoothed detection model to obtain a target detection result set; the target detection result set includes a plurality of detection results; the number of target detection results is the same as the number of sampled noises; calculating the Jaccard distance between each element in the target detection result set and the target detection result, and obtaining the number of elements within the safe region; using the probability value detection of two-sided hypothesis to obtain the probability that the elements in the target detection result set are within the safe region; and obtaining the robustness guarantee range according to the probability that the elements in the target detection result set are within the safe region and the standard deviation of the Gaussian distribution.
[0013] In some exemplary embodiments, the calculation of the robustness guarantee range is shown in formula (2):
[0014] r = σΦ -1 (p) (2)
[0015] where p represents the probability that the elements in the target detection result set obtained by using the smoothed detection model are within the safe region; Φ -1 is the inverse of the cumulative distribution function of the standard Gaussian distribution.
[0016] In a second aspect, an embodiment of the present application further provides a target detection system with robustness guarantee, including: a smoothed detection model construction module, a safe region division module, a robustness guarantee range calculation module, and a result output module connected in sequence; the smoothed detection model construction module is used to construct a smoothed detection model according to Gaussian distribution noise and a target detection model; input the data to be detected into the smoothed detection model to obtain a target detection result; the safe region division module is used to regard the output space as a semi-metric space according to a distance metric function and divide the safe region around the target detection result; the robustness guarantee range calculation module is used to input the data to be detected, the target detection result, and the radius of the safe region into a robustness calculation model to obtain the robustness guarantee range of the input space; the result output module is used to output the target detection result and the robustness guarantee range; when the adversarial sample is within the robustness guarantee range, the target detection result is always within the safe region.
[0017] In some exemplary embodiments, the robustness calculation model includes a noise module, a detection result module, a distance metric module, and a calculation module connected in sequence; the noise module is used to perform Monte Carlo sampling on Gaussian distributed noise to obtain a plurality of sampled noises; the detection result module is used to add the sampled noises to the data to be detected to obtain a data set to be detected; and input the data set to be detected into the smoothing detection model to obtain a target detection result set; the target detection result set includes a plurality of detection results; the number of target detection results is the same as the number of sampled noises; the distance metric module is used to calculate the Jaccard distance between each element in the target detection result set and the target detection result, and obtain the number of elements within the safe area; the calculation module is used to perform probability value detection using a two-sided hypothesis to obtain the probability that the elements in the target detection result set are within the safe area; and based on the probability that the elements in the target detection result set are within the safe area and the standard deviation of the Gaussian distribution, obtain the robustness guarantee range.
[0018] In addition, the present application also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned target detection method with robustness guarantee.
[0019] In addition, the present application also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned target detection method with robustness guarantee is implemented.
[0020] The technical solutions provided by the embodiments of the present application have at least the following advantages:
[0021] The embodiments of the present application provide a target detection method, system, device, and medium with robustness guarantee. The method includes the following steps: First, based on Gaussian distributed noise and a target detection model, a smoothing detection model is constructed; then, the data to be detected is input into the smoothing detection model to obtain a target detection result; next, based on a distance metric function, the output space is regarded as a semi-metric space, and a safe area around the target detection result is divided; then, the data to be detected, the target detection result, and the radius of the safe area are input into the robustness calculation model to obtain the robustness guarantee range of the input space; finally, the target detection result and the robustness guarantee range are output; when the adversarial sample is within the robustness guarantee range, the target detection result is always within the safe area.
[0022] The present application provides an object detection method with robustness guarantee. By designing a smooth detection model, the output space is regarded as a semi-metric space using a distance metric function, and a safe region is divided. The robustness guarantee range is calculated in the robustness calculation model. The present application can not only calculate the robustness guarantee range of the input sample, but also input the attack samples within this range (regardless of the type of attack obtained) into the model, and a detection result with a detection error within a fixed small range will be obtained. The model of the present application provides a quantitative description of robustness while outputting the object detection result. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not constitute a limitation on the embodiments. Unless otherwise stated, the figures in the drawings do not constitute a scale limitation.
[0024] Figure 1 It is a schematic flowchart of an object detection method with robustness guarantee provided by an embodiment of the present application;
[0025] Figure 2 It is a simplified flowchart of an object detection method with robustness guarantee provided by an embodiment of the present application;
[0026] Figure 3 It is a schematic flowchart of the calculation process of the robustness calculation model provided by an embodiment of the present application;
[0027] Figure 4 It is a schematic structural diagram of an object detection system with robustness guarantee provided by an embodiment of the present application;
[0028] Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] As can be seen from the background art, the existing object detection algorithms are extremely vulnerable to adversarial samples, resulting in detection errors. Especially in the fields with high security requirements, adversarial attacks will seriously affect the usability and reliability of the algorithms. And most of the existing methods for improving the robustness of object detection algorithms are empirical, often only able to resist fixed types of attacks and usually be broken by more advanced attack types.
[0030] To solve the above technical problems, the present application provides an object detection method with robustness guarantee, including the following steps: First, based on Gaussian distribution noise and an object detection model, a smoothed detection model is constructed; then, the data to be detected is input into the smoothed detection model to obtain an object detection result; next, based on a distance metric function, the output space is regarded as a semi-metric space, and a safe area around the object detection result is divided; then, the data to be detected, the object detection result, and the radius of the safe area are input into a robustness calculation model to obtain the robustness guarantee range of the input space; finally, the object detection result and the robustness guarantee range are output; when the adversarial sample is within the robustness guarantee range, the object detection result is always within the safe area. By providing an object detection method with robustness guarantee, the present application designs a smoothed object detection model, which can calculate the robustness guarantee range of the input sample. Inputting the attack samples within this range (regardless of the attack type) into the model will obtain a detection result with a detection error within a fixed small range. The model of the present application provides a quantitative description of robustness while outputting the object detection result.
[0031] The following will elaborate on each embodiment of the present application with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in each embodiment of the present application, many technical details are provided to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented.
[0032] See Figure 1 , the embodiment of the present application provides an object detection method with robustness guarantee, including the following steps:
[0033] Step S1: Based on Gaussian distribution noise and an object detection model, a smoothed detection model is constructed.
[0034] Step S2: The data to be detected is input into the smoothed detection model to obtain an object detection result.
[0035] Step S3: Based on a distance metric function, the output space is regarded as a semi-metric space, and a safe area around the object detection result is divided.
[0036] Step S4: The data to be detected, the object detection result, and the radius of the safe area are input into a robustness calculation model to obtain the robustness guarantee range of the input space.
[0037] Step S5: The object detection result and the robustness guarantee range are output; when the adversarial sample is within the robustness guarantee range, the object detection result is always within the safe area.
[0038] It should be noted that in step S1, the target detection model is a traditional target detection model. Based on the traditional target model, this application designs a target detection model with a smooth distribution, that is, a smooth detection model. The smooth detection model has stronger anti-perturbation ability and the characteristic of robustness guarantee compared with the traditional target detection model.
[0039] To ensure the robustness of the target detection algorithm, improve the ability of the target detection model to cope with adversarial attacks, and enhance the reliability of the target detection algorithm in practical applications, this application provides a target detection algorithm with robustness guarantee. The overall flowchart is as Figure 2 shown. This algorithm takes the data to be detected as input and outputs the detection result and a quantitative robustness guarantee range. It includes steps such as constructing a smooth model, delimiting a safe area, and calculating the robustness range. First, a smooth detection model is constructed using Gaussian distribution noise and a traditional target detection model. Then, the data to be detected (the image to be detected) is input into the smooth detection model to obtain the target detection result. Next, the output space is regarded as a semi-metric space using a distance metric function to delimit the safe area around the target detection result. Then, the radius of the safe area is input into the robustness calculation model to obtain the robustness guarantee range in the input space. Finally, the target detection result and the robustness guarantee range are output. This algorithm can achieve that when the adversarial sample is within the robustness guarantee range, the target detection result always falls within the safe area (that is, ensuring that the error of the target detection is always within a fixed small range).
[0040] In some embodiments, in steps S1 and S2, based on Gaussian distribution noise and the target detection model, a smooth detection model is constructed; the data to be detected is input into the smooth detection model to obtain the target detection result, including:
[0041] Step S1011: Use Monte Carlo sampling for Gaussian distribution noise to obtain multiple sampled noises.
[0042] Step S1012: Add the sampled noise to the data to be detected to obtain a dataset to be detected.
[0043] Step S1013: Input the dataset to be detected into the target detection model to obtain an initial detection result set; the target detection model is a traditional detection model; the initial detection result set includes multiple detection results; the number of detection results is the same as the number of sampled noises.
[0044] Step S1014: Remove outliers from the detection results in the initial detection result set and take the average of the detection results after removing outliers to obtain a smooth detection result.
[0045] Step S1015: Based on the smooth detection result, obtain the target detection result.
[0046] Specifically, in steps S1 and S2 of this application, a smoothed target detection model, i.e., a smoothed detection model (also referred to as a smoothed distribution model), is constructed by Gaussian-distributed noise and a traditional target detection model, and the image to be detected is input into the smoothed detection model to obtain the target detection result. Specifically, the model first uses Monte Carlo sampling on the Gaussian distribution to obtain N 1 sampling noises, adds the sampling noises to the data x to be detected to obtain the dataset to be detected; inputs the dataset to be detected into the traditional target detection model to obtain an initial detection result set Y 1 containing N 1 detection results; takes the average of the detection result set after removing outliers to obtain the smoothed detection result y. The smoothed detection result y is the target detection result.
[0047] In some embodiments, in step S3, based on the distance metric function, the output space is regarded as a semi-metric space, and a safety region around the target detection result is divided, including:
[0048] Step S301: Adopt the distance metric method of Jaccard distance to calculate the Jaccard distance between each element in the detection result set and the target detection result to obtain a distance set; the detection result set is the set of target detection results obtained by inputting the data to be detected into the smoothed detection model in step S2.
[0049] Step S302: Denote the median of the distance set as the radius of the safety region.
[0050] Step S303: Based on the radius of the safety region, obtain the safety region around the target detection result.
[0051] In some embodiments, the definition of the distance metric method of Jaccard distance in step S301 is shown in formula (1):
[0052]
[0053] where IOU represents the overlap between two detection results in the detection result set. As shown in formula (1), the overlap is the ratio of the intersection of two detection results to the union of two detection results.
[0054] Specifically, in step S3 of the present application, the output space is regarded as a semi-metric space by using a distance metric function, and a safety region around the object detection result is divided. The distance metric method applied in the present application is the Jaccard distance, and its definition is shown in formula (1). The algorithm first calculates the Jaccard distance between each element in the detection result set Y and the object detection result y to obtain a distance set D. The median of the distance set D is taken as the radius d of the safety region. Then, based on the radius d of the safety region, the safety region around the object detection result is obtained.
[0055] In some embodiments, in step S4, the data to be detected, the object detection result, and the radius of the safety region are input into a robustness calculation model to obtain the robustness guarantee range of the input space, including:
[0056] Step S401: Monte Carlo sampling is used for Gaussian distribution noise to obtain multiple sampling noises.
[0057] Step S402: The sampling noise is added to the data to be detected to obtain a data set to be detected.
[0058] Step S403: The data set to be detected is input into a smoothed detection model to obtain an object detection result set; the object detection result set includes multiple detection results; the number of object detection results is the same as the number of sampling noises.
[0059] Step S404: Calculate the Jaccard distance between each element in the object detection result set and the object detection result, and obtain the number of elements within the safety region.
[0060] Step S405: Use the probability value detection of two-sided hypothesis to obtain the probability that the elements in the object detection result set are within the safety region.
[0061] Step S406: According to the probability that the elements in the object detection result set are within the safety region and the standard deviation of the Gaussian distribution, obtain the robustness guarantee range.
[0062] In some embodiments, the calculation of the robustness guarantee range in step S406 is shown in formula (2):
[0063] r = σΦ -1 (p) (2)
[0064] where p represents the probability that the elements in the object detection result set obtained by using the smoothed detection model are within the safety region; Φ -1 is the inverse of the cumulative distribution function of the standard Gaussian distribution.
[0065] Specifically, in step S4 of this application, the radius d of the safe area, the data x to be detected, and the target detection result y are input into the robustness calculation model to obtain the robustness guarantee range r of the input space. The flowchart is as Figure 3 shown. Specifically, first, Monte Carlo sampling is used for the Gaussian distribution to obtain N 2 (N 2 = 10N 1 ) sampling noises, and the detection result set Y 2 is obtained by using the smoothed detection model; calculate the Jaccard distance between the elements in the detection result set Y 2 and the target detection result y, and count the number Nd of elements within the safe area; use the p-value detection of the two-sided hypothesis to obtain the probability p that the elements in the detection result set Y2 are within the safe area; finally, obtain the robustness guarantee range r according to the probability p and the standard deviation of the Gaussian distribution. The calculation of the robustness guarantee range r is shown in formula (2).
[0066] This application provides an object detection method with robustness guarantee. By constructing an object detection model with a smooth distribution, and using a distance metric function to regard the output space as a semi-metric space and divide the safe area, then calculate the robustness guarantee range in the robustness calculation model. The output of this algorithm includes the object detection result and a quantitative description of the robustness. The designed model of the algorithm has complete robustness guarantee: when the perturbation of the input is within a fixed range, the output detection results have high similarity (that is, the output error is within a fixed small range).
[0067] In addition, the object detection method of this application proposes a quantitative robustness guarantee, which can resist any type of attack within a fixed range; on the basis of the traditional object detection model, the output of the robustness guarantee range is added, making the algorithm more reliable in practical applications.
[0068] To verify the effect of the object detection method provided by this application, this application conducts experiments in the face detection scenario, using the pre-trained face detection models MTCNN and the CelebA face dataset. Generally speaking, the object detection method provided by this application can ensure that when the l 2 perturbation of the input is less than 0.1, regardless of the type of attack, the IOU of the face detection result is always greater than 90%.
[0069] See Figure 4, the present application further provides an object detection system with robustness guarantee, including: a smooth detection model construction module 101, a safety region division module 102, a robustness guarantee range calculation module 103, and a result output module 104 connected in sequence; wherein, the smooth detection model construction module 101 is used to construct a smooth detection model according to Gaussian distribution noise and an object detection model; input the data to be detected into the smooth detection model to obtain an object detection result; the safety region division module 102 is used to regard the output space as a semi-metric space according to a distance metric function and divide the safety region around the object detection result; the robustness guarantee range calculation module 103 is used to input the data to be detected, the object detection result, and the radius of the safety region into a robustness calculation model to obtain the robustness guarantee range of the input space; the result output module 104 is used to output the object detection result and the robustness guarantee range; when the adversarial sample is within the robustness guarantee range, the object detection result is always within the safety region.
[0070] In some embodiments, the robustness calculation model includes a noise module 1031, a detection result module 1032, a distance metric module 1033, and a calculation module 1034 connected in sequence; the noise module 1031 is used to perform Monte Carlo sampling on Gaussian distribution noise to obtain a plurality of sampled noises; the detection result module 1032 is used to add the sampled noise to the data to be detected to obtain a data set to be detected; and input the data set to be detected into the smooth detection model to obtain an object detection result set; the object detection result set includes a plurality of detection results; the number of the object detection results is the same as the number of the sampled noises; the distance metric module 1033 is used to calculate the Jaccard distance between each element in the object detection result set and the object detection result, and obtain the number of elements within the safety region; the calculation module 1034 is used to perform probability value detection using two-sided hypothesis to obtain the probability that the elements in the object detection result set are within the safety region; and obtain the robustness guarantee range according to the probability that the elements in the object detection result set are within the safety region and the standard deviation of the Gaussian distribution.
[0071] See Figure 5 , another embodiment of the present application provides an electronic device, including: at least one processor 110; and a memory 111 communicatively connected to the at least one processor; wherein, the memory 111 stores instructions executable by the at least one processor 110, and the instructions are executed by the at least one processor 110 so that the at least one processor 110 can execute any of the above method embodiments.
[0072] Among them, the memory 111 and the processor 110 are connected in a bus manner. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors 110 and the memory 111 together. The bus may also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art, and thus will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver may be one component or multiple components, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor 110 is transmitted on the wireless medium through the antenna. Further, the antenna also receives data and transmits the data to the processor 110.
[0073] The processor 110 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 111 can be used to store the data used by the processor 110 when performing operations.
[0074] Another embodiment of the present application relates to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the method embodiments described above are implemented.
[0075] That is, those skilled in the art can understand that all or part of the steps in implementing the methods of the above embodiments can be completed by instructing relevant hardware through a program. The program is stored in a storage medium and includes several instructions for causing a device (which may be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, etc., which can store program codes.
[0076] According to the above technical solution, the embodiments of the present application provide an object detection method, system, device and medium with robustness guarantee. The method includes the following steps: First, based on Gaussian distribution noise and an object detection model, a smoothed detection model is constructed; then, the data to be detected is input into the smoothed detection model to obtain an object detection result; next, based on a distance metric function, the output space is regarded as a semi-metric space, and a safe area around the object detection result is divided; then, the data to be detected, the object detection result, and the radius of the safe area are input into a robustness calculation model to obtain the robustness guarantee range of the input space; finally, the object detection result and the robustness guarantee range are output; when the adversarial sample is within the robustness guarantee range, the object detection result is always within the safe area.
[0077] The present application provides an object detection method with robustness guarantee. By designing a smoothed detection model, using a distance metric function to regard the output space as a semi-metric space and divide the safe area, and calculating the robustness guarantee range through the robustness calculation model. The present application can not only calculate the robustness guarantee range of the input sample, but also input the attack samples within this range (regardless of the type of attack obtained) into the model, and a detection result with a detection error within a fixed small range will be obtained. The model of the present application provides a quantitative description of the robustness while outputting the object detection result.
[0078] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present application. In actual applications, various changes can be made in form and details without departing from the spirit and scope of the present application. Any person skilled in the art can make their own changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application should be subject to the scope defined by the claims.
Claims
1. A target detection method with robustness guarantee, characterized in that, it includes: Based on Gaussian distribution noise and a target detection model, construct a smoothed detection model; Input the data to be detected into the smoothed detection model to obtain a target detection result; Based on a distance metric function, regard the output space as a semi-metric space, and divide out the safe area around the target detection result; Input the data to be detected, the target detection result, and the radius of the safe area into a robustness calculation model to obtain the robustness guarantee range of the input space; Output the target detection result and the robustness guarantee range; when the adversarial sample is within the robustness guarantee range, the target detection result is always within the safe area; Based on the noise of the Gaussian distribution and the target detection model, construct a smoothed detection model; Input the data to be detected into the smoothed detection model to obtain a target detection result, including: Use Monte Carlo sampling for Gaussian distribution noise to obtain multiple sampled noises; Add the sampled noise to the data to be detected to obtain a dataset to be detected; Input the dataset to be detected into the target detection model to obtain an initial detection result set; the target detection model is a traditional detection model; the initial detection result set includes multiple detection results; the number of detection results is the same as the number of sampled noises; Remove outliers from the detection results in the initial detection result set, and take the average of the detection results after removing outliers to obtain a smoothed detection result; Based on the smoothed detection result, obtain the target detection result; Calculate the Jaccard distance between each element in the initial detection result set and the target detection result, and obtain the number of elements within the safe area; Use the probability value detection of two-sided hypothesis to obtain the probability that the elements in the initial detection result set are within the safe area; According to the probability that the elements in the initial detection result set are within the safe area and the standard deviation of the Gaussian distribution, obtain the robustness guarantee range.
2. The target detection method with robustness guarantee according to claim 1, characterized in that, Based on the distance metric function, regarding the output space as a semi-metric space, and dividing out the safe area around the target detection result, includes: Adopt the distance metric method of Jaccard distance to calculate the Jaccard distance between each element in the detection result set and the target detection result to obtain a distance set; the detection result set is obtained by inputting the data to be detected into the smoothed detection model to obtain a set of target detection results; Record the median of the distance set as the radius of the safe area; Based on the radius of the safe area, obtain the safe area around the target detection result.
3. The target detection method with robustness guarantee according to claim 2, characterized in that, The definition of the distance metric method using Jaccard distance is shown in formula (1): (1) Among them, d J represents the Jaccard distance; A and B respectively represent two detection results in the detection result set; IoU represents the overlap of two detection results in the detection result set; the overlap is the ratio of the intersection of two detection results to the union of two detection results.
4. The target detection method with robustness guarantee according to claim 1, characterized in that, The calculation of the robustness guarantee range is shown in formula (2): (2) Among them, r represents the range of robustness guarantee; represents the standard deviation of the Gaussian distribution; p represents the probability that the elements in the initial detection result set obtained by using the smoothing detection model are in the safe area; is the inverse of the cumulative distribution function of the standard Gaussian distribution.
5. A target detection system with robustness guarantee, characterized in that, it includes: a smoothly detecting model construction module, a safety region division module, a robustness guarantee range calculation module, and a result output module that are connected in sequence; the smoothly detecting model construction module is used to construct a smoothly detecting model according to Gaussian distribution noise and a target detection model; input the data to be detected into the smoothly detecting model to obtain a target detection result; the safety region division module is used to regard the output space as a semi-metric space according to a distance metric function, and divide the safety region around the target detection result; the robustness guarantee range calculation module is used to input the data to be detected, the target detection result, and the radius of the safety region into a robustness calculation model to obtain the robustness guarantee range of the input space; the result output module is used to output the target detection result and the robustness guarantee range; when the adversarial sample is within the robustness guarantee range, the target detection result is always within the safety region; the robustness calculation model includes a noise module, a detection result module, a distance metric module, and a calculation module that are connected in sequence; the noise module is used to perform Monte Carlo sampling on Gaussian distribution noise to obtain a plurality of sampled noises; the detection result module is used to add the sampled noise to the data to be detected to obtain a data set to be detected; and input the data set to be detected into the target detection model to obtain an initial detection result set; the target detection model is a traditional detection model; the initial detection result set includes a plurality of detection results; the number of detection results is the same as the number of sampled noises; the distance metric module is used to calculate the Jaccard distance between each element in the initial detection result set and the target detection result, and obtain the number of elements within the safety region; the calculation module is used to perform probability value detection using a two-sided hypothesis to obtain the probability that the elements in the initial detection result set are within the safety region; and obtain the robustness guarantee range according to the probability that the elements in the initial detection result set are within the safety region and the standard deviation of the Gaussian distribution.
6. An electronic device, characterized in that, it includes: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the target detection method with robustness guarantee according to any one of claims 1 to 4.
7. A computer-readable storage medium storing a computer program, characterized in that, when the computer program is executed by a processor, it implements the target detection method with robustness guarantee according to any one of claims 1 to 4.
Citation Information
Patent Citations
Model robustness detection method and device, equipment and medium
CN114419346A
System and method of measuring the robustness of a deep neural network
US20200065664A1