Adversarial sample detection method and device, electronic equipment and storage medium

By calculating the original predicted label loss value of the target sample and perturbing the sample in the direction of increasing loss value, adversarial examples are detected by utilizing the correspondence between perturbation intensity and results. This solves the problem of low detection efficiency in existing technologies and achieves efficient and accurate adversarial example detection.

CN117058482BActive Publication Date: 2026-03-03SHANGHAI MIHOYO TIANMING TECH CO LTD
View PDF 4 Cites -1 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-07
Publication Date
2026-03-03

Smart Images

  • Figure CN117058482B_ABST
    Figure CN117058482B_ABST
Patent Text Reader

Abstract

This disclosure relates to the field of data processing, specifically disclosing a method, apparatus, electronic device, and storage medium for detecting adversarial examples. The method includes: acquiring the original predicted label of a target sample and calculating the loss value of the original predicted label; performing perturbation processing on the target sample to increase the loss value of the original predicted label; acquiring the perturbation result of the perturbation processing of the target sample; and detecting whether the target sample is an adversarial example based on the correspondence between the perturbation intensity and the perturbation result. This method does not require pre-training a model and can quickly and conveniently determine whether a target sample is an adversarial example by performing a small number of perturbation processes on the target sample, thus improving the efficiency and accuracy of adversarial example detection.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Text auditing-oriented Chinese adversarial sample generation method and device

    CN112364641A

  • Electromagnetic signal intelligent identification system decoy method based on gradient disturbance

    CN112488023A

  • Adversarial sample generation method based on target detection model feature vector migration

    CN114549933A

  • Confrontation sample generation method and device, storage medium and electronic equipment

    CN116030309A