Robust path-based target detection model adversarial robustness evaluation method and device

By adding perturbations and decomposing features into the object detection model, robust neurons are identified to construct robust paths, which solves the problem of insufficient interpretability in the adversarial robustness assessment in the prior art. This enables the scientific selection of the best adversarial robustness model and improves the stability and accuracy of the model.

CN117496308BActive Publication Date: 2026-07-21NAT UNIV OF DEFENSE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NAT UNIV OF DEFENSE TECH
Filing Date
2023-11-21
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing adversarial robustness assessment methods lack interpretability, making it difficult to scientifically select the target detection model with the best adversarial robustness, which affects the stability and accuracy of the model.

Method used

By acquiring an evaluation image sample set and adding perturbations to the object detection model, the model is decomposed into robust and non-robust features. Robust neurons are identified and robust paths are constructed. The adversarial robustness of the model is evaluated based on the coverage of the robust paths.

Benefits of technology

This improves the accuracy and interpretability of the adversarial robustness assessment of the target detection model, ensuring the stability and accuracy of the target detection results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117496308B_ABST
    Figure CN117496308B_ABST
Patent Text Reader

Abstract

The application relates to a method and device for evaluating adversarial robustness of a target detection model based on robust paths. The method comprises the following steps: obtaining an evaluation image sample set and a plurality of target detection models to be evaluated; inputting the evaluation image sample into the target detection model, adding disturbance in an intermediate layer feature space, obtaining disturbed image features and propagating the disturbed image features to an output layer; decomposing the disturbed image features into robust features and non-robust features according to a prediction result of the output layer; starting from the last layer of the current target detection model, screening robust neurons from each layer in turn according to the robust features, connecting the robust neurons of adjacent layers to obtain robust paths, and then obtaining model-level robust paths according to the robust paths of all the evaluation image samples to evaluate the adversarial robustness of the corresponding target detection model. The method can scientifically screen the target detection model with the best adversarial robustness, and improve the accuracy and stability of target detection.
Need to check novelty before this filing date? Find Prior Art