A random adversarial training method for an intelligent face recognition model

CN118095406BActive Publication Date: 2026-08-28BEIJING INST OF COMP TECH & APPL
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410297400.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-15
Publication Date
2026-08-28
Estimated Expiration
2044-03-15

AI Technical Summary

Technical Problem

但是,该方法依然存在的不足之处在于:提高了自然干扰场景下的人脸识别模型鲁棒性,但是无法防御人为精心构造的对抗攻击

Benefits of technology

[0025]一、人脸识别模型在进行对抗训练时,将数据增强后生成的训练集和进行对抗攻击后生成的训练集合并作为对抗训练集,在增强人脸识别模型抵御对抗攻击的同时,能够保证在干净人脸样本上的识别准确率;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118095406B_ABST
    Figure CN118095406B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of random confrontation training methods for intelligent face recognition model, belong to artificial intelligence security field.It includes:1.build face recognition model and initialize algorithm parameter, construct face picture training set;2.face picture training set is randomly divided into multiple mutually disjoint training subsets;3.utilize the training subset after division to generate confrontation training subset;4.utilize confrontation training subset and weighted loss function to carry out back propagation training to face recognition model;5.judge whether all training subsets are completed confrontation training, yes, then execute step 6, otherwise return to step 3;6.judge whether the iteration number of face recognition model reaches termination condition, yes, then output final robust face recognition model, otherwise return to step 2 and continue to execute.The present application can resist face disguise attack and face escape attack simultaneously, enhance the recognition accuracy of face recognition model against attack and can guarantee clean face sample, enhance the robustness and generalization ability of model.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Data enhancement method for robust face identification

    CN107153816A

  • A data augmentation method for robust face recognition

    CN107153816B

  • Target classification model adversarial training method and system

    CN117197589A

  • Injection randomization confrontation training method

    CN110222502A

  • Method and device for generating adversarial sample and electronic equipment

    CN112364745A