A random adversarial training method for an intelligent face recognition model
CN118095406BActive Publication Date: 2026-08-28BEIJING INST OF COMP TECH & APPL
Patent Information
- Application Number
- CN202410297400.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2044-03-15
AI Technical Summary
Technical Problem
但是,该方法依然存在的不足之处在于:提高了自然干扰场景下的人脸识别模型鲁棒性,但是无法防御人为精心构造的对抗攻击
Benefits of technology
[0025]一、人脸识别模型在进行对抗训练时,将数据增强后生成的训练集和进行对抗攻击后生成的训练集合并作为对抗训练集,在增强人脸识别模型抵御对抗攻击的同时,能够保证在干净人脸样本上的识别准确率;
✦ Generated by Eureka AI based on patent content.
Smart Images

Figure CN118095406B_ABST
Abstract
The present application relates to a kind of random confrontation training methods for intelligent face recognition model, belong to artificial intelligence security field.It includes:1.build face recognition model and initialize algorithm parameter, construct face picture training set;2.face picture training set is randomly divided into multiple mutually disjoint training subsets;3.utilize the training subset after division to generate confrontation training subset;4.utilize confrontation training subset and weighted loss function to carry out back propagation training to face recognition model;5.judge whether all training subsets are completed confrontation training, yes, then execute step 6, otherwise return to step 3;6.judge whether the iteration number of face recognition model reaches termination condition, yes, then output final robust face recognition model, otherwise return to step 2 and continue to execute.The present application can resist face disguise attack and face escape attack simultaneously, enhance the recognition accuracy of face recognition model against attack and can guarantee clean face sample, enhance the robustness and generalization ability of model.
Need to check novelty before this filing date? Find Prior Art
Citation Information
Patent Citations
Data enhancement method for robust face identification
CN107153816A
A data augmentation method for robust face recognition
CN107153816B
Target classification model adversarial training method and system
CN117197589A
Injection randomization confrontation training method
CN110222502A
Method and device for generating adversarial sample and electronic equipment
CN112364745A