Generalized adversarial perturbation, face adversarial sample generation method and device
Patent Information
- Application Number
- CN202410039635.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-10
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2044-01-10
AI Technical Summary
人脸识别也同样面临着对抗扰动攻击和隐私泄露的隐患
[0021]本说明书实施例提供的方案,能在频域中产生通用对抗扰动,相比于在空域中直接产生扰动,可以提升对抗扰动的隐蔽性性能,且该方案还考虑了人脸图像不同频段的细致信息,这样能使得生成的通用对抗扰动可作用的范围更全面,相应的攻击性也就更佳。由此,该方案能面向人脸识别模型生成攻击性和隐蔽性更优的通用对抗扰动。通过将该通用对抗扰动叠加到干净的人脸图像上,能获得具有较高有效性的人脸对抗样本,将该人脸对抗样本用于训练该人脸识别模型,能有助于提高该人脸识别模型的对抗防御能力,实现隐私保护。
Smart Images

Figure CN118135626B_ABST
Abstract
Description
Technical Field
[0001] The embodiments in this specification relate to the field of computer technology, specifically to a general adversarial perturbation generation method and apparatus for face recognition models, and a face adversarial sample generation method and apparatus. Background Technology
[0002] With the rapid development of artificial intelligence technology, various deep learning techniques have matured, and models built on deep neural networks are playing an increasingly important role in various classification and recognition tasks. Among them, facial recognition, as an efficient method of identity verification, is gaining popularity due to its advantages such as ease of collection, non-contact nature, and static nature. As the most convenient biometric feature, its combination with deep learning technology makes facial recognition one of the most effective artificial intelligence applications at present.
[0003] Despite the significant achievements of deep neural networks in various large-scale tasks, they still harbor some security vulnerabilities. Recent research has revealed that neural networks are highly susceptible to adversarial perturbations. Adversarial perturbations can be the addition of imperceptible noise to the input image; even a clean image with this perturbation can cause the model to make incorrect predictions. Face recognition also faces the risks of adversarial perturbation attacks and privacy breaches.
[0004] Therefore, there is an urgent need for a reasonable and reliable solution that can generate general adversarial perturbations with better offensiveness and concealment for face recognition models, which can help improve the adversarial defense capabilities of face recognition models and achieve privacy protection. Summary of the Invention
[0005] This specification provides a general adversarial perturbation and face adversarial sample generation scheme, which can generate general adversarial perturbations with better offensiveness and concealment for face recognition models. By superimposing this general adversarial perturbation onto a clean face image, highly effective face adversarial samples can be obtained. Using these face adversarial samples to train face recognition models can help improve the adversarial defense capabilities of face recognition models and achieve privacy protection.
[0006] Firstly, embodiments of this specification provide a general adversarial perturbation generation method for face recognition models. The method involves several rounds of iterative optimization, wherein any round of iterative optimization includes: for each target face image in the training set, acquiring face information in different frequency bands in the frequency domain, and acquiring perturbation information of the adversarial perturbation image in different frequency bands; superimposing the perturbation information of the corresponding frequency bands onto the face information in the different frequency bands to obtain adversarial information in different frequency bands, and fusing the adversarial information in the different frequency bands into full-band adversarial information; combining the face information in the different frequency bands and the perturbation information in the different frequency bands... The adversarial information and the full-band adversarial information are transformed from the frequency domain to the spatial domain to obtain face images, adversarial images, and full-band adversarial images corresponding to the target face image in different frequency bands; the first image features of the preset image extracted by the face recognition model and the second image features of the full-band adversarial image are obtained; the preset image is far away from any image in the entire training set; the parameters in the adversarial perturbation image are optimized with the goal of reducing the difference between the first image features and the second image features, and reducing the difference between the face images in different frequency bands and the adversarial images in the corresponding frequency bands.
[0007] In some embodiments, prior to performing the plurality of rounds of iterative optimization, the method further includes: randomly initializing the parameters in the adversarial perturbation image.
[0008] In some embodiments, acquiring face information in different frequency bands in the frequency domain and acquiring perturbation information of the adversarial perturbation image in different frequency bands includes: performing discrete cosine transform on each target face image and the adversarial perturbation image to obtain the frequency domain face information of each target face image and the frequency domain perturbation information of the adversarial perturbation image; performing frequency division operation on the frequency domain face information and the frequency domain perturbation information using a preset filter to obtain face information in different frequency bands of each target face image and the perturbation information in different frequency bands of the adversarial perturbation image; converting the face information in different frequency bands, the adversarial information in different frequency bands, and the full-band adversarial information from the frequency domain to the spatial domain includes: performing inverse discrete cosine transform on the face information in different frequency bands, the adversarial information in different frequency bands, and the full-band adversarial information.
[0009] In some embodiments, the filter includes a high-frequency filter, an intermediate-frequency filter, and a low-frequency filter, and the different frequency bands include a high-frequency band, an intermediate-frequency band, and a low-frequency band.
[0010] In some embodiments, the method further includes: using a pre-trained image processing model to extract the third image features of the face images of different frequency bands and the fourth image features of the adversarial images of different frequency bands; reducing the difference between the face images of different frequency bands and the adversarial images of the corresponding frequency bands includes: reducing the difference between the third image features of the face images of different frequency bands and the fourth image features of the adversarial images of the corresponding frequency bands.
[0011] In some embodiments, the image processing model includes a Visual Geometry Group (VGG) network.
[0012] In some embodiments, optimizing the parameters in the adversarial perturbation image with the goal of reducing the difference between the first image features and the second image features, and reducing the difference between the face images of different frequency bands and the adversarial images of the corresponding frequency bands, includes: determining a first loss based on the difference between the second image features and the first image features of the full-band adversarial images corresponding to each target face image; determining a second loss based on the difference between the face images of different frequency bands corresponding to each target face image and the adversarial images of the corresponding frequency bands; determining a total prediction loss, which is positively correlated with the first loss and the second loss; and optimizing the parameters in the adversarial perturbation image with the goal of minimizing the total prediction loss.
[0013] In some embodiments, optimizing the parameters in the adversarial perturbation image includes: optimizing the parameters in the adversarial perturbation image with the constraint that the values of the parameters in the adversarial perturbation image do not exceed a target threshold; wherein the target threshold is set by using the L∞ norm.
[0014] In some embodiments, after performing any round of iterative optimization, the method further includes: superimposing the optimized adversarial perturbation image onto the first face image included in each of the multiple image pairs in the verification set to obtain a face adversarial image; wherein, a single image pair includes a first face image and a second face image of the same person; for each of the multiple image pairs, obtaining the fifth image feature of the second face image in the image pair extracted by the face recognition model, and the sixth image feature of the face adversarial image corresponding to the first face image in the image pair; determining the attack success rate of the optimized adversarial perturbation image based on the similarity between each fifth image feature and the corresponding sixth image feature; if the attack success rate reaches a predetermined success rate, storing the optimized adversarial perturbation image and ending the iterative optimization of the adversarial perturbation image; if the attack success rate does not reach the predetermined success rate, performing the next round of iterative optimization on the adversarial perturbation image.
[0015] Secondly, embodiments of this specification provide a method for generating adversarial examples of faces, comprising: acquiring an adversarial perturbation image, which is obtained by performing several rounds of iterative optimization using the method described in the first aspect; acquiring several face images to be perturbed; and for each face image among the several face images, superimposing the adversarial perturbation image on the face image to obtain an adversarial example of a face.
[0016] Thirdly, embodiments of this specification provide a general adversarial perturbation generation device for face recognition models. The device implements any one of several rounds of iterative optimization through the following units: a first acquisition unit, configured to acquire face information in different frequency bands of each target face image in the training set, and acquire perturbation information of the adversarial perturbation image in different frequency bands; a perturbation unit, configured to superimpose the face information in the different frequency bands with the corresponding frequency band perturbation information to obtain adversarial information in different frequency bands, and fuse the adversarial information in the different frequency bands into full-band adversarial information; a conversion unit, configured to convert the face information in the different frequency bands, the perturbation information in the training set, and the perturbation information in the training set into full-band adversarial information. Adversarial information in different frequency bands and the full-band adversarial information are converted from the frequency domain to the spatial domain to obtain face images in different frequency bands, adversarial images in different frequency bands, and full-band adversarial images corresponding to the target face image; the second acquisition unit is configured to acquire the first image features of a preset image extracted by the face recognition model, and the second image features of the full-band adversarial image; the preset image is far away from any image in the entire training set; the optimization unit is configured to optimize the parameters in the adversarial perturbation image with the goal of reducing the difference between the first image features and the second image features, and reducing the difference between the face images in different frequency bands and the adversarial images in the corresponding frequency bands.
[0017] Fourthly, embodiments of this specification provide a face adversarial example generation apparatus, comprising: a first acquisition unit configured to acquire an adversarial perturbation image, which is obtained by performing several rounds of iterative optimization using the method described in the first aspect; a second acquisition unit configured to acquire a plurality of face images to be perturbed; and a perturbation unit configured to superimpose the adversarial perturbation image on each of the plurality of face images to obtain a face adversarial example.
[0018] Fifthly, embodiments of this specification provide a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, it causes the computer to perform the method described in either the first or second aspect.
[0019] Sixthly, embodiments of this specification provide a computing device including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method described in either the first or second aspect.
[0020] In a seventh aspect, embodiments of this specification provide a computer program product, wherein when the computer program product is executed in a computer, the computer performs the method as described in either the first or second aspect.
[0021] The scheme provided in the embodiments of this specification can generate universal adversarial perturbations in the frequency domain. Compared with generating perturbations directly in the spatial domain, this improves the stealth performance of the adversarial perturbations. Furthermore, this scheme considers the detailed information of different frequency bands of the face image, making the generated universal adversarial perturbations more comprehensive and thus more offensive. Therefore, this scheme can generate universal adversarial perturbations with superior offensiveness and stealth for face recognition models. By superimposing this universal adversarial perturbation onto a clean face image, highly effective adversarial examples can be obtained. Using these adversarial examples to train the face recognition model can help improve the adversarial defense capability of the face recognition model and achieve privacy protection. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the various embodiments disclosed in this specification, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only a few embodiments disclosed in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of any round of iterative optimization process performed on an adversarial image in the embodiments of this specification;
[0024] Figure 2 This is a flowchart of a general adversarial perturbation generation method for face recognition models in the embodiments of this specification;
[0025] Figure 3 This is a schematic diagram of the frequency domain image generation process in the embodiments of this specification;
[0026] Figure 4 This is a flowchart of a general adversarial perturbation generation method for face recognition models in the embodiments of this specification;
[0027] Figure 5 This is a flowchart of the face adversarial example generation method in the embodiments of this specification;
[0028] Figure 6This is a schematic diagram of the general adversarial perturbation generation device for face recognition models in the embodiments of this specification;
[0029] Figure 7 This is a schematic diagram of the face adversarial sample generation device in the embodiments of this specification. Detailed Implementation
[0030] The present specification will now be described in further detail with reference to the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. The described embodiments are only a part of the embodiments described herein, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments in this specification without inventive effort are within the scope of protection of this application.
[0031] It should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described herein can be combined with each other. Furthermore, the terms "first," "second," etc., used in the embodiments of this specification are for informational purposes only and do not constitute any limitation.
[0032] As mentioned earlier, with the rapid development of artificial intelligence technology, various deep learning techniques have matured, and models built on deep neural networks are playing an increasingly important role in various classification and recognition tasks. Among them, facial recognition, as an efficient method of identity verification, is gaining popularity due to its advantages such as ease of collection, non-contact nature, and static nature. As the most convenient biometric feature, its combination with deep learning technology makes facial recognition one of the most effective artificial intelligence applications at present.
[0033] Despite the significant achievements of deep neural networks in various large-scale tasks, they still harbor some security vulnerabilities. Recent research has revealed their high susceptibility to adversarial perturbations. Adversarial perturbations involve adding imperceptible noise to the input image; even a clean image with this perturbation can cause the model to make incorrect predictions. Face recognition also faces the risks of adversarial perturbation attacks and privacy breaches. To address this issue, robust adversarial defense methods are needed.
[0034] In adversarial defense, whether it's adversarial example detection, adversarial perturbation cleanup, or improving the network's own anti-interference capabilities, all rely on effective adversarial attack algorithms. Existing methods for generating face adversarial perturbations include those that directly generate them through generative adversarial networks via gradient calculation, and others that generate unique adversarial perturbations for each individual face training sample through complex optimization methods.
[0035] Existing single adversarial perturbation generation schemes for face recognition primarily generate adversarial perturbations for specific individuals. Different objects require the generation of entirely new adversarial perturbations to meet the requirements. These schemes can be categorized into physical domain and digital domain. In the physical domain, special wearable items are generated to disrupt physical objects and deceive face recognition models. For example, adversarial glasses frames can help attackers evade face recognition or impersonate others; adversarial patterns can be generated and affixed to hats, so that even when an attacker wears a hat, their facial features are not obscured, yet the face recognition system still fails to recognize them. Similar examples include masks and makeup. In the digital domain, the feature point positions of a clean face can be modified to deceive the face recognition model. However, both physical and digital domain implementations share a drawback: they only address single face images. Generating a large number of adversarial examples requires generating perturbations individually for each image, significantly increasing the operational process and generation cost.
[0036] Compared to adversarial perturbations on specific face images, general adversarial perturbations are a method for generating adversarial examples applicable to the entire dataset. This method only requires generating a general adversarial perturbation once, which can then be linearly appended to any face image in the dataset to produce an adversarial attack effect, significantly reducing the cost of generating adversarial examples. Currently, general adversarial perturbations for faces can add imperceptible noise to the entire face image globally through optimization or generation.
[0037] Current general adversarial perturbation generation schemes for natural image classification tasks commonly employ the UAP (Universal Adversarial Perturbation) approach. It was the first to demonstrate the existence of general adversarial perturbations for non-target attacks in CNNs (Convolutional Neural Networks). It modifies the Deepfool algorithm, continuously pushing training samples across decision boundaries in the image classification model to find the shortest general adversarial perturbation distance, generating a general adversarial perturbation that can interfere with the majority of samples in the entire dataset that follow a uniform distribution. However, this scheme generates perturbations directly in the spatial domain, which is not very effective in terms of stealth. The resulting general adversarial perturbations do not achieve a good balance between offensiveness and stealth.
[0038] Since the spatial feature information of facial images is relatively fixed, the concealment effect of global perturbations is not good. Therefore, it is necessary to explore general adversarial perturbations for the concealment of facial images.
[0039] This specification provides a general adversarial perturbation and face adversarial sample generation scheme, which can generate general adversarial perturbations with better offensiveness and concealment for face recognition models. By superimposing this general adversarial perturbation onto a clean face image, highly effective face adversarial samples can be obtained. Using these face adversarial samples to train face recognition models can help improve the adversarial defense capabilities of face recognition models and achieve privacy protection.
[0040] Specifically, the solution provided in the embodiments of this specification can be divided into a data preparation stage and an iterative optimization stage. In the data preparation stage, the face recognition model F to be attacked can be determined. face That is, determining the face recognition model F that needs to improve its adversarial defense capabilities. face In one example, the face recognition model F face This may include, but is not limited to, the Arcface face recognition model. The Arcface face recognition model is a face recognition model trained on the CASIA-WebFace dataset. Its input image size can be 112*112*3, which represent the length, width and RGB three channels of the face image, respectively. The pixel values can be normalized from [0, 255] to the range of [-1, 1].
[0041] Additionally, the training and validation sets to be used in the iterative optimization phase can be determined. For example, multiple face images can be randomly selected from a predefined dataset to form the training set, and multiple face image pairs can be randomly selected from that dataset to form the validation set. Optionally, a test set comprising multiple face image pairs can also be determined, such that the test set is used to evaluate the generalization performance of the general adversarial perturbation in generating adversarial examples on unknown face images. It should be noted that a single face image pair includes two face images of the same person, such as two different face images of the same person. The training, validation, and test sets can include different face images, and the number of images in the training set can be greater than the number of face image pairs in the validation and test sets, respectively.
[0042] In one example, the pre-defined dataset may include, but is not limited to, the LFW (Labeled Faces in the Wild) dataset, and the test set may include, but is not limited to, the LFW test set. The LFW dataset contains tens of thousands of face images, such as over 13,000 face images involving more than 5,000 people. The LFW test set may include 2,000 face image pairs. Taking the LFW dataset as an example, for instance, 6,000 face images could be randomly selected from the LFW dataset to form a training set for optimizing the overlay of general adversarial perturbations, and an additional 2,000 face object pairs, whose face images differ from those in the training set, could be randomly selected to form a validation set.
[0043] It should be noted that the face images in the preset dataset and the test set can have the same size. Besides determining the face recognition model F... face In addition to the training, validation, and test sets, an adversarial perturbation image v with the same size as the face image can be determined, and the parameters in the adversarial perturbation image v can be randomly initialized, as well as the image X to be used in the iterative optimization phase can be determined. t Image X t Far removed from any image in the entire training set. Specifically, image X t It is independent of the distribution of the preset dataset. In one example, a Gaussian noise image that is independent of the distribution of the dataset can be randomly generated as image X. t .
[0044] After completing the preparatory work described above, several rounds of iterative optimization can be performed on the adversarial perturbation image v during the iterative optimization phase to obtain the final general adversarial perturbation. It should be noted that image X... t Hereinafter referred to as preset image X t .
[0045] See Figure 1 This diagram illustrates any round of iterative optimization for adversarial images in the embodiments of this specification. This iterative optimization process can be executed by any device, platform, or cluster of devices with data storage, computing, and processing capabilities. Figure 1 As shown, for each target face image x in the training set (e.g., the face images in the current batch determined in the training set), the adversarial perturbation information of the corresponding frequency band of the adversarial perturbation image v can be superimposed on the face information of different frequency bands in the frequency domain to obtain adversarial information of different frequency bands. The adversarial information of different frequency bands is then fused into full-band adversarial information X. adv Then, the facial information from different frequency bands, the adversarial information from those different frequency bands, and the full-band adversarial information X can be combined. adv The frequency domain is transformed into the spatial domain to obtain the face images of the target face image x in different frequency bands, the adversarial images in different frequency bands, and the full-band adversarial image x. adv Next, the facial recognition model F can be used to obtain... face Extracted preset image X t First image features (such as) Figure 1 The F shown face (X t )), and full-band adversarial image x adv Second image features (such as) Figure 1 The F shown face (x adv Then, it is possible to reduce F. face (x adv ) and F face (Xt The goal is to optimize the parameters in the adversarial perturbation image v by reducing the differences between face images in different frequency bands and adversarial images in the corresponding frequency bands.
[0046] Below, in conjunction with Figure 2 This section details the implementation of the iterative optimization process for any round of adversarial perturbation images. Figure 2 This is a flowchart of a general adversarial perturbation generation method for face recognition models, as described in the embodiments of this specification. This method can be executed by any device, platform, or device cluster with data storage, computing, and processing capabilities, and includes steps S201-S209 as shown below.
[0047] like Figure 2 As shown, in step S201, for each target face image in the training set, the face information in different frequency bands in the frequency domain is obtained, and the perturbation information of the adversarial perturbation image in different frequency bands is obtained.
[0048] Specifically, if the training set contains cached facial information for each target face image x in different frequency bands, then the cached facial information for each target face image x in different frequency bands can be retrieved. If the facial information for each target face image in different frequency bands is not cached, then... Figure 3 As shown, a Discrete Cosine Transform (DCT) is performed on each target face image x to obtain frequency domain face information X. Then, preset filters are used to perform frequency division on the frequency domain face information X to obtain face information in different frequency bands for each target face image x. Figure 3 This is a schematic diagram of the frequency domain image generation process in the embodiments of this specification. In one implementation, when each target face image x needs to participate in subsequent rounds of iterative optimization, after obtaining the face information of each target face image x in different frequency bands by performing frequency division operations, in order to improve the execution efficiency of the iterative optimization process, the face information of different frequency bands can be associated with the corresponding target face image x for caching.
[0049] For the image v that is being countered by perturbation, it can also be subjected to DCT transformation to obtain frequency domain perturbation information V, and then the frequency domain perturbation information V can be divided by filters to obtain perturbation information of different frequency bands of the image v that is being countered by perturbation.
[0050] It should be noted that DCT is an important mathematical tool that can be used to transform an image from the spatial domain to the frequency domain in order to extract the frequency domain features of the image. DCT can decompose an image into a series of frequency components, which can be represented as a linear combination of a set of cosine functions. The formula for DCT can be expressed as shown in formula (1) below:
[0051]
[0052] Here, X(k1,k2) represents the DCT transform of an image block of size N1 rows and N2 columns (i.e., N1×N2) at position (k1,k2), x(n1,n2) represents the pixel value at (n1,n2) in the image block, and c1 and c2 can both represent cosine functions. Typically, N1 = N2 = 8, so that an 8×8 image block x(k1,k2) in the spatial domain can be transformed into an 8×8 frequency response block X(k1,k2) in the frequency domain using DCT transform. This frequency response block can cover 64 frequency bands.
[0053] It should be noted that for any image in the target face image x and the adversarial perturbation image v, when the size of the image is greater than N1×N2, the image can be divided into multiple image blocks of N1×N2. Then, DCT transformation is performed on each of the divided image blocks to obtain the information of the image in the frequency domain.
[0054] For each frequency band covered by the frequency response block, the cutoff range of the filters can be controlled by setting the 0 and 1 values for each frequency band. In one example, the filters may include high-frequency filters (such as...). Figure 3 The High frequency filter shown in the figure), intermediate frequency filter (such as...) Figure 3 The Middle shown) and low-frequency filters (such as Figure 3 (As shown in the image, Low). Based on this, the different frequency bands mentioned above can include high-frequency bands, mid-frequency bands, and low-frequency bands.
[0055] Furthermore, it can be like Figure 3 As shown, high-frequency filters, intermediate-frequency filters, and low-frequency filters are used to extract the high-frequency face information X from the frequency domain face information X. H Facial information X in the mid-frequency band M and facial information X in the low-frequency band L Additionally, high-frequency filters, intermediate-frequency filters, and low-frequency filters can be used to extract the frequency domain disturbance information V in the high-frequency band. H The disturbance information V in the mid-frequency band M and the disturbance information V in the low-frequency band L .
[0056] Next, in step S203, perturbation information of the corresponding frequency band is superimposed on the face information of different frequency bands to obtain adversarial information of different frequency bands, and the adversarial information of different frequency bands is fused into full-band adversarial information.
[0057] Continue with Figure 3For example, as shown in the example, Figure 3 As shown, it can be facial information X H Superimposed disturbance information V H Obtain high-frequency band adversarial information X adv(H) Facial information X M Superimposed disturbance information V M Obtain mid-frequency band adversarial information X adv(M) and facial information X L Superimposed disturbance information V L Obtain low-frequency band adversarial information X adv(L) After that, the adversarial information X can be... adv(H) X adv(M) X adv(L) Fusion into full-band countermeasure information X adv .
[0058] Next, in step S205, the face information of different frequency bands, the adversarial information of different frequency bands, and the adversarial information of the whole frequency band are converted from the frequency domain to the spatial domain to obtain the face image of different frequency bands, the adversarial image of different frequency bands, and the adversarial image of the whole frequency band corresponding to the target face image.
[0059] Specifically, inverse discrete cosine transform (IDCT) can be performed on face information in different frequency bands, adversarial information in different frequency bands, and adversarial information in the whole frequency band to obtain face images in different frequency bands, adversarial images in different frequency bands, and adversarial images in the whole frequency band corresponding to the target face image x.
[0060] Continue with Figure 3 For example, as shown in Figure 3, facial information X from different frequency bands can be processed. H X M X L Countermeasure information X in different frequency bands adv(H) X adv(M) X adv(L) And full-band countermeasure information X adv Perform IDCT transformation on each image to obtain the high-frequency face image x corresponding to the target face image x. H Mid-frequency facial images x M Low-frequency facial images x L High-frequency adversarial image x adv(H) Mid-frequency adversarial image x adv(M) Low-frequency adversarial image x adv(L) and full-band adversarial image x adv .
[0061] Next, in step S207, the first image features of the preset image extracted by the face recognition model and the second image features of the full-band adversarial image are obtained; the preset image is far away from any image in the entire training set.
[0062] Specifically, in the cache, there is a face recognition model F face Extracted preset image X t Image features F face (X t In the case of ), the cached image features F can be obtained. face (X t ). In uncached image features F face (X t In the case of ), the preset image X can be t Input face recognition model F face Image feature extraction is performed to obtain the face recognition model F. face Output image features F face (X t Additionally, it is possible to use full-band adversarial images x. adv Input face recognition model F face Image feature extraction is performed to obtain the face recognition model F. face Output image features F face (x adv ).
[0063] Next, in step S209, the parameters in the adversarial perturbation image are optimized with the goal of reducing the difference between the first image features and the second image features, and reducing the difference between face images of different frequency bands and adversarial images of the corresponding frequency bands.
[0064] Specifically, in one implementation, the parameters in the adversarial perturbation image v can be optimized by performing the sub-steps S2091-S2097 shown below.
[0065] In sub-step S2091, based on the full-band adversarial image x corresponding to each target face image x, adv Image features F face (x adv ) and image features F face (X t The difference between the two losses determines the first loss. This first loss can be referred to as the adversarial loss.
[0066] According to common knowledge, cosine distance = 1 - cosine similarity. Given vectors a and b, the formula for calculating cosine similarity can be shown in formula (2) below:
[0067]
[0068] Where ρ(a,b) represents the cosine similarity between vectors a and b.
[0069] Therefore, for each target face image x in each target face image x, in its corresponding full-band adversarial image x adv Image features F face (x adv ) and preset image X t Image features F face (X t When all are feature vectors, the loss function L shown in the following formula (3) can be used. cos Based on F face (x adv ) and F face (X t The difference between them determines the sub-adversarial loss:
[0070] L cos =1-ρ(F face (X t ),F face (x adv (3)
[0071] Wherein, the loss function L cos The calculation results can be used as sub-adversarial losses. After obtaining each sub-adversarial loss, a first loss can be determined based on each sub-adversarial loss. For example, the average value of each sub-adversarial loss can be determined as the first loss.
[0072] It should be noted that by controlling L cos To make the full-band adversarial image x smaller adv and preset image X t The higher the similarity of the feature vectors, the better the ability to perform full-band adversarial attacks against image x. adv The similarity between the image and the corresponding target face image x decreases continuously, and the purpose of adversarial purposes is achieved by controlling the differences in data distribution.
[0073] In sub-step S2093, a second loss is determined based on the differences between the face images of different frequency bands corresponding to each target face image x and the adversarial images of the corresponding frequency bands. This second loss can be referred to as the concealment loss.
[0074] Specifically, for each target face image x in each target face image x, the loss function L shown in the following formula (4) can be used. crypticity Based on the differences between face images in different frequency bands and adversarial images in the corresponding frequency bands, the sub-concealment loss is determined:
[0075]
[0076] Where n can represent the number of frequency bands in different frequency bands, x i This can represent the face image corresponding to the target face image x in the i-th frequency band, x adv(i) This can represent the adversarial image corresponding to the target face image x in the i-th frequency band. The loss function L... crypticity The calculation results can be used as the sub-concealment loss.
[0077] After obtaining the concealment loss of each sub-pair, a second loss can be determined based on the concealment loss of each sub-pair. For example, the average value of the concealment loss of each sub-pair can be determined as the second loss.
[0078] It should be noted that by controlling L crypticity By reducing the size, the similarity between face images in different frequency bands and adversarial images in the corresponding frequency bands can be increased, thereby improving the concealment of general adversarial perturbations.
[0079] Next, in sub-step S2095, the total predicted loss is determined, which is positively correlated with the first loss and the second loss.
[0080] Specifically, taking L as the loss function used to calculate the total prediction loss, L1 as the loss function used to calculate the first loss, and L2 as the loss function used to calculate the second loss as an example, weight values λ1 related to the first loss and λ2 related to the second loss can be preset. The loss function L can be expressed by the following formula (5):
[0081] L=λ1L1+λ2L2 (5)
[0082] Next, in sub-step S2097, the parameters in the adversarial perturbation image v are optimized with the goal of minimizing the total prediction loss.
[0083] Specifically, the parameters in the adversarial perturbation image v can be optimized using the stochastic gradient descent algorithm, which is used to calculate the total prediction loss, based on the loss function L. As an example, the gradient value corresponding to the adversarial perturbation image v can be calculated, and this gradient value can be denoted as... Then, the parameters in the adversarial image v can be optimized based on this gradient value, for example, using the formula... Optimize the parameters in the adversarial perturbation image v. Here, η can represent the learning rate.
[0084] In one implementation, to control the intensity of the perturbation, the L∞ norm can be used to constrain the general adversarial perturbation. For example, a target threshold can be set using the L∞ norm, with the constraint that the values of the parameters in the adversarial perturbation image v do not exceed the target threshold, to optimize the parameters in the adversarial perturbation image v. It should be noted that as long as the values of the parameters in the adversarial perturbation image v do not exceed the target threshold, the effect of being invisible to the human eye can be considered to be satisfied.
[0085] Figure 2 The corresponding embodiment provides a solution that generates general adversarial perturbations in the frequency domain. Compared to directly generating perturbations in the spatial domain, this improves the stealth performance of the adversarial perturbations. Furthermore, this solution considers detailed information from different frequency bands of the face image, making the generated general adversarial perturbations more comprehensive and thus more offensive. Therefore, this solution can generate general adversarial perturbations with superior offensiveness and stealth for face recognition models. By superimposing this general adversarial perturbation onto a clean face image, highly effective adversarial examples can be obtained. Using these adversarial examples to train the face recognition model helps improve its adversarial defense capabilities and achieve privacy protection.
[0086] In one implementation, to further enhance the stealth of the general adversarial perturbation, during the data preparation stage as described above, a pre-trained image processing model can be determined for feature extraction from images of different frequency bands. This image processing model can then be used to extract the third image features of face images in different frequency bands and the fourth image features of adversarial images in different frequency bands, thereby reducing the difference between the third image features of face images in different frequency bands and the fourth image features of the corresponding adversarial images, ultimately achieving the goal of reducing the difference between face images in different frequency bands and the corresponding adversarial images.
[0087] The image processing model can include, but is not limited to, the VGG (Visual Geometry Group) network. The VGG network is a classic convolutional neural network model in deep learning; its shallow layers can learn features such as image texture and contours. Extracting shallow features from face images and adversarial images of different frequency bands using the VGG network, and then using these shallow features to calculate the concealment loss, can improve the concealment of the final generated general adversarial perturbation.
[0088] See Figure 4 This is a flowchart of a general adversarial perturbation generation method for face recognition models in the embodiments of this specification. This method can be executed by any device, platform, or device cluster with data storage, computing, and processing capabilities, and includes steps S401-S417 as shown below.
[0089] like Figure 4 As shown, in step S401, for each target face image in the training set, the face information in different frequency bands in the frequency domain is obtained, and the perturbation information of the adversarial perturbation image in different frequency bands is obtained.
[0090] Next, in step S403, perturbation information of the corresponding frequency band is superimposed on the face information of different frequency bands to obtain adversarial information of different frequency bands, and the adversarial information of different frequency bands is fused into full-band adversarial information.
[0091] Next, in step S405, the face information of different frequency bands, the adversarial information of different frequency bands, and the adversarial information of the whole frequency band are converted from the frequency domain to the spatial domain to obtain the face image of different frequency bands, the adversarial image of different frequency bands, and the adversarial image of the whole frequency band corresponding to the target face image.
[0092] Next, in step S407, the first image features of the preset image extracted by the face recognition model and the second image features of the full-band adversarial image are obtained; the preset image is far away from any image in the entire training set.
[0093] It should be noted that, in order to improve the efficiency of iterative optimization, step S407 and step S411 (described below) can be executed in parallel. Furthermore, after executing step S407, step S409 can be executed next.
[0094] In step S409, a first loss is determined based on the difference between the second image features and the first image features of the full-band adversarial image corresponding to each target face image.
[0095] For an explanation of steps S401-S409, please refer to the relevant explanations of steps S201-S209 in the previous text, which will not be repeated here.
[0096] In step S411, the pre-trained VGG network is used to extract the third image features of face images in different frequency bands and the fourth image features of adversarial images in different frequency bands.
[0097] Specifically, face images and adversarial images of different frequency bands can be input into the VGG network for image feature extraction processing to obtain the third image features of the face images of different frequency bands and the fourth image features of the adversarial images of different frequency bands output by the VGG network.
[0098] Next, in step S413, a second loss is determined based on the difference between the third image features of the face image corresponding to each target face image in different frequency bands and the fourth image features of the adversarial image in the corresponding frequency band.
[0099] Specifically, for each target face image x in each target face image x, the loss function L shown in the following formula (6) can be used. VGC Based on the differences between the third image features of face images in different frequency bands and the fourth image features of adversarial images in the corresponding frequency bands, the sub-concealment loss is determined:
[0100]
[0101] Where n can represent the number of frequency bands in different frequency bands, x i VGG(x) can represent the face image corresponding to the target face image x in the i-th frequency band. i ) can represent a face image x i The third image feature, x adv(i) VGG(x) can represent the adversarial image corresponding to the target face image x in the i-th frequency band. adv(i) ) can represent the adversarial image x adv(i) The fourth image feature. Loss function L VGG The calculation results can be used as sub-concealment loss.
[0102] After obtaining the concealment loss of each sub-pair, a second loss can be determined based on the concealment loss of each sub-pair. For example, the average value of the concealment loss of each sub-pair can be determined as the second loss.
[0103] Next, in step S415, the total predicted loss is determined, which is positively correlated with the first loss and the second loss.
[0104] Next, in step S417, the parameters in the adversarial perturbation image are optimized with the goal of minimizing the total prediction loss.
[0105] For an explanation of steps S415 and S417, please refer to the relevant explanations of sub-steps S2095 and S2097 of step S209 in the previous text, which will not be repeated here.
[0106] exist Figure 4 The corresponding embodiment provides a solution that generates general adversarial perturbations in the frequency domain. Compared to generating perturbations directly in the spatial domain, this improves the stealth performance of the adversarial perturbations. Furthermore, this solution considers detailed information from different frequency bands of the face image, making the generated general adversarial perturbations more comprehensive and thus more offensive. Additionally, by extracting shallow features from face images and adversarial images of different frequency bands using a VGG network and applying these shallow features to the stealth loss calculation, the final generated general adversarial perturbations exhibit even better stealth. Therefore, this solution generates general adversarial perturbations with superior offensiveness and stealth for face recognition models. By superimposing this general adversarial perturbation onto a clean face image, more effective adversarial samples can be obtained. Using these adversarial samples to train the face recognition model helps improve its adversarial defense capabilities and achieves privacy protection.
[0107] In one implementation, during the iterative optimization process, to find a general adversarial perturbation with better generalization ability, after each iteration, the attack success rate of the optimized adversarial perturbation image can be verified using a validation set. If the attack success rate reaches a predetermined success rate, the optimized adversarial perturbation image can be determined as the final general adversarial perturbation, and the optimized adversarial perturbation image is stored, thus ending the iterative optimization of the adversarial perturbation image. If the attack success rate does not reach the predetermined success rate, the adversarial perturbation image can be subjected to the next round of iterative optimization.
[0108] It should be noted that when verifying the attack success rate of the optimized adversarial perturbation image using a validation set, the optimized adversarial perturbation image can be superimposed on the first face image included in each of the multiple image pairs in the validation set to obtain adversarial face images. Each image pair includes the first and second face images of the same person. Then, for each image pair, the fifth image feature of the second face image in that pair, extracted by the face recognition model, and the sixth image feature of the adversarial face image corresponding to the first face image in that pair can be obtained. Then, the attack success rate of the optimized adversarial perturbation image can be determined based on the similarity between each fifth image feature and its corresponding sixth image feature. Furthermore, for each generated adversarial face image, if the similarity between the sixth image feature and its corresponding fifth image feature does not reach a similarity threshold, it can be determined that the adversarial face image caused the face recognition model to make an incorrect prediction, thus classifying the adversarial face image as a successfully attacked image. Then, the ratio of successfully attacked images to the total number of successfully attacked images in each generated adversarial face image can be calculated, and this ratio can be determined as the attack success rate of the optimized adversarial perturbation image.
[0109] Based on the preceding description, this specification proposes a frequency-adaptive general adversarial perturbation generation method for face recognition, addressing the issue of concealment in general adversarial perturbations. This method can disrupt the facial representation information of a face recognition model. Unlike existing methods that generate perturbations in the spatial domain, the proposed method generates three frequency domain perturbations based on the high, mid, and low frequency characteristics of the face image. These perturbations are then fused and inversely transformed into the spatial domain to generate the final perturbation. This method considers more detailed and concealed frequency information, achieving a superior overall performance in terms of attack power and attack concealment.
[0110] Furthermore, the method proposed in the embodiments of this specification unifies targeted and non-targeted attacks within the framework of targeted attacks, enabling the achievement of non-targeted attack tasks through targeted attacks. For targeted attack tasks, simply setting the preset image as the face image of the target as described above suffices. For non-targeted attack tasks, the preset image can be set as a random image (such as a random noise image). By inputting the random image and a face image with added general adversarial perturbation (a full-band adversarial image) into the face recognition model, the cosine distance of the output is calculated. By controlling the cosine distance between the full-band adversarial image and the random image to continuously narrow, the cosine distance between the full-band adversarial image and the clean face image is continuously widened, i.e., the full-band adversarial image moves away from the distribution of the clean face image dataset, thereby optimizing the general adversarial perturbation through gradient backpropagation.
[0111] In one implementation, after performing several rounds of iterative optimization on the adversarial perturbation image as described above to obtain a final general adversarial perturbation image, the adversarial perturbation image can be used to generate adversarial face samples.
[0112] Specifically, see Figure 5 This is a flowchart of the face adversarial example generation method in the embodiments of this specification. The method can be executed by any device, platform, or device cluster with data storage, computing, and processing capabilities, and includes steps S501-S505 as shown below.
[0113] like Figure 5 As shown, in step S501, an anti-perturbation image is acquired, which is obtained by employing methods such as... Figure 2 The method described was obtained after several rounds of iterative optimization.
[0114] In step S503, several face images to be perturbed are acquired.
[0115] As an example, when it is necessary to generate adversarial examples of faces based on several face images in the preset dataset described above, several face images to be perturbed can be obtained from the dataset.
[0116] Next, in step S505, for each face image in the plurality of face images, an adversarial perturbation image is superimposed on the face image to obtain face adversarial samples.
[0117] Figure 5 The corresponding implementation provides a solution by obtaining and adopting, as shown in the example. Figure 2The described method involves obtaining an adversarial perturbation image after several rounds of iterative optimization, acquiring several face images to be perturbed, and overlaying the adversarial perturbation image onto each of these face images. This method can generate highly effective adversarial face examples with low generation cost. These adversarial face examples are then used for training. Figure 2 The facial recognition model described in the method can help improve the adversarial defense capabilities of the facial recognition model and achieve privacy protection.
[0118] Figure 6 This is a schematic diagram of the general adversarial perturbation generation device for face recognition models, as described in the embodiments of this specification. This device can be applied to any device, platform, or device cluster with data storage, computing, and processing capabilities. This device can perform actions such as... Figure 2 , Figure 4 The method described herein implements any one of several rounds of iterative optimization through the following units: a first acquisition unit 601 is configured to acquire face information in different frequency bands of each target face image in the training set, and acquire perturbation information of the adversarial perturbation image in different frequency bands; a perturbation unit 602 is configured to superimpose the face information in different frequency bands with the corresponding perturbation information to obtain adversarial information in different frequency bands, and fuse the adversarial information in different frequency bands into full-band adversarial information; a conversion unit 603 is configured to convert the face information in different frequency bands, the adversarial information in different frequency bands, and... The full-band adversarial information is converted from the frequency domain to the spatial domain to obtain face images of different frequency bands, adversarial images of different frequency bands, and full-band adversarial images corresponding to the target face image; the second acquisition unit 604 is configured to acquire the first image features of the preset image extracted by the face recognition model, and the second image features of the full-band adversarial image; the preset image is far away from any image in the entire training set; the optimization unit 605 is configured to optimize the parameters in the adversarial perturbation image with the goal of reducing the difference between the first image features and the second image features, and reducing the difference between the face images of different frequency bands and the adversarial images of the corresponding frequency bands.
[0119] Figure 7 This is a schematic diagram of the face adversarial example generation device in the embodiments of this specification. This device can be applied to any device, platform, or device cluster with data storage, computing, and processing capabilities. This device can perform actions such as... Figure 5 The described method includes: a first acquisition unit 701 configured to acquire an adversarial perturbation image, which acquires an adversarial perturbation image by employing, for example... Figure 2 The method described is obtained after several rounds of iterative optimization; the second acquisition unit 702 is configured to acquire several face images to be perturbed; the perturbation unit 703 is configured to superimpose an adversarial perturbation image on each face image in the several face images to obtain face adversarial samples.
[0120] This specification also provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, it causes the computer to perform actions such as... Figure 2 , Figure 4 , Figure 5 The method described.
[0121] This specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements, as shown in the embodiment. Figure 2 , Figure 4 , Figure 5 The method described.
[0122] This specification also provides a computer program product, wherein when the computer program product is executed in a computer, it causes the computer to perform the following: Figure 2 , Figure 4 , Figure 5 The method described.
[0123] Those skilled in the art will recognize that the functions described in the various embodiments disclosed in this specification in one or more of the examples above can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.
[0124] In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0125] The specific embodiments described above further illustrate the purpose, technical solutions, and beneficial effects of the multiple embodiments disclosed in this specification. It should be understood that the above descriptions are merely specific implementations of the multiple embodiments disclosed in this specification and are not intended to limit the protection scope of the multiple embodiments disclosed in this specification. Any modifications, equivalent substitutions, improvements, etc., made based on the technical solutions of the multiple embodiments disclosed in this specification should be included within the protection scope of the multiple embodiments disclosed in this specification.
Claims
1. A general adversarial perturbation generation method for face recognition models, the method involving several rounds of iterative optimization, wherein any round of iterative optimization includes: For each target face image in the training set, obtain its face information in different frequency bands in the frequency domain, and obtain the perturbation information of the adversarial perturbation image in different frequency bands. The perturbation information of the corresponding frequency band is superimposed on the facial information of the different frequency bands to obtain the adversarial information of the different frequency bands, and the adversarial information of the different frequency bands is fused into full-band adversarial information; The face information of different frequency bands, the adversarial information of different frequency bands, and the adversarial information of the whole frequency band are transformed from the frequency domain to the spatial domain to obtain the face image of different frequency bands, the adversarial image of different frequency bands, and the adversarial image of the whole frequency band corresponding to the target face image. Obtain the first image features of the preset image extracted by the face recognition model, and the second image features of the full-band adversarial image; the preset image is far away from any image in the entire training set; With the goal of reducing the difference between the first image features and the second image features, and reducing the difference between the face images of different frequency bands and the adversarial images of the corresponding frequency bands, the parameters in the adversarial perturbation image are optimized.
2. The method according to claim 1, wherein, Before performing the aforementioned rounds of iterative optimization, the following is also included: The parameters in the adversarial perturbation image are randomly initialized.
3. The method according to claim 1, wherein, The acquisition of facial information in different frequency bands in the frequency domain, and the acquisition of perturbation information of the anti-perturbation image in different frequency bands, include: Discrete cosine transform is performed on each target face image and the adversarial perturbation image to obtain the frequency domain face information of each target face image and the frequency domain perturbation information of the adversarial perturbation image. The frequency domain face information and the frequency domain perturbation information are divided by a preset filter to obtain the face information of each target face image in different frequency bands, and the perturbation information of the perturbation image in different frequency bands. The step of converting the facial information of different frequency bands, the adversarial information of different frequency bands, and the full-band adversarial information from the frequency domain to the spatial domain includes: Inverse discrete cosine transform is performed on the facial information of different frequency bands, the adversarial information of different frequency bands, and the adversarial information of the entire frequency band.
4. The method according to claim 3, wherein, The filter includes a high-frequency filter, a mid-frequency filter, and a low-frequency filter, and the different frequency bands include a high-frequency band, a mid-frequency band, and a low-frequency band.
5. The method according to claim 1, further comprising: Using a pre-trained image processing model, the third image features of each face image in different frequency bands and the fourth image features of each adversarial image in different frequency bands are extracted. The reduction of the difference between face images of different frequency bands and adversarial images of corresponding frequency bands includes: Reduce the difference between the third image features of each face image in different frequency bands and the fourth image features of the adversarial image in the corresponding frequency band.
6. The method according to claim 5, wherein, The image processing model includes the Visual Geometry Group (VGG) network.
7. The method according to claim 1, wherein, The optimization of parameters in the adversarial perturbation image, aimed at reducing the difference between the first image features and the second image features, and reducing the difference between the face images of different frequency bands and the adversarial images of the corresponding frequency bands, includes: The first loss is determined based on the difference between the second image features and the first image features of the full-band adversarial image corresponding to each target face image; The second loss is determined based on the difference between the face images of different frequency bands corresponding to each target face image and the adversarial images of the corresponding frequency bands; Determine the total predicted loss, which is positively correlated with the first loss and the second loss; The parameters in the adversarial perturbation image are optimized with the goal of minimizing the total prediction loss.
8. The method according to claim 1, wherein, The optimization of parameters in the anti-perturbation image includes: The parameters in the adversarial perturbation image are optimized with the constraint that the values of the parameters in the adversarial perturbation image do not exceed a target threshold; wherein the target threshold is set by using the L∞ norm.
9. The method according to any one of claims 1-8, wherein, After completing any of the aforementioned rounds of iterative optimization, the process also includes: To verify the adversarial perturbation image after superimposing and optimizing the first face image included in the set of multiple image pairs, a face adversarial image is obtained; wherein, a single image pair includes the first face image and the second face image of the same person; For each of the plurality of image pairs, the fifth image feature of the second face image in the image pair is obtained by the face recognition model, and the sixth image feature of the adversarial face image corresponding to the first face image in the image pair is obtained. The attack success rate of the optimized adversarial perturbation image is determined based on the similarity between each fifth image feature and its corresponding sixth image feature. If the attack success rate reaches the predetermined success rate, the optimized adversarial perturbation image is stored, and the iterative optimization of the adversarial perturbation image ends. If the attack success rate does not reach the predetermined success rate, the adversarial perturbation image will be iterated and optimized in the next round.
10. A method for generating adversarial examples of faces, comprising: An adversarial image is obtained by performing several rounds of iterative optimization using the method described in claim 1. Obtain several face images to be perturbed; For each face image in the plurality of face images, the adversarial perturbation image is superimposed on the face image to obtain face adversarial samples.
11. A general adversarial perturbation generation device for face recognition models, wherein the device implements any one of several rounds of iterative optimization through the following units: The first acquisition unit is configured to acquire face information in different frequency bands in the frequency domain for each target face image in the training set, and to acquire perturbation information of the adversarial perturbation image in different frequency bands. The perturbation unit is configured to superimpose the perturbation information of the corresponding frequency band onto the face information of the different frequency bands to obtain the adversarial information of the different frequency bands, and to fuse the adversarial information of the different frequency bands into full-band adversarial information; The conversion unit is configured to convert the face information of different frequency bands, the adversarial information of different frequency bands, and the full-band adversarial information from the frequency domain to the spatial domain, so as to obtain the face image of different frequency bands, the adversarial image of different frequency bands, and the full-band adversarial image corresponding to the target face image; The second acquisition unit is configured to acquire the first image features of a preset image extracted by the face recognition model, and the second image features of the full-band adversarial image; the preset image is far away from any image in the entire training set; The optimization unit is configured to optimize the parameters in the adversarial perturbation image with the goal of reducing the difference between the first image features and the second image features, and reducing the difference between the face images of different frequency bands and the adversarial images of the corresponding frequency bands.
12. A face adversarial sample generation device, comprising: The first acquisition unit is configured to acquire an adversarial image, which is obtained by performing several rounds of iterative optimization using the method described in claim 1. The second acquisition unit is configured to acquire several face images to be perturbed; The perturbation unit is configured to overlay the adversarial perturbation image onto each of the plurality of face images to obtain adversarial face samples.
13. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed in the computer, it causes the computer to perform the method according to any one of claims 1-10.
14. A computing device comprising a memory and a processor, wherein, The memory stores executable code, and when the processor executes the executable code, it implements the method of any one of claims 1-10.
Citation Information
Patent Citations
Method and device for generating face adversarial patch
CN111738217A
Face verification privacy protection method and device
CN116311439A