Verifiable robustness optimization method in adversarial environments based on masked autoencoders

By adopting a mask autoencoder-based approach, the challenge of verifiable robustness evaluation of deep learning models in adversarial environments is solved, achieving fast and reliable image cleansing and robustness evaluation. The random smoothing technique is optimized to improve the accuracy and global representativeness of the evaluation.

CN119418155BActive Publication Date: 2026-01-06HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411463375.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-21
Publication Date
2026-01-06
Estimated Expiration
2044-10-21

AI Technical Summary

Technical Problem

Existing methods struggle to accurately assess the verifiable robustness of deep learning models in adversarial environments, and the cleansing model is typically a black box that cannot be theoretically proven, impacting the mathematical proof process of stochastic smoothing methods.

Method used

We employ a mask autoencoder-based approach, employing random attacks on the dataset, evaluation of the boundary curvature of adversarial sample distributions, mask autoencoder reconstruction, and global smoothing optimization to design a fast and reliable image purification model and optimize the random smoothing process.

Benefits of technology

It achieves fast and reliable image cleansing in adversarial environments, improves the accuracy and global representativeness of verifiable robustness assessment, avoids the influence of chance, has faster inference speed, and has significant cleansing effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119418155B_ABST
    Figure CN119418155B_ABST
Patent Text Reader

Abstract

The application provides a verifiable robustness optimization method in an adversarial environment based on a mask autoencoder, and comprises the following steps: firstly, an image dataset is acquired, and random attacks and preprocessing are performed on the dataset; then, distribution boundary curvature evaluation is performed on adversarial samples in the dataset after the random attacks, and the adversarial samples with low purifying potential are removed according to the evaluation results; secondly, the mask autoencoder is used to reconstruct the adversarial samples after the purification and removal, so that purified samples are obtained; finally, global smoothing optimization is performed on the purified samples to improve the global representativeness. The method can effectively purify the samples after the adversarial attacks, and can avoid the problem that the purification model is a black box and cannot be theoretically proved through process design, and moreover, the method process of the random smoothing technology is optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of adversarial attack and defense and information protection technology, specifically to a verifiable robustness optimization method based on a mask autoencoder in an adversarial environment. Background Technology

[0002] With the success of deep learning in various application fields, deep learning models have been widely deployed in many commercial systems, including critical systems with extremely high security requirements, such as autonomous driving and AI-assisted diagnostic systems. Therefore, the security, reliability, and robustness of deep learning models are receiving increasing attention. However, research has shown that deep learning models are highly vulnerable to adversarial examples, which are constructed by adding subtle perturbations to benign examples and can mislead the model into making incorrect final decisions with high confidence. In recent years, there has been a significant amount of research on model robustness relying on empirical methods, such as Adversarial Training, which has played a certain role. However, these defensive methods are often quickly broken by more powerful adaptive attacks and cannot fundamentally guarantee the robustness of the model.

[0003] Verifiable robustness is considered a method that provides a robustness lower bound guarantee for deep learning models. It is a rigorous model credibility metric based on mathematical proof. In image classification tasks, verifiable robustness can measure the robustness lower bound of a classifier and calculate the robustness radius for each image sample, indicating that norm attacks of all attack strengths within this radius will not interfere with the classification results of the classifier. This technique has several advantages, such as: (1) ensuring that the model can maintain its performance and prediction reliability when facing adversarial examples, preventing malicious attackers from using adversarial examples to launch attacks; (2) providing compliance standards for deep learning models to operate under legal and regulatory frameworks; and (3) effectively preventing malicious use of datasets and promoting data sharing and technological progress.

[0004] In recent years, with the continuous development of deep learning technology, Lecuyer et al. proposed the random smoothing technique in 2019. Random smoothing can transform any base classifier into a new "smooth classifier" that is provably robust under the Euclidean norm, and it was used to train the first provably robust classifier for ImageNet. Cohen et al. proved that the first tight robustness guarantees random smoothing and used the Monte Carlo algorithm to solve the problem of the inability to accurately calculate the robustness radius. Subsequent research has employed different training strategies to maximize the certified robustness radius, including the ensemble method proposed by Horvath and adversarial training of the smoothing model proposed by Salman et al. Furthermore, Yang et al. extended this method to general bilinear perturbations by employing noise of different shapes.

[0005] In summary, the field of verifiable robustness is a topic worthy of in-depth research. This patent aims to explore this topic from several key aspects of the field and address the difficulties and key points of current methods.

[0006] A key aspect of verifiable robustness is prioritizing dataset security; a malicious attack on the dataset will lead subsequent inference chains to incorrect results. However, most current methods simply adhere to this premise without considering how to ensure the correct evaluation of verifiable robustness in adversarial environments. Specifically, there are two main challenges:

[0007] 1. How to correctly evaluate the verifiable robustness of a model in an adversarial environment. This mainly focuses on image sample cleansing and restoration, exploring how to design a fast and reliable image cleansing model that comprehensively considers time efficiency and cleansing capability.

[0008] 2. The distribution of the cleaned image will deviate from the original distribution, affecting the mathematical proof of the random smoothing method. However, the cleansing model is usually a black box, making it impossible to determine the mathematical relationship between the distributions before and after cleansing. Therefore, measuring the impact of the cleaned image distribution on the results and re-proving the verifiable robustness radius of the classifier is a necessary task. Summary of the Invention

[0009] The purpose of this invention is to address the shortcomings of existing technologies by proposing a verifiable robustness optimization method based on a masked autoencoder in adversarial environments. This method can effectively clean up samples after adversarial attacks and avoids the problem that the cleanup model is a black box and cannot be theoretically proven through process design. Furthermore, it optimizes many methods and processes of random smoothing techniques.

[0010] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows:

[0011] A verifiable robustness optimization method based on mask autoencoder in adversarial environments includes the following steps:

[0012] Step 1: Random attack on the dataset;

[0013] Step 2: Evaluation of the boundary curvature of the adversarial sample distribution;

[0014] Step 3: Reconstruct sanitized adversarial examples using a masked autoencoder;

[0015] Step 4: Use global smoothing optimization to improve the global representativeness of the results;

[0016] Step 5: Evaluate the results by running a random smoothing method on the purified samples.

[0017] As a preferred approach, step 1 involves a random attack on the dataset, with the specific steps as follows:

[0018] 1-1. Random Attack. This involves using existing methods to perform white-box attacks on image samples in the dataset, causing them to deviate from the original image distribution and altering the classifier's label.

[0019] 1-2. Image cropping and scaling to match the input of the mask autoencoder.

[0020] As a preferred option, step 2 involves evaluating the boundary curvature of the adversarial sample distribution, and the specific steps are as follows:

[0021] 2-1. Use a pre-trained classification network as classifier E to sample the image samples in L2 norm spheres with different noise intensities of σ.

[0022] 2-2. For each noise intensity σ, the sampling result is quantified by entropy to determine the degree of disorder in the distribution information within the sampling range. The entropy expression is:

[0023]

[0024] Where the random variable X represents the sample being calculated, p(x) i ) is the probability that a random variable X is classified as a different label by a classifier.

[0025] 2-3. Samples with low purification potential are eliminated in advance, and specific results are returned directly.

[0026] Preferably, the pre-trained classification network in step S2 is BEiT.

[0027] As a preferred option, step 3 uses a masked autoencoder to reconstruct and clean up the adversarial sample. The specific steps are as follows:

[0028] 3-1. For adversarial examples, Grad-CAM technique is used to reveal the decision-making process of convolutional neural networks. The activation map H of the last convolutional layer and the gradient c obtained through backpropagation are used. Gradient c reflects the sensitivity of the network output (i.e., the class score) to the features of the convolutional layer. Finally, we combine gradient c and the activation map H of the convolutional layer to calculate the sum of weighted feature maps, thus obtaining the activation map of a class. This process can be represented as a weighted summation operation, where the activation value of each feature map is multiplied by its corresponding gradient value and then summed. These locations that contribute significantly to the result are often also the locations where noise is concentrated.

[0029] 3-2. Employing an activation mapping-based approach The masking strategy is used to perform batch masking on the adversarial sample X, masking a portion of the adversarial noise and other random locations each time, resulting in the masked input.

[0030] 3-3. Transform the input after the mask The input is fed into the encoder part of a pre-trained masked autoencoder. The encoder is a neural network that compresses the input into a low-dimensional latent space representation. This indicates that the key features of the input data have been captured. Then, the decoder part of the pre-trained masked autoencoder is used for reconstruction, resulting in the reconstructed data. This reconstruction process attempts to restore the visible parts of the original input, fill in the masked parts, and finally integrate them through a consolidation operation. Restore to the original image after purification This means that the reconstructed patch is placed in the spatial context of the original image to form a complete image;

[0031] 3-4. For all batches of reconstructed original images The data distribution is weighted at the pixel level to obtain the final purified image.

[0032] The above technical solution uses a novel approach to clean up samples after adversarial attacks and designs a reasonable masking strategy to achieve the cleanup objective.

[0033] As a preferred option, step 4 uses global smoothing optimization to improve the global representativeness of the results, as follows:

[0034] 4-1. The purified input sample Sampling is performed, and for each sampling, in the sample Samples are taken from an L2 norm sphere with ambient noise intensity σ and fed into a classifier to obtain a confidence vector.

[0035] 4-2. Store all confidence vectors in a set. For each element in the set, perform a weighted average with C other random elements to obtain the final result, in order to avoid the randomness of the result.

[0036] 4-3. Convert the weighted average global confidence vector into a label y for output.

[0037] In the above technical solution, samples with low purification potential are eliminated in advance by analyzing the boundary curvature of the adversarial sample distribution, a combined masking strategy is used to purify the image, and global smoothing technology is used to ensure the globality of the result.

[0038] This invention has the following characteristics and beneficial effects:

[0039] Using the above technical solution, this method addresses the shortcomings of previous verifiable robustness evaluation methods in adversarial environments by innovatively proposing a sanitization method based on a mask autoencoder, which offers faster inference speed compared to traditional diffusion-based sanitization methods. Simultaneously, the random smoothing method is optimized to better reflect the global distribution. Experimental results clearly demonstrate the efficiency and practicality of the proposed method. The proposed method provides a more comprehensive consideration of verifiable robustness evaluation methods.

[0040] The specific features are as follows: (1) It makes the evaluation method suitable for a strict adversarial attack environment; (2) The purification method has a fast reasoning speed and a significant purification effect; (3) It uses information entropy to evaluate the boundary curvature of the adversarial sample distribution and screens data in advance based on the purification potential; (4) The evaluation output results can better reflect global characteristics and avoid the influence of randomness on the results; (5) The method process has strong transferability. Attached Figure Description

[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 This is a flowchart illustrating the working architecture of an embodiment of the present invention.

[0043] Figure 2 This is a flowchart illustrating the purification method according to an embodiment of the present invention.

[0044] Figure 3 The results show the comparison of evaluation indicators between the embodiments of the present invention and the prior art.

[0045] Figure 4This is the result of a comparison experiment of the purification rate of this method with other methods. Detailed Implementation

[0046] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.

[0047] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.

[0048] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art will understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0049] This invention provides a verifiable robustness optimization method for adversarial environments based on a masked autoencoder, such as... Figure 1 As shown, it includes the following steps:

[0050] Step 1: Obtain the image dataset and perform random attacks and preprocessing on the dataset. Specifically:

[0051] Random attack: White-box attack on image samples in the dataset using existing methods to make them deviate from the original image distribution and change the classifier's classification label. Specifically, the autoAttack library is used to select the attack model, and the corresponding common attack strength is set according to the dataset to carry out the attack.

[0052] Preprocessing: Image cropping and scaling to make the samples match the input of the masked autoencoder. For the ImageNet dataset, it is cropped to a size of 224*224 to fit the input of the model in subsequent steps.

[0053] Step 2: Evaluate the distribution boundary curvature of adversarial samples in the dataset after random attacks, and remove adversarial samples with low cleanup potential based on the evaluation results.

[0054] Specifically, the steps are as follows:

[0055] 2-1. Using a pre-trained noise-robust classification network as the classifier E, samples are taken from L2 norm spheres with different noise intensities σ in the image samples.

[0056] In this embodiment, BEiT is used as classifier E. It should be noted that other classification networks are also applicable to the technical solution of this invention. For example, ResNet50 can replace BEiT as classifier E.

[0057] Furthermore, in this embodiment, the value of σ is 0.00, 0.25, 0.50, 0.75, and 1.00.

[0058] 2-2. For each noise intensity σ, the entropy is used to quantify the disorder of the distributed information within the sampling range.

[0059] The specific method is as follows: Samples are taken at different noise intensities and fed into classifier E to obtain the top K labels corresponding to the confidence vector of each sampling point. The frequency of the top 3 labels in the total sample points and the changes in the top 3 labels after changes in noise intensity σ are also analyzed. The curvature of the distribution boundary corresponding to a specific entropy value is calculated as a measure of the potential for purification; its expression is:

[0060]

[0061] Where the random variable X represents the sample being calculated, p(x) i ) is the probability that a random variable X is classified as a different label by a classifier.

[0062] Understandably, entropy can reflect the curvature of the distribution boundary of the current samples to a certain extent, and thus serve as a measure of cleansing potential. Specifically, if the entropy of a batch of data is high, then their distribution in Gaussian space may be more dispersed, and their cleansing potential is smaller, because they do not belong to multiple labels for the classifier.

[0063] 2-3. Samples with low purification potential should be eliminated in advance.

[0064] Specifically, the top 3 labels were obtained under four different σ values, for a total of 12 label data.

[0065] It should be noted that, in the ideal case (with a stable distribution boundary), the top 3 labels are the same for each σ. In this case, after deduplication of 12 labels, there are only 3 labels, and the entropy value reaches its minimum. In the worst case, after deduplication, there are 12 labels, and the entropy value reaches its maximum.

[0066] Therefore, selecting an appropriate entropy value can define the curvature threshold of the distribution boundary curve, thereby excluding samples that are difficult to clean because they are located at a "convex point". In this embodiment, the entropy values ​​of the 12 distributions range from approximately 1.75 to 3.25. Through experiments, 2.5 was set as the entropy threshold to represent that the distribution boundary of the classifier for the current sample is "convex".

[0067] Step 3: Use a masked autoencoder to reconstruct the cleaned adversarial samples to obtain the cleaned samples.

[0068] The specific steps are as follows:

[0069] 3-1. For adversarial examples, we use the CAM heatmap H and the gradient c obtained from the backpropagation of the network. The gradient c reflects the sensitivity of the network output (i.e., the class score) to the convolutional layer features. Finally, we combine the gradient c and the convolutional layer activation map H to calculate the sum of the weighted feature maps, thereby obtaining the activation mapping of a class. This process can be represented as a weighted summation operation, where the activation value of each feature map is multiplied by its corresponding gradient value and then summed; the output of the deactivated convolutional layer is then calculated.

[0070] This can be understood as these locations that contribute significantly to the results are usually also locations where noise is concentrated. Depending on the need for fine granularity in the heatmap, appropriate layers can be selected, such as 7*7 or 14*14.

[0071] In this embodiment, 14*14 is used, that is, for the cropped 224*224 size ImageNet dataset, the size of each image patch is 16*16.

[0072] 3-2. Employing an activation mapping-based approach The masking strategy is used to mask the adversarial sample X in batches, with each mask overwriting the activation map. The input after masking is obtained from some highly activated regions and some randomly selected background regions.

[0073] The high activation region refers to the region where anti-noise may be concentrated.

[0074] Considering that high values ​​in a heatmap often correspond to key image features and are also areas of concentrated adversarial noise, masking these features can effectively cover adversarial regions. However, masking key features can negatively impact image reconstruction. To address this contradiction, this embodiment employs a batch masking strategy, which primarily satisfies the following points:

[0075] 1. The single mask distribution needs to meet a certain degree of randomness and cannot mask continuous areas, which is related to the reconstruction effect of the mask autoencoder.

[0076] 2. Pre-extract all feature locations, i.e., adversarial regions, and mask a portion of them each time to ensure that every location is masked overall.

[0077] 3. A random masking strategy is adopted for other background parts to ensure the randomness of the results, while also taking into account the purification of background noise.

[0078] 3-3. Transform the input after the mask The input is fed into the encoder part of a pre-trained masked autoencoder. Understandably, the encoder is a neural network that compresses the input into a low-dimensional latent space representation. This indicates that the key features of the input data have been captured. Then, the decoder part of the pre-trained masked autoencoder is used for reconstruction, resulting in the reconstructed data. This reconstruction process attempts to restore the visible parts of the original input, fill in the masked parts, and finally integrate them through a consolidation operation. Restore to the original image after purification This means that the reconstructed patch is placed in the spatial context of the original image to form a complete image.

[0079] 3-4. For all batches of reconstructed original images The data distribution is weighted at the pixel level to obtain the final purified image. Specifically, such as Figure 2 As shown.

[0080] Step 4: Perform global smoothing optimization on the cleaned samples to improve global representativeness. The specific steps are as follows:

[0081] 4-1. The purified input sample Sampling is performed, and for each sampling, in the sample Samples are taken from an L2 norm sphere with an ambient noise intensity of σ, and fed into a classifier to obtain confidence vectors. Here, the total number of samples taken is set to N, and the final result is these N confidence vectors.

[0082] 4-2. Store all confidence vectors in a set. For each element in the set, perform a weighted average with C other random elements to obtain the final result, in order to avoid the randomness of the result.

[0083] Understandably, the larger the value of C (e.g., around 10), the better it represents the global distribution within the L2 norm sphere. This strategy is beneficial for samples with stable surrounding distributions. In contrast, this method has already eliminated unstable samples in advance through curvature analysis.

[0084] 4-3. Convert the weighted average global confidence vector into a label y for output.

[0085] Finally, to further illustrate the effectiveness of the technical solution in this embodiment, the results of running a random smoothing method on the purified samples are evaluated. The specific steps are as follows:

[0086] First, for the input sample Perform n0 samplings within an L2 norm sphere of Gaussian noise with intensity σ, and input the samples into the classifier to obtain the initial predicted class.

[0087] Repeat the above sampling steps, but perform a larger number of n samples, input them into the classifier to obtain the main classification result, and calculate... The lower bound of the confidence score. The confidence score set of the main classification results is as follows: Then you can get The expression for the lower bound of the confidence level:

[0088]

[0089] If p a If the value is greater than 0.5, return the predicted class and robustness radius; otherwise, discard the result. The formula for calculating the robustness radius is:

[0090]

[0091] To verify the efficiency of the proposed method, it is compared with current excellent methods (such as randomizedsmoothing, DiffSmooth, etc.), the inference time and verifiable robustness radius are calculated, and the sample results are integrated and statistically analyzed to determine the lower bound of the model's robustness. The method is also calculated on multiple datasets and models to analyze its reusability.

[0092] The experimental results of this embodiment are compared with those of existing verifiable robustness assessment methods, for example... Figure 3 As shown. (Through) Figure 3 It can be seen that the proposed method has higher verifiable robustness accuracy than other methods at various robust radii σ.

[0093] Furthermore, for the proposed masked autoencoder-based sanitization method, a separate module was used to evaluate its sanitization capability. Based on the BobustBench benchmark, the standard robustness accuracy (Standard Acc) and adversarial robustness accuracy (Robust Acc) of the model were tested using the standard adversarial attack AutoAttack. In this embodiment, the models used were BEiT and ResNet-50, with standard robustness accuracies of approximately 80% and 66.5%, respectively. Standard adversarial examples were used to evaluate their adversarial robustness accuracy. The experimental results of this embodiment are compared with those of existing sanitization methods. Figure 4 As shown. (Through) Figure 4 It can be seen that, under both BEiT and ResNet-50 model architectures, the proposed method has higher verifiable robustness accuracy at various robust radii σ than other methods.

[0094] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings, but the present invention is not limited to the described embodiments. For those skilled in the art, various changes, modifications, substitutions, and variations can be made to these embodiments, including components, without departing from the principles and spirit of the present invention, and these variations still fall within the protection scope of the present invention.

Claims

1. A method for verifiable robustness optimization under adversarial environment based on masked autoencoder, characterized in that, The method comprises the following steps: Step 1, obtaining an image data set and performing random attack and preprocessing on the data set; Step 2, performing distribution boundary curvature evaluation on the adversarial samples in the data set after random attack, and removing the adversarial samples with low purifying potential according to the evaluation results; In the step 2, a pre-trained classification network BEiT is used for adversarial sample distribution boundary curvature evaluation; The distribution boundary curvature evaluation method is as follows: First, a pre-trained classification network BEiT is used as a classifier E, and different intensity σ L2 norm balls of image samples are sampled; For the sampling results under each noise intensity σ, the entropy is used to quantify the confusion degree of the distribution information in the sampling range, and the entropy expression is as follows: where the random variable X represents the current computed sample, p(x i ) is the probability that the random variable X is classified as a different label by the classifier; Step 3, using a mask autoencoder to reconstruct the purified adversarial samples after purification and removal to obtain purified samples; The method comprises the following steps: Step 3-1, for the adversarial sample, the Grad-CAM technology is used to reveal the decision-making process of the convolutional neural network, using the activation map H of the last convolutional layer and the gradient c obtained by back propagation, combining the gradient c and the convolutional layer activation map H to calculate the sum of the weighted feature map, so as to obtain the activation map of a class Step 3-2: Employ an activation mapping-based approach. The masking strategy is used to mask the adversarial sample X in batches, masking a portion of the adversarial noise and other random locations each time, resulting in the masked input. Step 3-3: Mask the input The encoder part of the pre-trained masked autoencoder will receive the input. Compressed into a low-dimensional latent space representation Next, the decoder part of the pre-trained mask autoencoder is used for reconstruction to obtain the reconstructed result. Finally, through integration operations... Restore to the original image after purification This means that the reconstructed patch is placed in the spatial context of the original image to form a complete image; Step 3-4, pixel-level weighted average of data distribution of all batch-reconfigured original maps to obtain the final purified image Step 4, performing global smoothing optimization on the purified samples to improve the global representativeness.

2. The method of claim 1, wherein, The random attack method is to perform white-box attack on the image samples in the data set to make them deviate from the distribution of the original image and change the classification label of the classifier.

3. The method of claim 1, wherein, The preprocessing method is to crop and scale the samples to match the input of the mask autoencoder.

4. The method of claim 1, wherein, The step 4 comprises the following steps: Step 4-1, sampling the purified input sample The sampling is performed, and for each sampling, a sample is taken within an L2 norm sphere with a surrounding noise intensity σ, is input into a classifier to obtain a confidence vector, the total number of samples taken is set to N, and finally N confidence vectors are obtained. The sampling is performed, and for each sampling, a sample is taken within an L2 norm sphere with a surrounding noise intensity σ, is input into a classifier to obtain a confidence vector, the total number of samples taken is set to N, and finally N confidence vectors are obtained. Step 4-2, storing all confidence vectors into a set, and obtaining a global confidence vector by weighted averaging each confidence vector with other random C confidence vectors, and taking the global confidence vector as the final result; Step 4-3, converting the weighted average global confidence vector into a label y for output.

Citation Information

Patent Citations

  • Member reasoning attack method based on data robustness difference

    CN113516245A

  • Network traffic anomaly detection system and method based on adversarial mask

    CN115589329A